---
title: Connecting a Fastly account to your corp
summary: null
url: >-
  https://www.fastly.com/documentation/guides/next-gen-waf/account-info/connecting-a-fastly-account-to-your-corp
---

> **IMPORTANT:** This guide only applies to Next-Gen WAF customers who **cannot** access the WAF in the Fastly control panel.

When you connect a Fastly account to your Next-Gen WAF corp, you gain access to the Next-Gen WAF and through the [Fastly control panel](https://manage.fastly.com) and [Fastly API](https://www.fastly.com/documentation/reference/api/ngwaf/) while retaining access to the [Next-Gen WAF control panel](https://dashboard.signalsciences.net) and [Next-Gen WAF API](https://www.fastly.com/documentation/signalsciences/api/). If purchased, Bot Management also becomes available through both control panels and APIs. Your WAF configuration settings and user accounts are shared across both control panels, so any changes you make will be immediately reflected in both experiences.

## Limitations and considerations

The option to connect a Fastly account to your corp is not available if you have:

- an Edge WAF deployment that protects a CDN service with mutual TLS (mTLS) enabled.
- CDN services from multiple Fastly accounts that are protected by a single corp.

To link a corp to a Fastly account, you must be an Owner of the corp and a Superuser of the Fastly account that you're linking. If you do not have a Fastly account, you need to [create](https://www.fastly.com/documentation/guides/full-site-delivery/getting-started-with-full-site-delivery/#create-an-account) one.

## How it works

Start by logging in to the Next-Gen WAF control panel and [selecting the Fastly account](https://www.fastly.com/documentation/guides/next-gen-waf/account-info/connecting-a-fastly-account-to-your-corp#linking-a-fastly-account) that you'd like to connect to your corp. This action is permanent and cannot be changed. Next, if you have an Edge WAF deployment, [transition its management](https://www.fastly.com/documentation/guides/next-gen-waf/account-info/connecting-a-fastly-account-to-your-corp#transitioning-edge-waf-management) to the Fastly control panel or the Fastly Terraform provider.

### Initial user provisioning

After you've connected your corp to a Fastly account, Fastly adds your corp users to the linked Fastly account and assigns them equivalent security roles (as shown in the following table). This means your users will be able to access the Next-Gen WAF and (if purchased) [Bot Management](https://docs.fastly.com/products/bot-management) through both control panels and APIs.

| [Signal Sciences account role](https://www.fastly.com/documentation/guides/next-gen-waf/account-info/using-user-roles-and-permissions/) | [Fastly account role](https://www.fastly.com/documentation/guides/account-info/user-and-account-management/about-user-roles-and-permissions/#security-next-gen-waf-roles) |
| --------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Owner                                                                                                                                   | Next-Gen WAF Owner                                                                                                                                                        |
| Admin                                                                                                                                   | Next-Gen WAF Admin                                                                                                                                                        |
| User                                                                                                                                    | Next-Gen WAF User                                                                                                                                                         |
| Observer                                                                                                                                | Next-Gen WAF Observer                                                                                                                                                     |

Corp users who are new to the Fastly control panel can log in to <https://manage.fastly.com> using their <https://dashboard.signalsciences.net> credentials. Users who already had access to both control panels with the same email address will experience no credential changes.

### Managing shared configurations

Your WAF configuration settings and user accounts are accessible across both the Next-Gen WAF and Fastly control panels, with changes immediately applied to both.

However, the Fastly control panel provides more configuration options for the following signals:

- Login Attempt
- Login Success
- Login Failure
- Registration Attempt
- Registration Success
- Registration Failure

This means that if you use the Fastly control panel to configure them, the changes may not be visible in the Next-Gen WAF control panel. If you use the Next-Gen WAF control panel to configure these signals, your changes will override whatever is displayed in the Fastly control panel. The Fastly control panel will always represent the latest configuration.

