Skip to content
ORGANIZATIONS

B2B auth, without the rebuild.

Organizations, members and enforced roles — plus the controls your largest customers actually check: forced MFA, per-org audit trails, and an SSO path that is never priced per connection.

What you get

Organizations & members

First-class organizations with members and invitations — admin-gated, and every change lands in the audit trail.

Enforced roles

Admin and member roles are enforced at the API on every request — not decoration in a settings table.

Org-forced MFA

Require MFA for an organization: a user without a second factor can only enroll one until they comply.

Enterprise SSO path

SAML / OIDC connections live at the API today; the self-serve portal ships after launch. Never metered per connection.

Organizations, roles, policy — built in.

Organizations with members, invitations and enforced roles — and organization-level security policy like forced MFA, applied at sign-in, not suggested in a banner.

Open the live demo
Acme GmbH
org_2x9 · 24 members
SSOSCIM
LMLena MüllerAdmin
PDPauline DuboisDeveloper
ENErik NilssonMember
HOW A CUSTOMER LANDS

From signed contract to onboarded team.

01

Create the organization

One call or one click — the organization exists with you as its admin, isolated from every other tenant.

02

Invite the team, roles attached

Invitations carry a role. The member and their enforced permissions exist the moment they accept — nothing to sync afterwards.

03

Set the security policy

Turn on forced MFA, connect SSO through the API, and watch every change land in the organization’s audit trail.

BUILT FOR B2B

The controls a business account actually needs.

Invitations that create real members

An admin invites by email with a role attached — the member and their enforced role exist the moment the invite lands.

Security policy at the org level

Forced MFA is an organization policy with teeth: enrollment-only sessions until the user adds a factor, self-healing once they do.

Audit per organization

Every identity event in the organization — sign-ins, role changes, deletions — queryable and exportable, stored in your EU region.

Step-up-gated administration

Destructive org operations — deletions, policy changes, invitations — require the admin to re-prove their identity first.

WHERE THINGS STAND

Live today — and what ships after launch.

Organizations, members & invitations
Live today
Enforced admin / member roles
Live today
Org-forced MFA policy
Live today
SAML / OIDC connections through the API
Live today
Self-serve SSO portal for your customers
After launch
SCIM provisioning
Okta, Entra ID and the rest
After launch

The same rule as everywhere on this site: what is done says done, what is planned says planned.

Bring your users home to Europe.

Built and tested, in closed hardening before public launch. The waitlist gets access first.