How single sign-on works
Eazi Digital products don't have their own separate sign-in — when you try to use one and aren't signed in, it redirects you to Eazi Digital Keystone IAM to authenticate, then sends you back once you're done. If you're already signed in to Eazi Digital Keystone IAM from using another product, you're usually sent straight back without having to enter your details again.
This only works for applications you've been given access to — see Giving a user access to applications. If you're redirected here for a product you don't have access to, ask your administrator to add it to your account.
The organisation picker
If your account belongs to more than one organisation, you'll be asked to pick which one you're signing in as before you're sent on to the application. This matters because your access, roles, and data are all scoped to whichever organisation you choose — the same as switching organisations inside the Tenant Portal.
Signing in on a device without a browser
Some applications — for example a command-line tool or a TV app — can't show you a full sign-in page directly. In that case, the application shows you a short code and asks you to visit /device from a phone or computer. Enter the code there, sign in as normal, and the original device picks up automatically once you approve it.
Signing out everywhere
Signing out of Eazi Digital Keystone IAM ends your single sign-on session, and connected applications are notified in the background so their own sessions end too — you shouldn't need to sign out of each product separately. If an application still shows you as signed in after this, treat it as a bug and see Troubleshooting.
Next, see Activity Logs to review sign-in and account activity.