### Managing Edge WAF deployments

After you've connected your corp to a Fastly account and [transitioned your Edge WAF deployments](https://www.fastly.com/documentation/guides/next-gen-waf/account-info/connecting-a-fastly-account-to-your-corp#transitioning-edge-waf-management), the method you use to create and manage Edge WAF deployments may change:

- **Fastly control panel and API:** use for Compute services and CDN services without mutual TLS (mTLS).
- **Next-Gen WAF API:** use for CDN services with mTLS.
- **Fastly Terraform provider:** use for all Edge WAF deployments that use Terraform without mTLS.
  {/_ vale Fastly.Spelling["Sigsci"] = NO _/}
- **Sigsci Terraform provider:** use for all Edge WAF deployments that use Terraform with mTLS.
  {/_ vale Fastly.Spelling["Sigsci"] = YES _/}

## Linking a Fastly account

Linking your Next-Gen WAF corp to a Fastly account is a one-time action that permanently connects the corp to the Fastly account. To link your corp to a Fastly account, complete the following steps:

1.   Log in to the [Next-Gen WAF control panel](https://dashboard.signalsciences.net).

2. In the banner at the top of the Corp Overview dashboard, click the **Link account** link.
3. Click **Link account**.
4. Check the box to confirm that you understand that the link will be permanent and cannot be changed and click **Continue to account selection**.
5. From the **Fastly account** menu, select the Fastly account that you'd like to link to your corp.
6. In the **Account name** field, enter the name of the Fastly account to confirm that you made the correct selection.
7. Click **Confirm and link account**. The corp and account are permanently linked and Fastly begins copying all corp users to the linked Fastly account. Upon completion, Fastly emails all superusers of the Fastly account.
8. _(Optional)_ If [single sign-on (SSO)](https://www.fastly.com/documentation/guides/account-info/user-and-account-management/setting-up-single-sign-on-sso/#requiring-sso-for-your-organization) is enabled for your Fastly account, add the email addresses for the corp users to your identity provider (IdP).

## Transitioning Edge WAF management

If you have an Edge WAF deployment for a Compute service or a CDN service without mutual TLS (mTLS), you need to transition its management to the Fastly control panel or the Fastly Terraform provider.

### Fastly control panel migration

To transition management of your Edge WAF deployment from the Next-Gen WAF API to the Fastly control panel, complete the following steps:

1.   Log in to the [Fastly control panel](https://manage.fastly.com).

2.   From the [**Home**](https://manage.fastly.com/home) page, select the appropriate service. You can use the search box to search by ID, name, or domain.

3. Click **Service configuration** and then **Security**.

4. Fill out the following deployment settings on the Next-Gen WAF card:

   ![Edit Next-Gen WAF deployment settings](/img/ngwaf/edit-ngwaf-deployment.png)

   - From the **Workspace** menu, select the workspace that you want to link to the service. If your account only has one workspace, this field is read-only.
   - (CDN services only) In the **% of traffic** field, enter the percentage of traffic that you want the Next-Gen WAF to inspect. When set to `100`, all traffic to your service is inspected. When the value is less than 100, a random sample of the specified percentage is inspected.

5. Click the **Next-Gen WAF** switch to the **On** position.

6. In the confirmation window, click **Update all versions**.

### Terraform migration

{/_ vale Fastly.Spelling["sigsci"] = NO _/}
To transition management of your Edge WAF deployments from the [sigsci Terraform provider](https://registry.terraform.io/providers/signalsciences/sigsci/latest/docs) to the [Fastly Terraform provider](https://registry.terraform.io/providers/fastly/fastly/latest/docs), complete the following steps:
{/_ vale Fastly.Spelling["sigsci"] = YES _/}

1. In your terraform configuration, comment out the `sigsci_edge_deployment_service` and `resource sigsci_edge_deployment` definitions. For example, comment out this:

   ```text
   resource "sigsci_edge_deployment" "ngwaf_edge_site_service" {
    site_short_name = var.NGWAF_SITE
   }
    resource "sigsci_edge_deployment_service" "edge" {
    site_short_name  = sigsci_edge_deployment.edge.site_short_name
    fastly_sid       = "<fastly SID>"
    activate_version = true
    percent_enabled  = 100
    depends_on = [sigsci_edge_deployment.ngwaf_edge_site_service]
   }
   ```

2. In a terminal application, run `terraform plan / terraform apply`.

3. In your terraform configuration, add the following to your `fastly_service_vcl` section:

   ```text
   product_enablement {
      ngwaf {
        enabled=true
        workspace_id="<workspace shortname here>"
      }
   }
   ```

4. In a terminal application, run `terraform plan / terraform apply`. Your Edge WAF deployment now uses the [Fastly Terraform provider](https://registry.terraform.io/providers/fastly/fastly/latest/docs).

## Related content

- [About user roles and permissions](https://www.fastly.com/documentation/guides/account-info/user-and-account-management/about-user-roles-and-permissions/)
- [Edge WAF deployment using the Fastly control panel](https://www.fastly.com/documentation/guides/next-gen-waf/setup-and-configuration/edge-deployment/edge-waf-deployment-using-the-fastly-control-panel/)
