Secure access
First login and authentication
Sign in with the correct role, complete identity checks, and recover access without sharing credentials.
All usersPlatform owner
Who does thisEvery user; administrators configure policy
Before you startAn active account, correct application URL, and access to the configured verification channel
Successful outcomeA verified session with only the access required for the user’s job
What this means in plain language
Authentication proves who is signing in. Authorization decides what that person may do afterward. A successful login never replaces role, institute, permission, or ownership checks.
Step-by-step
- Open the canonical ExamNova URL and check the domain before entering credentials.
- Enter your own email and password. Do not use a shared administrator account.
- Complete email verification, one-time password, or authenticator challenge when policy requires it.
- Check the institute and role shown after login. Ask an administrator to correct membership instead of switching accounts.
- Use the password-reset link for forgotten credentials. Never ask another user to disclose a password or recovery code.
- Review active sessions and sign out other devices after suspected account exposure.







How to know it worked
- The browser ends on the correct role dashboard.
- Protected pages outside the role remain unavailable.
- Verification and reset messages arrive through the configured channel.
- Signing out invalidates the active session.
Common mistakes
- Sharing one administrator login among multiple people.
- Assuming a hidden menu is proof that a route is protected.
- Sending passwords or recovery codes through support tickets.
If something goes wrong
- Confirm the exact email address and account status before resetting a password.
- Check mail configuration and queues when a verification message is delayed.
- If an account is locked, follow the configured lockout window and review the associated security event.
Privacy and security: Passwords, OTPs, authenticator secrets, recovery codes, reset links, and session cookies must never appear in documentation screenshots or support messages.
What to do next
Administrators should configure the institute and academic structure; other users can continue to the workflow assigned to their role.