ExamNovaDocumentation
Offline readyChangelog
Secure access

First login and authentication

Sign in with the correct role, complete identity checks, and recover access without sharing credentials.

All usersPlatform owner
Who does thisEvery user; administrators configure policy
Before you startAn active account, correct application URL, and access to the configured verification channel
Successful outcomeA verified session with only the access required for the user’s job
Role and permission handoffWork moves from platform owner to assessment staff, students, reviewers, and result consumers.OwnerAdminAuthorStudentMarkerModeratorPublisher
Role and permission handoff. Work moves from platform owner to assessment staff, students, reviewers, and result consumers.

What this means in plain language

Authentication proves who is signing in. Authorization decides what that person may do afterward. A successful login never replaces role, institute, permission, or ownership checks.

Step-by-step

  1. Open the canonical ExamNova URL and check the domain before entering credentials.
  2. Enter your own email and password. Do not use a shared administrator account.
  3. Complete email verification, one-time password, or authenticator challenge when policy requires it.
  4. Check the institute and role shown after login. Ask an administrator to correct membership instead of switching accounts.
  5. Use the password-reset link for forgotten credentials. Never ask another user to disclose a password or recovery code.
  6. Review active sessions and sign out other devices after suspected account exposure.
ExamNova sign-in screen
Live seeded-demo screen. Users enter their own account credentials at the canonical domain.
ExamNova one-time password challenge
Live seeded-demo screen. A configured verification challenge is completed before access.
ExamNova authenticator challenge
Live seeded-demo screen. Authenticator-based two-factor verification protects sensitive roles.
ExamNova administrator security settings
Live seeded-demo screen. Authorized administrators review security policy and sessions.
ExamNova email verification notice
Live seeded-demo screen. The account verifies its own email address before protected work begins.
ExamNova password reset screen
Live seeded-demo screen. A user chooses a new password through a time-limited recovery flow.
ExamNova locked-session screen
Live seeded-demo screen. Repeated or policy-triggered failures stop access without disclosing protected account details.

How to know it worked

Common mistakes

  • Sharing one administrator login among multiple people.
  • Assuming a hidden menu is proof that a route is protected.
  • Sending passwords or recovery codes through support tickets.

If something goes wrong

  • Confirm the exact email address and account status before resetting a password.
  • Check mail configuration and queues when a verification message is delayed.
  • If an account is locked, follow the configured lockout window and review the associated security event.
Privacy and security: Passwords, OTPs, authenticator secrets, recovery codes, reset links, and session cookies must never appear in documentation screenshots or support messages.

What to do next

Administrators should configure the institute and academic structure; other users can continue to the workflow assigned to their role.