What you get
Organizations & members
First-class organizations with members and invitations — admin-gated, and every change lands in the audit trail.
Enforced roles
Admin and member roles are enforced at the API on every request — not decoration in a settings table.
Org-forced MFA
Require MFA for an organization: a user without a second factor can only enroll one until they comply.
Enterprise SSO path
SAML / OIDC connections live at the API today; the self-serve portal ships after launch. Never metered per connection.
Organizations, roles, policy — built in.
Organizations with members, invitations and enforced roles — and organization-level security policy like forced MFA, applied at sign-in, not suggested in a banner.
Open the live demoFrom signed contract to onboarded team.
Create the organization
One call or one click — the organization exists with you as its admin, isolated from every other tenant.
Invite the team, roles attached
Invitations carry a role. The member and their enforced permissions exist the moment they accept — nothing to sync afterwards.
Set the security policy
Turn on forced MFA, connect SSO through the API, and watch every change land in the organization’s audit trail.
The controls a business account actually needs.
Invitations that create real members
An admin invites by email with a role attached — the member and their enforced role exist the moment the invite lands.
Security policy at the org level
Forced MFA is an organization policy with teeth: enrollment-only sessions until the user adds a factor, self-healing once they do.
Audit per organization
Every identity event in the organization — sign-ins, role changes, deletions — queryable and exportable, stored in your EU region.
Step-up-gated administration
Destructive org operations — deletions, policy changes, invitations — require the admin to re-prove their identity first.
Live today — and what ships after launch.
The same rule as everywhere on this site: what is done says done, what is planned says planned.