Teams, enterprise & SSO
Teams, enterprise & SSO
An enterprise account gives your team shared capabilities and allowances, a verified email domain, and single sign-on. Enterprises are set up by sales. Once yours exists, this page covers what an owner or admin configures.
Roles
Every member of an enterprise has a role:
- Owner: full control, including billing and enterprise settings.
- Admin: manages members, domains, and SSO, but can’t touch owner-only controls.
- Member: a regular user in the enterprise, with access to the enterprise’s capabilities and allowances.
Domain verification (DNS-TXT)
Before you can auto-provision or enforce SSO for your users, you verify that you own their email domain:
- Add your domain in the enterprise settings.
- The platform gives you a verification token.
- Publish that token as a DNS TXT record on the domain.
- The platform checks the record and marks the domain verified.
A verified domain is what lets the platform associate new sign-ins from that domain with your enterprise.
Single sign-on (OIDC)
Enterprises connect their own identity provider over OIDC. Once configured, your users sign in through your IdP instead of a local password. Two settings control the behavior:
- Auto-provision: when on, a user signing in from a verified domain is automatically created and placed in your enterprise as a member. No manual invite needed for known-domain users. (On by default.)
- Enforce SSO: when on, users on your domain must sign in through SSO, and other sign-in methods are refused. Use this to make SSO mandatory once you’ve confirmed the connection works.
Configure the connection carefully. Turn on Enforce SSO only after you’ve verified a test user can sign in through it, so you don’t lock your team out.
Inviting members
For users outside your verified domain, or before auto-provisioning is on, invite members directly from the enterprise settings. Invited users join with the role you assign (admin or member).
Usage across the team
The enterprise’s capabilities apply to every member. Storage and investigation-unit allowances are set at the enterprise level and applied to each member, so one heavy user doesn’t consume a teammate’s budget. Admins can see usage across the team. See Investigation units & quotas for how usage is counted.
Next
- Plans & pricing: capabilities and allowances.
- Security & data handling: how the platform handles auth and data.