.md to its URL.
How to run the session
- Ask the admin’s role first (IT admin, security, or department champion). Then ask the “Decisions” questions two or three at a time, with options to pick from.
- Propose a short numbered plan in the step order below, skipping anything the admin does not need.
- Guide one step at a time. For each step, give the direct settings link, what to choose (start from that step’s Recommended setup and adjust it to their answers), and how to confirm it worked. Wait for the admin to confirm before moving on.
- Use only facts from this page and the linked Gumloop docs. Do not invent settings, UI labels, limits, prices, or timelines. If the docs do not cover something, say so and suggest the admin contact their Gumloop team or support@gumloop.com.
- Never ask for passwords, API keys, or other secrets. When setup is done, summarize what was configured so the admin can share it.
- Organization settings require the organization Admin role (some pages also allow Security).
How Gumloop is organized
- Organization: company-wide settings, organization roles, Custom Roles, and policies.
- Teams: shared spaces for people who work together. Team members get User access to team agents by default.
- Agents: do the work. Owners maintain an agent; Users run it.
- Connectors: the apps an agent reaches, through each person’s own account or a shared Team account.
- Organization roles (Admin, Manager, Security, Developer, Analytics, Member) grant administrative authority. Custom Roles control which apps, tools, scopes, models, and features each group can use, plus usage caps.
Decisions
Setup steps
1. General settings
Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/general (headed Organization Overview). Recommended setup:- Domain whitelisting: Add every company email domain so employees join without an invitation. Finish the default Custom Role (step 05) before you announce Gumloop.
- Default Team: Your pilot Team, once you create it in step 07.
- Approval assignees: Your IT admin for every request type.
- Review Organization Name and the Organization ID used for support.
- Default Team: where new members land, or No default team. Revisit after creating the pilot Team.
- Domain whitelisting: Add domain lets matching new users join automatically without an invitation. It does not enforce SSO, and removing a domain does not remove existing members. Enable new domains only after the default role, models, connector restrictions, and default Team are ready.
- Approval assignees: choose who handles Feature access, Credit limits, Model access, App access, and Organization roles requests.
- Done when: the admin knows where new members land and who approves requests.
- Docs: https://docs.gumloop.com/core-concepts/teams
2. Setup administrators
Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/members Recommended setup:- Admin: Two or three IT admins, so setup never depends on one person.
- Security: Your security owner.
- Everyone else: Member only.
- In Add Member to Organization, enter Email, select Roles, then Add.
- Use Admin for organization setup and Security for security controls. Admin also covers billing and SSO, so keep that group small. Ordinary employees need neither.
- Done when: setup owners have accepted and can reach the settings they need.
- Docs: https://docs.gumloop.com/core-concepts/organization_user_roles
3. Models and defaults
Owner: IT admin or Security. Settings: https://www.gumloop.com/settings/organization/models and https://www.gumloop.com/settings/organization/agents Recommended setup:- Restrict model access: On, with Block Selected.
- Blocked models: Only models your company does not allow, such as open-source models or specific providers. Leave everything else available.
- File Sharing Behavior: Default.
- Under Restrictions, turn on Restrict model access, then choose Allow Only Selected or Block Selected.
- Every model Gumloop serves runs under zero data retention except Anthropic’s Claude Fable family, which keeps prompts and outputs for 30 days to check for misuse and does not train on them. Allow non-zero data retention models controls whether those models are available.
- In organization Agents, review the default Model and File Sharing Behavior for new agents. Defaults do not change existing agents.
- Custom Roles cannot allow a model blocked organization-wide. Provider keys and model proxies (API Keys & Proxies, https://www.gumloop.com/settings/organization/api-keys) are optional.
- Docs: https://docs.gumloop.com/enterprise-features/ai_model_control and https://docs.gumloop.com/enterprise-features/agent_default_settings
4. Custom Roles
Owner: Security. Settings: https://www.gumloop.com/settings/organization/groups Recommended setup:- Default role: Full access, with the changes below.
- Features: Turn off External chat sharing and External artifact sharing. Turn on everything else.
- Usage Limits: Set Concurrent Agent Limit to 10, so one heavy user cannot hold up everyone else.
- Extra roles: Only for groups that need different access.
- Review the default role automatically assigned to new members. The first Custom Role becomes the default if none exists.
