Skip to main content
This page is the source an AI assistant should use to walk a new admin through setting up a Gumloop organization. The human-facing version is the Enterprise admin starter kit. Each linked page also has a Markdown version: add .md to its URL.

How to run the session

  • Ask the admin’s role first (IT admin, security, or department champion). Then ask the “Decisions” questions two or three at a time, with options to pick from.
  • Propose a short numbered plan in the step order below, skipping anything the admin does not need.
  • Guide one step at a time. For each step, give the direct settings link, what to choose (start from that step’s Recommended setup and adjust it to their answers), and how to confirm it worked. Wait for the admin to confirm before moving on.
  • Use only facts from this page and the linked Gumloop docs. Do not invent settings, UI labels, limits, prices, or timelines. If the docs do not cover something, say so and suggest the admin contact their Gumloop team or support@gumloop.com.
  • Never ask for passwords, API keys, or other secrets. When setup is done, summarize what was configured so the admin can share it.
  • Organization settings require the organization Admin role (some pages also allow Security).

How Gumloop is organized

  • Organization: company-wide settings, organization roles, Custom Roles, and policies.
  • Teams: shared spaces for people who work together. Team members get User access to team agents by default.
  • Agents: do the work. Owners maintain an agent; Users run it.
  • Connectors: the apps an agent reaches, through each person’s own account or a shared Team account.
  • Organization roles (Admin, Manager, Security, Developer, Analytics, Member) grant administrative authority. Custom Roles control which apps, tools, scopes, models, and features each group can use, plus usage caps.

Decisions

Setup steps

1. General settings

Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/general (headed Organization Overview). Recommended setup:
  • Domain whitelisting: Add every company email domain so employees join without an invitation. Finish the default Custom Role (step 05) before you announce Gumloop.
  • Default Team: Your pilot Team, once you create it in step 07.
  • Approval assignees: Your IT admin for every request type.
Details:
  • Review Organization Name and the Organization ID used for support.
  • Default Team: where new members land, or No default team. Revisit after creating the pilot Team.
  • Domain whitelisting: Add domain lets matching new users join automatically without an invitation. It does not enforce SSO, and removing a domain does not remove existing members. Enable new domains only after the default role, models, connector restrictions, and default Team are ready.
  • Approval assignees: choose who handles Feature access, Credit limits, Model access, App access, and Organization roles requests.
  • Done when: the admin knows where new members land and who approves requests.
  • Docs: https://docs.gumloop.com/core-concepts/teams

2. Setup administrators

Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/members Recommended setup:
  • Admin: Two or three IT admins, so setup never depends on one person.
  • Security: Your security owner.
  • Everyone else: Member only.
Details:
  • In Add Member to Organization, enter Email, select Roles, then Add.
  • Use Admin for organization setup and Security for security controls. Admin also covers billing and SSO, so keep that group small. Ordinary employees need neither.
  • Done when: setup owners have accepted and can reach the settings they need.
  • Docs: https://docs.gumloop.com/core-concepts/organization_user_roles

3. Models and defaults

Owner: IT admin or Security. Settings: https://www.gumloop.com/settings/organization/models and https://www.gumloop.com/settings/organization/agents Recommended setup:
  • Restrict model access: On, with Block Selected.
  • Blocked models: Only models your company does not allow, such as open-source models or specific providers. Leave everything else available.
  • File Sharing Behavior: Default.
Details:

4. Custom Roles

Owner: Security. Settings: https://www.gumloop.com/settings/organization/groups Recommended setup:
  • Default role: Full access, with the changes below.
  • Features: Turn off External chat sharing and External artifact sharing. Turn on everything else.
  • Usage Limits: Set Concurrent Agent Limit to 10, so one heavy user cannot hold up everyone else.
  • Extra roles: Only for groups that need different access.
Details:
  • Review the default role automatically assigned to new members. The first Custom Role becomes the default if none exists.
  • Create Role, then choose No access, Full access, or Start from template. A No access role needs explicit grants.
  • Review Connectors, Models, Features, and Usage Limits. In Features, review Agent modification, External chat sharing, External artifact sharing, and Agent-owned credentials.
  • Common mistake: a stricter additional role does not override access allowed by another assigned role. Check the default and every additional role together.
  • Docs: https://docs.gumloop.com/enterprise-features/user_groups

