> For the complete documentation index, see [llms.txt](https://docs.p0.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.p0.dev/getting-started/p0-security-onboarding.md).

# Set up P0 for your organization

Deploy P0 Security, integrate your cloud environments, and establish just-in-time access for human and non-human identities. For security and DevOps teams.

Welcome to **P0 Security**.

This guide provides a structured pathway for deploying P0, integrating your cloud environments, and establishing secure, just-in-time (JIT) access for both human and non-human identities. It is designed for Security Engineers, DevOps practitioners, and engineering leaders seeking a precise and unified approach to modern access governance.

## Table of contents

1. [Prerequisites](#prerequisites)
2. [Account setup](#account-setup)
3. [Core capabilities](#core-capabilities)
   * [Getting started with Inventory & Posture](#️-getting-started-with-inventory-and-posture)
   * [Getting started with Just-in-Time Access](#️-getting-started-with-just-in-time-access)
   * [Governing what your AI Agents can do](#-governing-what-your-ai-agents-can-do)
4. [Next steps and resources](#next-steps-and-resources)

## Prerequisites

Before onboarding, confirm the following:

* A corporate email address for registration.
* Permissions to establish cloud integrations (AWS, GCP, Azure, etc.).
* The ability to assign or manage custom IAM roles within your provider.
* *(Optional)* Slack workspace access if leveraging Slack-based requests.
* *(Optional)* Microsoft Teams access if leveraging Teams-based requests.

## Account Setup

1. **Choose an identity provider**
   * Select the authentication method for your organization.
   * See [Supported identity providers](/getting-started/p0-security-onboarding/supported-identity-providers.md) for available options.
   * For Okta sign-in, contact P0 Security before proceeding.
2. **Create your P0 account**
   * Register with your organizational email at <https://p0.app/create-account>.
   * Sign in using your chosen identity provider.
3. **Initial organization configuration**
   * Complete the onboarding wizard.
   * Define your organization name.
   * Invite foundational team members.

## Core capabilities

P0 offers three primary capabilities: gaining visibility into your cloud environments, managing just-in-time access, and governing what your AI agents can do. You can set them up in any order.

### ⬇️ Getting started with Inventory & Posture

To begin discovering, analyzing, and securing your cloud identity and access posture, you will need to connect your cloud environments to P0. This involves creating an integration and running an initial scan to populate your inventory.

For a complete walkthrough, see the detailed guides:

* [**Explore who has access to what with Access Inventory**](/getting-started/getting-started-with-access-inventory.md)
* [**Find risky access with Posture**](/getting-started/getting-started-with-posture.md)

### ⬇️ Getting started with Just-in-Time Access

To enable secure, temporary access to your cloud resources, you will need to configure integrations, set up approval workflows, and make your first request. This process includes installing P0 on specific IAM resources and assigning security reviewers.

For a step-by-step tutorial, refer to the detailed guide:

* [**Grant just-in-time access to your cloud**](/getting-started/getting-started-with-just-in-time-access.md)

### 🤖 Governing what your AI Agents can do

To put runtime authorization in front of your AI agents, you will need to deploy the P0 AI Gateway into your own Kubernetes cluster, expose an MCP server behind it, and write the policy that governs what agents may do. Every tool call is then checked against that policy and attributed to a named person and a specific agent.

For a step-by-step tutorial, refer to the detailed guide:

* [**Govern what your AI Agents can do**](/getting-started/govern-what-your-ai-agents-can-do.md)

## Next steps and resources

You are now positioned to:

* Extend integrations (IAM, databases, developer tools).
* Connect P0 to your corporate directory.
* Automate workflows and configure advanced access policies.
* Enable continuous risk analysis and remediation.

### Share P0 with your team

If you've installed the Slack integration, you can use the Slack bot to instruct users on requesting access through P0.

Type `/p0 share` in any channel or DM, and the P0 bot will respond with a message that explains how to use P0 for access requests and includes a button to immediately begin an access request.

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-cba008ae09f2a96cb22ec477e137bd1804061829%2Fimage.png?alt=media" alt="Slack message from P0 Security bot explaining how to use /p0 request for access requests, with a Request Access button"><figcaption></figcaption></figure>

`/p0 share` also accepts an optional user argument: use the command `/p0 share USER_EMAIL` or `/p0 share @USER_MENTION` to have the bot directly DM the specified user.

This can help your organization transition towards using P0 as the only system for access requests: if somebody makes a request through another means, use `/p0 share` to inform them of P0, and they can quickly get started with their first request.

## Support

📧 <support@p0.dev>

## Recommended reading

* [Creating an environment](/getting-started/creating-an-environment.md)
* [Access Inventory & Posture guides](/inventory/access-inventory.md)

**P0 Security:** Delivering secure cloud access at engineering velocity.\
Welcome to unified access governance.
