Enterprise SSO & SCIM provisioning
On the Enterprise plan, your company can sign in through its own identity provider and manage who has a seat — centrally, from the same place you manage every other app.
SAML single sign-on
Register your identity provider under Settings → SSO, verify your email domain, and teammates can sign in through your IdP. New teammates are provisioned on first sign-in, so joining the workspace is as simple as being granted the app in your IdP.
Passwordless email sign-in stays available as the universal fallback for every account — SSO adds a path, it never locks one out.
SCIM provisioning
The workspace exposes a SCIM 2.0 endpoint, so your IdP can create and deactivate users automatically as people join and leave your company. Groups are supported for role assignment: moving someone between IdP groups adjusts their workspace role, while membership itself stays governed by user provisioning.
Who this is for
If you're not on Enterprise, regular email invitations from Settings → Members cover team access on every other plan — see Invite your team & set roles.
Related
- Invite your team & set roles — the roles SCIM groups map onto.
- Contact support — for help planning an Enterprise rollout.

