Documentation
Open app

Security

On this page

The Security page (Console → Your org → Security) has SSO and IP Access Rules surfaces for org owners and admins (plus the SotaAgents operations team when assisting you).

IP Access Rules#

Add the trusted IPv4 CIDR ranges, then enable the organization IP policy. Once enabled, requests from an address outside every active rule are rejected with ORG_IP_DENIED. The workspace shell shows a persistent access-denied notice; use an allowed network or ask an administrator to correct the rules. Plan and role gates still apply.

Enterprise plan required

Configuring or enforcing SSO requires an Enterprise Cloud subscription. You can still remove an existing provider or disable enforcement on any plan.

SSO protocol#

Choose between two protocols:

ProtocolWhat to provide
OIDCIssuer URL, Client ID, Client Secret. Optionally a custom Discovery Endpoint (defaults to issuer/.well-known/openid-configuration). Copy the Callback URL shown on the form into your IdP's allowed redirect URIs.
SAMLIdP Entry Point URL, IdP Issuer, and the IdP certificate (PEM). Optionally paste the IdP metadata XML. Copy the ACS URL, SP Entity ID, and SP Metadata URL shown on the form into your IdP.
Secrets are write-only

Client Secret (OIDC) and certificate (SAML) are never shown after saving — the form only displays whether one has been set. Re-enter the value to replace it.

Email domains#

Add the email domains your org uses (e.g. company.com). A domain must be verified before SSO enforcement can be enabled.

Verification methods

MethodHow it works
DNS TXTA challenge token is generated when you add the domain. Create a DNS TXT record at _sotaagents-sso-verify.<domain> containing the token, then click Verify DNS.
ManualThe SotaAgents operations team reviews and approves or rejects the domain request.

Test SSO#

Click Test SSO to start a real round-trip with the configured IdP. The result appears inline — the connection test must pass before enforcement can be turned on.

Enforce SSO#

The Enforce SSO toggle requires members to authenticate through the configured IdP. It can only be enabled when:

  • A provider has been saved.
  • At least one domain is verified.
  • The SSO connection test has passed for the current configuration.
Locked out?

If enforcement is on and your IdP becomes misconfigured, contact support. The SotaAgents operations team can disable enforcement via a recovery endpoint to restore access.

Contents

Esc

Search titles and body text across every chapter.