First-run setup¶
This page applies only to a brand-new RiskVault installation. It follows the experience from the first sign-in, through the setup checklist, to the point where RiskVault opens for everyone else.
- The RiskVault team supplies temporary setup credentials and makes sure the required infrastructure is configured.
- Your organization chooses a default RiskVault administrator to configure the application. This person signs in once with the temporary credentials, gives a real email address, and receives an invitation to create the first administrator account. That account needs a unique password that meets the security requirements, and must enroll in multifactor authentication.
- The new administrator then works through a short checklist of organization-specific settings before RiskVault becomes generally available.
Before starting¶
The deployment must already have:
- the temporary setup email and password (
FirstRunUser:EmailandFirstRunUser:Password) as deployment secrets; - the public RiskVault base URL and outbound email. A deployment-level email provider covers email out of the box, so your organization's own SMTP server is not required before first run (see Email delivery);
- the databases, Redis, Data Protection key, sign-in certificate, file storage, and other infrastructure RiskVault needs to start.
Do not use the temporary setup email as a normal RiskVault account. RiskVault does not add it to the user directory, give it a role or policy, or give it an ordinary sign-in session. Its only purpose is to authorize sending the first administrator invitation.
The invitation link is valid for 30 minutes
The first-administrator registration link expires 30 minutes after RiskVault generates it. Ordinary user invitations last 7 days, but this link is created before anyone has signed in and grants administrator access, so its window is deliberately short. Have the future administrator ready to register before you send it.
Send the first administrator invitation¶
- Open the new RiskVault installation. While setup is incomplete, RiskVault sends browser users to Setup.
- Select Start first-run setup and enter the temporary setup email and password supplied by the deployment operator. Rejected attempts are rate limited.
- Enter a real email address that the first administrator can access.
- Review the warning and select Send administrator invitation.
- The temporary setup login is now permanently disabled. RiskVault keeps the invitation record as a lasting "already used" marker, even across restarts and after the invitation expires. The operator should now remove
FirstRunUser:*from the deployment secrets.
Image needed: Setup page showing the temporary sign-in step and the Send administrator invitation confirmation.
Register the first administrator¶
- Open the invitation email and follow its link to the registration page.
- Create the permanent account and complete the profile and legal-acceptance fields.
- RiskVault confirms the email address, grants the account the Admin role and Admin Policy, and signs the administrator in.
- Enroll an authenticator app and verify a current six-digit code. This is mandatory for the first administrator, whatever MFA policy you later choose for everyone else.
- Continue to Setup and work through the checklist below.
Until setup is finished, anyone else who signs in sees a holding page instead of the product.
If the invitation expires or the email doesn't arrive¶
There is no self-service recovery. The temporary login does not turn back on, and no button or admin screen can resend the invitation. Contact whoever operates your RiskVault deployment. They have an operator-only procedure that issues a fresh link, with a new 30-minute window, to the address you give them. The previous link then stops working.
If the invitation has not expired but the email hasn't arrived, ask the operator to check the sender address, spam filtering, and the background email queue first. Recovery cannot replace an invitation that is still valid.
Work through the setup checklist¶
Setup is a checklist titled Finish setting up RiskVault. You can do the steps in any order and come back later; progress is saved as you go.
| Step | What you decide | Required to finish? |
|---|---|---|
| Organization profile | Organization display name, default time zone, support/contact email, and — if you use the Terms of Use gate — the legal contact, document version, and effective date. | Yes |
| Authentication & security | Whether people can create their own accounts (and from which email domains), whether MFA is optional or required for everyone, and whether accounts created by user import, SCIM, or first-time external sign-in record Terms of Use acceptance automatically. If you choose open sign-up, you're asked to confirm it. The Admin role only MFA option isn't offered here; set it later under Password & Login Policies. | Yes |
| Risk rating matrix | Opens the risk matrix editor (size, level labels, rating bands, and colors). The step completes itself once you Activate the matrix. This is the one irreversible setup decision. See Configure the risk matrix. | Yes |
| Reference data | Review the business units, regions, risk factors, and impact areas people pick from (plus asset types when the asset inventory is on). An empty list shows a warning that you can acknowledge and move on from. | Yes |
| Operating defaults | Automatic reviewer assignment, the notification sender name and address, the SLA badge/queue/digest switches, and the asset inventory. Accept recommended keeps the suggested values. | No — optional |
Image needed: Setup checklist showing the five steps, their completion status, and the Readiness check panel.
Readiness check¶
A Readiness check sits beside the checklist. It helps, but it never stops you from finishing. It checks:
- that a test email can be sent;
- that a test file can be saved to, read from, and removed from file storage;
- that the public base URL matches the address you're using;
- that the pick-lists (reference data) aren't empty.
The email and file tests only run when you ask for them.
Finish setup¶
When the four required steps are done, Review shows every choice together and enables Finish setup & open RiskVault. RiskVault checks the steps again when you select it, in case something changed since the page loaded.
After setup is finished, the checklist pages send you to the RiskVault is set up page instead. It lists what setup configured (highlighting anything you changed from the defaults), anything still worth doing, and follow-up work for the deployment operator, such as removing the temporary setup credentials. The page stays reachable from the Configuration Hub.
Every later change to these settings is made in the Configuration Hub, not by re-running setup.