> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberopsource.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Signing In

> How to access your organization's Compliance OS environment.

# Signing In

Compliance OS access begins with your organization's client-specific entry point.

## Before you sign in

You generally need:

* an account that has been invited or provisioned for your organization,
* an active Compliance OS user record,
* access to at least one applicable engagement or application,
* your organization's correct Client Portal address.

Use the email address associated with your invitation or account.

## Sign-in flow

1. Open the Client Portal URL provided by Cyber Op Source.
2. Select the available sign-in method for your account.
3. Complete the identity-provider authentication process.
4. After authentication, Compliance OS verifies your active user and client context.
5. The Client Portal shows the applications and information authorized for you.

Depending on your organization's configuration, sign-in may use email/password or an approved federated identity option.

## Why the URL matters

Client Portal addresses identify the client context you are attempting to enter. Authentication alone is not sufficient to authorize a different client environment.

This helps prevent a valid account from being used as a shortcut into another organization's portal.

## If sign-in succeeds but you see no applications

Authentication and application assignment are separate concepts.

You may be successfully signed in but still lack:

* an assigned interview,
* remediation access,
* executive governance access,
* engagement-scoped permissions.

Review [Roles & Access](/getting-started/roles-access) and contact your Cyber Op Source engagement lead if the result does not match your expected responsibilities.

## Good account practices

* Do not share your account.
* Use your own assigned identity.
* Protect authentication factors and recovery methods.
* Sign out of shared or unmanaged devices.
* Report unexpected access or account behavior promptly.
* Do not reuse screenshots containing sensitive client information outside approved channels.

<Warning>
  Never send your password, authentication code, access token, or recovery secret to Cyber Op Source through a documentation form or ordinary email.
</Warning>
