Enterprise SSO & SCIM provisioning
On Enterprise, your company signs in through its own identity provider and manages who has a seat centrally — from the same place you manage every other app.
What you get
- One sign-in for your whole company, through the identity provider you already run.
- Automatic seat provisioning and deprovisioning as people join and leave — no manual member cleanup.
- Role assignment from your IdP's groups, so promoting someone in your directory promotes them in the workspace too.
Set up SSO
- Register your identity provider under Settings → SSO.
- Verify your email domain.
- Teammates sign in through your IdP from that point on; new teammates are provisioned automatically on first sign-in, so joining the workspace is as simple as being granted the app in your IdP.
Passwordless email sign-in stays available as the universal fallback for every account — SSO adds a path, it never locks one out.
SCIM provisioning
The workspace exposes a SCIM 2.0 endpoint, so your IdP can create and deactivate users automatically as people join and leave your company. Groups are supported for role assignment: moving someone between IdP groups adjusts their workspace role, while membership itself stays governed by user provisioning.
Who this is for
SSO and SCIM are Enterprise-only. If you're not on Enterprise, regular email invitations from Settings → Members cover team access on every other plan — see Invite your team & set roles.
Go further
- Invite your team & set roles — the roles SCIM groups map onto.
- Billing & credits basics — see what unlocks on Enterprise.
- Contact support — get help planning an Enterprise rollout.

