← All posts

Security

Signup, email OTP, and authenticator apps (elected Local Database default)

2026-09-12 · 5 min read

SIGHTLEARN elects Local Database authentication for both platform and tenant surfaces (TEP §6.1). Microsoft Entra ID is an optional Integration Module provider and is never the elected default.

Institution Owners create an account on the public site, then enter a 6-digit email code. Every user then enrols Google Authenticator or Microsoft Authenticator (standard TOTP). Later logins ask for password, then an app code. If the app is unavailable, the user can request an email OTP for that attempt only.

Platform Owner accounts are created manually by an authorized Platform admin (seed, admin API, or ops). There is no public Platform Owner signup and no invite-email product flow. First-login password + 2FA enrolment still apply after manual create.

Staff invites remain for Admin and Teacher only. Never share invite tokens over insecure channels.