When to use Cloudraw accounts
Cloudraw accounts are for organizations without a central directory: small offices, workgroup PCs, branch offices, or a few contractors. Cloudraw keeps the accounts. You add people and invite them by e-mail, and each person chooses their own password.
Every sign-in has two steps: the person's e-mail address and password, then a one-time code that Cloudraw e-mails to them.
Invitations are only available when no identity provider (Microsoft Entra ID, Google, Okta or OpenID Connect) is connected to the workspace. If one is connected, people sign in with their existing account there and need no invitation.
1. Add people
- Open PeopleIn the Cloudraw admin console, open People and click Add a person.
- Enter their detailsEnter the person's e-mail address (required, and it must be one they can read) and their name. You can put them in groups now or later.
- SaveThe person now uses one seat. The People page shows how many seats you use out of your plan's total.
In onboarding step 3, Sign-in for your users, the option Cloudraw accounts (no directory) takes you through adding and inviting people.
2. Invite them
- Send the invitationOn the People page, choose the person and click Invite. You can invite several people at once.
- Check the statusThe person shows as Invited until they sign in for the first time.
The first invitation also turns on sign-in for your workspace and makes the e-mail code the second step for every sign-in in that workspace. This includes Active Directory users, if you also use Active Directory.
What your people receive
An e-mail with the subject "You're invited to your workspace", sent from noreply@cloudraw.com or from your own sender address if you have set one up (see Send codes from your own domain). It says:
- Set your password with the button in the e-mail.
- Install Cloudraw Connect from the download link in the e-mail.
- Open Cloudraw Connect, choose "Sign in", and sign in with their e-mail address and password. A one-time code is e-mailed to them every time they sign in.
The password link expires after a while. If it has expired, send the invitation again.
Also tell your people your workspace name. Cloudraw Connect asks for it before the sign-in window opens. You find it under Settings→Identity & SSO, and onboarding step 6 has a Copy text button with a ready-made message for your users.
Their first sign-in
- Set a passwordThe person clicks Set your password in the e-mail and chooses a password.
- Install and open Cloudraw ConnectSee Install Cloudraw Connect and enroll your computer.
- Sign inThey type the workspace name, click Sign in, then enter their e-mail address and password in the browser window.
- Enter the e-mail codeThey type the one-time code from the e-mail "Your sign-in code for workspace".
Resend an invitation
Click Invite again on the person (the console shows Invited · resend). Each resend e-mails a fresh Set your password link. You can resend once a minute.
Common reasons to resend: the link expired, the e-mail went to spam, or the person deleted it. If the e-mail address was wrong, correct it on the person first.
Alternative: create an account with a starting password
If a person cannot receive e-mail yet, open Settings→Identity & SSO, go to Users and click Add a user. Cloudraw shows a starting password once. Pass it on securely. The person must change it at their first sign-in. Invitations are the better choice, because nobody but the person ever knows the password.
Organize people with groups
Without a directory, you create the groups yourself. Groups decide what people can reach, through access rules.
- Create a groupClick New group, give it a name such as Finance, and pick its members. Group names must be unique.
- Change members or renameOpen the group to add or remove members or rename it. Membership changes apply to people's devices right away.
- Use it in an access ruleIn Access rules, choose the group as who can reach an app or network.
- Delete a groupYou can delete a group only when no access rule uses it. If one does, the console lists the rules to change first.
No groups yet? An access rule can also name people or devices directly, for example "dana@yourcompany.com" or "Reception PC". This suits very small teams. Switch to groups when you have more than a handful of people.
Suspend or remove someone
| Action | Where | What happens |
|---|---|---|
| Suspend | People, the person, Suspend | The person can no longer sign in or enroll a computer, and their devices lose access. Use it for leave, a lost laptop, or an investigation. Unsuspend to restore access. A suspended person cannot be invited. |
| Disable sign-in | Settings→Identity & SSO→Users, Disable | Blocks the sign-in account only. Enable turns it back on. |
| Remove | People, the person, delete | Removes the person and frees their seat. Also remove their sign-in account under Settings→Identity & SSO→Users, Remove. |
For a leaver, suspend first so access stops at once. Then remove the person and their sign-in account. Also remove or re-assign their computers under Devices.
Common questions
Can people reset their own password?
Sending the invitation again gives them a new Set your password link.
Can I use the same e-mail address in two Cloudraw workspaces?
Yes. Each workspace has its own account and password for that address. Cloudraw Connect can hold several workspaces on one computer.
Can I switch to Microsoft Entra ID or Google later?
Yes. Read Changing method later first. Accounts are not linked automatically.