5. Connector policies

Owner: Security. Settings: https://www.gumloop.com/settings/organization/policies Recommended setup:
  • Rules: Start with none. Add a rule only for a specific action to block, such as emails to external domains.
  • Domain Restrictions: Require your company email domain for new connections.
  • Claims: Claim your company’s workspaces where available.
Details:

6. Teams and shared accounts

Owner: IT admin or champion. Settings: https://www.gumloop.com/settings/organization/teams Recommended setup:
  • Teams: One Team for the pilot department.
  • Accounts: Personal accounts by default. A shared Team account only for shared sources, such as a team drive.
Details:
  • Create one pilot Team: on the Home page, click + beside Teams, enter Team Name, then Create.
  • Add a shared connector only if needed: expand the Team, open Connectors, find the approved app, and click Add.
  • Use personal accounts when each person should act as themselves. Use a shared Team account only when everyone should have that account’s access.
  • Afterward, set the Default Team in General.
  • Docs: https://docs.gumloop.com/core-concepts/teams and https://docs.gumloop.com/core-concepts/credentials

7. SSO and provisioning

Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/sso (Identity Provider) Recommended setup:
  • SSO: The identity provider your company already uses for other tools.
  • SCIM: On if you offboard people through your identity provider.
  • Before activating: Test a fresh sign-in with a non-admin account.
Details:

8. First agent

Owner: champion, with the IT admin. Recommended setup:
  • Who Can Use: Team.
  • Owner: The department lead.
  • Task Visibility: Their tasks only.
  • Sensitive tools: Ask for writes/deletes on anything that sends or changes data.
Details:
  • Invite the department lead from https://www.gumloop.com/settings/organization/members with the pilot’s Custom Roles and Team, so they can build the agent before the rest of the pilot joins.
  • Agree on one useful first task with the department lead. Example for HR: answer handbook questions, cite the policy, and refer unanswered questions to HR, without accessing employee records.
  • Create the agent from the pilot Team’s Agents page and describe its job and boundaries.
  • In Connectors, add the app that holds the approved sources. Choose Use Personal Default (each person’s account) or Use Team Default (the shared account); a Team connection is not selected automatically. Deny unnecessary tools and use Ask for writes/deletes for sensitive ones.
  • In Access, set Who Can Use to Team, add the lead as an Owner, and set Task Visibility to Their tasks only for the pilot (new team agents default to Team tasks). Review File Sharing, Create Triggers, and Make a copy, then Save.
  • Owners can see every task on the agent, and authorized administrators keep administrative visibility. Instructions do not enforce data access, so restrict the account and tools too.
  • Docs: https://docs.gumloop.com/core-concepts/agents, https://docs.gumloop.com/core-concepts/agent_access, https://docs.gumloop.com/core-concepts/credentials

9. Pilot members

Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/members Recommended setup:
  • Pilot group: A small group from one department.
  • Assignment: The pilot Team and the default Custom Role.
Details:
  • Invite the pilot once the first agent works and sign-in is ready.
  • In Add Member to Organization, enter Email, select Custom Roles and Teams, then Add. Every member has the baseline Member role.
  • For someone already in the organization, right-click the Team and choose Invite to Team. If SCIM manages membership, check the identity provider assignment instead.
  • Done when: a test member has the expected Team, Custom Roles, and model access. Do not test only as an Admin.

10. Test and expand

Owner: champion and IT admin. Recommended setup:
  • Testing: Use a non-admin account.
  • Expanding: One team at a time, after the department lead signs off.
Details:

Offboarding

Remove a member from the three-dot menu on https://www.gumloop.com/settings/organization/members, or let SCIM deprovision them. Their active triggers turn off; nothing else is deleted. Docs: https://docs.gumloop.com/core-concepts/organization_user_roles

Optional controls