Administration covers how people get in and what they can do: sign-in methods and SSO, roles, teams, network restrictions, and organization-wide settings. Most of it needs the Org admin role.
Where to find it: Settings → Administration (Members, Teams, API Keys, Org Config). Login and SSO are configured by an Org admin from the same area.
- Login & Authentication — email/password and Google sign-in, enterprise SSO (Okta, Microsoft Entra ID, custom OIDC), SCIM provisioning, multiple email domains, and admin recovery.
- Roles and permissions — Org admin, Member, Read-only at the organization level; Team admin and Member at the team level.
- Custom Roles — when the three built-in roles aren't the right fit: build a role that grants exactly the permissions you pick, and assign it from the Members table.
- Teams — create and manage teams, and choose the emoji shown on a team's chip.
- IP Allowlisting — restrict access to your organization by IP range.
- Organization config — organization-wide settings such as shift-start lead time.
- Scope: Global vs team settings — the scope selector at the top of the Settings sidebar switches between organization-wide (Global) and per-team settings; it decides what you see and what you can edit.
Teams, members, and API keys are managed under Settings → Administration; API keys are documented under Developers.
Last reviewed: 2026-09-02 · Still stuck? Email [email protected]
Login & Authentication
Roles and permissions
Custom Roles
IP Allowlisting
Organization config
Global and team pages
Teams