Guides

Day-to-day org admin tasks. Sections you cannot open yet (Passkeys, SCIM, …) are omitted.

Overview {#overview}

Organizations → your org shows name, slug, KPIs (members, workspaces), and owner actions:

Organization overview with KPIs and owner actions
Overview — rename, transfer ownership, or open quick links to members and workspaces.

Members {#members}

Members has three tabs when SSO join approval is enabled:

Tab Purpose
Members Active org members, change role, remove
Invitations Pending email invites, copy link, revoke
Pending approval SSO users waiting for admin approve/reject

Invite by email

  1. Invite members → enter emails → pick role → send.
  2. Share invite URLs from the results list if needed.
  3. Invites expire per server policy — re-invite if expired.

You cannot invite with role owner — use transfer instead.

Organization members list with invite button
Members — active roster, invitations, and pending SSO join requests when enabled.
Invite members drawer with email list and role picker
Invite — comma-separated emails and org role before sending.
Pending invitations and SSO join approval queue
Pending — email invites and SSO join requests awaiting admin action.

SSO join approval

When SSO is enabled without full auto-approve:

  1. User completes IdP login.
  2. Request appears under Pending approval.
  3. Admin Approve (grants org membership) or Reject.

Configure auto-approve rules on the SSO tab (including Lark department allowlists when applicable).

SSO {#sso}

  1. Open SSO.
  2. Enable a provider (Lark, OIDC, SAML, …) when your deployment supports it.
  3. Set credentials and organization slug where required.
  4. Test with Continue with SSO from a private window.
  5. Tune Member approval — auto-approve all, selected departments, or manual queue.

Before disabling password login, ensure at least one working SSO provider is enabled.

SSO provider configuration and member approval settings
SSO — enable Lark, OIDC, or SAML; tune auto-approve and department allowlists.

Security {#security}

Security covers org-wide auth policy:

When MFA is required, members see enrollment prompts until they complete Account → Security.

Organization security policy for passwords and MFA
Security — password rules and require MFA for all members.

Domains {#domains}

Verify domains you control:

  1. Add domain → follow DNS or hosted verification steps.
  2. Use verified domains to restrict SSO email or invitation eligibility.

Domain verification is org-admin only.

Verified email domains for the organization
Domains — add and verify domains to restrict SSO or invitation eligibility.

Workspaces {#workspaces}

Workspaces under the org lists every workspace in the tenant:

Creating many workspaces is an org-level decision; day-to-day env setup is under Workspaces → Environments.

Workspaces inventory under the organization
Org workspaces — switch context or create a workspace when quota allows.

Plan {#plan}

Quota errors surface when creating members or workspaces — upgrade or request seats on Plan.

Organization plan seats quotas and feature flags
Plan — seat counts, quotas, and feature flags for the org.

License {#license}

Org admins see grant cards for packs issued to the tenant. Platform operators manage grants under Platform → Licenses (not covered in this end-user guide).

Organization license grants with Spanline Pro pack and seat metadata
License — active commercial grants, licensed members, and request actions for org admins.

Audit {#audit}

Audit shows org-scoped events:

Workspace-scoped actions may include workspace id in metadata. Platform-only events stay in platform operator tools (not covered here).

Organization audit log with filters and export
Audit — filter org-scoped events and export CSV for compliance.