Log in and activate your account
To sign in to GLAIM, enter your email and password on the login screen and click "Log in". If you don't remember your password, use the "Forgot your password?" link to receive reset instructions. The "Remember me" checkbox keeps your session active for two days on that device.
If it's your first time logging in and an administrator required you to change your initial password, you'll see a dialog you can't close until you set a new one.
If your organization has two-factor authentication (MFA) enabled, after your first login you'll be taken automatically to the setup screen. The steps are:
- A QR code is shown on screen. The code also appears as text below it, in case you'd rather enter it manually into any TOTP-compatible authenticator app.
- Scan the code, or enter it manually, in your authenticator app.
- Type the 6-digit code your app shows into the "Verification code" field.
- Click "Enable MFA".
- The system gives you a set of one-time recovery codes, shown only at that moment. You can copy them or download them as a text file. Keep them somewhere safe: they're the only way back in if you lose access to your authenticator app.
- Click "I've saved my codes, continue" to finish setup.
From then on, every login will ask for the 6-digit code from your authenticator app in addition to your password. If your account uses your organization's single sign-on (SSO), this MFA step doesn't apply: verification is handled by your company's identity provider.
MFA status can be checked from your user profile, though it's informational only there: activation happens exclusively through the setup screen described above.
Create your first pentest
From the pentest list, click "New" to open the creation form. It's organized in three steps.
Step 1: General. If your organization has pentest templates configured, you can select one or more at the start so several fields fill in automatically (associated reports, checklist, compliance norms, among others). Then fill in: name, identifying code (there's a button to suggest one automatically), initial status, client (required, with search), associated service, tags, work types, work description and access credentials if applicable.
Step 2: Assignment. Here you define who works on the pentest: project owner, reviewer, assigned teams and users (with a dedication percentage per person), CVSS version to use, report template(s), methodology checklist, applicable compliance norms, scope (included assets) and relevant client contacts.
Step 3: Dates. Start date, end date, start and end of the planning/reporting phase, and the report delivery deadline. These five fields are required.
After finishing the last step, click "Create" to set up the pentest.
Invite your team
From the users section, click "Create user" to open the sign-up form. There are three ways to give a new person access:
- Invite by email: the user gets a link to set their own password.
- Generate a temporary setup link: a one-time URL is generated, valid for 24 hours, which you send through whichever channel you prefer.
- Manual assignment: you set an initial password yourself and share it securely.
Besides the email, the form asks for: first and last name, job title, interface language, role or roles (from those your organization has enabled) and, if the assigned role requires client scope, the corresponding client. You can also mark the account as active or inactive.
To organize several people into a working group, use the teams section. There, "Create team" opens a form with a name, description and a member list you select right in that same step: there's no separate flow to add people to an existing team, just edit it and change the member list.