---
title: "Security"
description: "The Security page (Console → Your org → Security) has SSO and IP Access Rules surfaces for org owners and admins (plus the SotaAgents operations team when assisting you)."
url: "https://sotaagents.ai/manual/admin-console/security"
generated_by: "sotaagents-ldp"
docs_index: "https://sotaagents.ai/manual/llms.txt"
locale: "en"
---

# Security

The **Security** page (_Console → Your org → Security_) has SSO and IP Access Rules surfaces for org owners and admins (plus the SotaAgents operations team when assisting you).

### IP Access Rules

Add the trusted IPv4 CIDR ranges, then enable the organization IP policy. Once enabled, requests from an address outside every active rule are rejected with `ORG_IP_DENIED`. The workspace shell shows a persistent access-denied notice; use an allowed network or ask an administrator to correct the rules. Plan and role gates still apply.

> [!WARNING]
> Enterprise plan required
>
> Configuring or enforcing SSO requires an Enterprise Cloud subscription. You can still remove an existing provider or disable enforcement on any plan.

### SSO protocol

Choose between two protocols:

| Protocol | What to provide |
| --- | --- |
| OIDC | Issuer URL, Client ID, Client Secret. Optionally a custom Discovery Endpoint (defaults to `issuer/.well-known/openid-configuration`). Copy the _Callback URL_ shown on the form into your IdP's allowed redirect URIs. |
| SAML | IdP Entry Point URL, IdP Issuer, and the IdP certificate (PEM). Optionally paste the IdP metadata XML. Copy the _ACS URL_, _SP Entity ID_, and _SP Metadata URL_ shown on the form into your IdP. |

> [!NOTE]
> Secrets are write-only
>
> Client Secret (OIDC) and certificate (SAML) are never shown after saving — the form only displays whether one has been set. Re-enter the value to replace it.

### Email domains

Add the email domains your org uses (e.g. `company.com`). A domain must be verified before SSO enforcement can be enabled.

#### Verification methods

| Method | How it works |
| --- | --- |
| DNS TXT | A challenge token is generated when you add the domain. Create a DNS TXT record at `_sotaagents-sso-verify.<domain>` containing the token, then click _Verify DNS_. |
| Manual | The SotaAgents operations team reviews and approves or rejects the domain request. |

### Test SSO

Click **Test SSO** to start a real round-trip with the configured IdP. The result appears inline — the connection test must pass before enforcement can be turned on.

### Enforce SSO

The _Enforce SSO_ toggle requires members to authenticate through the configured IdP. It can only be enabled when:

- A provider has been saved.
- At least one domain is verified.
- The SSO connection test has passed for the current configuration.

> [!WARNING]
> Locked out?
>
> If enforcement is on and your IdP becomes misconfigured, contact support. The SotaAgents operations team can disable enforcement via a recovery endpoint to restore access.