- Create Role, then choose No access, Full access, or Start from template. A No access role needs explicit grants.
- Review Connectors, Models, Features, and Usage Limits. In Features, review Agent modification, External chat sharing, External artifact sharing, and Agent-owned credentials.
- Common mistake: a stricter additional role does not override access allowed by another assigned role. Check the default and every additional role together.
- Docs: https://docs.gumloop.com/enterprise-features/user_groups
5. Connector policies
Owner: Security. Settings: https://www.gumloop.com/settings/organization/policies Recommended setup:- Rules: Start with none. Add a rule only for a specific action to block, such as emails to external domains.
- Domain Restrictions: Require your company email domain for new connections.
- Claims: Claim your company’s workspaces where available.
- Which apps each group can use was set in Custom Roles (step 4). Policies add optional company-wide rules on top. Allowing an app and connecting an account are separate steps.
- Rules: block or tag specific tool calls, for example block emails to external domains.
- Domain Restrictions (
?tab=domain-restrictions): require corporate email domains for new OAuth connections. This is not the same as organization Domain whitelisting. - Claims (
?tab=app-claims): claim a provider workspace for the organization. - Docs: https://docs.gumloop.com/enterprise-features/app-policies/overview, https://docs.gumloop.com/enterprise-features/app-policies/app-rules, https://docs.gumloop.com/enterprise-features/app-policies/domain-restrictions, https://docs.gumloop.com/enterprise-features/app-policies/app-claims
6. Teams and shared accounts
Owner: IT admin or champion. Settings: https://www.gumloop.com/settings/organization/teams Recommended setup:- Teams: One Team for the pilot department.
- Accounts: Personal accounts by default. A shared Team account only for shared sources, such as a team drive.
- Create one pilot Team: on the Home page, click + beside Teams, enter Team Name, then Create.
- Add a shared connector only if needed: expand the Team, open Connectors, find the approved app, and click Add.
- Use personal accounts when each person should act as themselves. Use a shared Team account only when everyone should have that account’s access.
- Afterward, set the Default Team in General.
- Docs: https://docs.gumloop.com/core-concepts/teams and https://docs.gumloop.com/core-concepts/credentials
7. SSO and provisioning
Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/sso (Identity Provider) Recommended setup:- SSO: The identity provider your company already uses for other tools.
- SCIM: On if you offboard people through your identity provider.
- Before activating: Test a fresh sign-in with a non-admin account.
- If SSO is required, set it up before inviting the pilot. The IT setup group can join first.
- Follow the provider guide. For Okta OIDC, Run test must pass before activation, and every existing user who needs access must be assigned to the Okta app.
- Common mistake: activating SSO turns off Google and email sign-in for the SSO domains. Test a fresh sign-in first; staying signed in is not proof the next sign-in works.
- SCIM automates provisioning, offboarding, and role or Team mappings. Request enablement from support, and set mappings before syncing the wider group. SCIM runs through a SAML app even if sign-in uses OIDC, and removing someone’s SAML app assignment can deactivate them in Gumloop.
- With OIDC sign-in, Gumloop matches an existing account by email on first sign-in.
- Docs: https://docs.gumloop.com/enterprise-features/sso_saml_oidc_scim, https://docs.gumloop.com/enterprise-features/idp-guides/oidc-with-okta, https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-okta, https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-entra, https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-google, https://docs.gumloop.com/enterprise-features/idp-guides/scim-with-okta, https://docs.gumloop.com/enterprise-features/idp-guides/scim-with-entra
8. First agent
Owner: champion, with the IT admin. Recommended setup:- Who Can Use: Team.
- Owner: The department lead.
- Task Visibility: Their tasks only.
- Sensitive tools: Ask for writes/deletes on anything that sends or changes data.
- Invite the department lead from https://www.gumloop.com/settings/organization/members with the pilot’s Custom Roles and Team, so they can build the agent before the rest of the pilot joins.
- Agree on one useful first task with the department lead. Example for HR: answer handbook questions, cite the policy, and refer unanswered questions to HR, without accessing employee records.
- Create the agent from the pilot Team’s Agents page and describe its job and boundaries.
- In Connectors, add the app that holds the approved sources. Choose Use Personal Default (each person’s account) or Use Team Default (the shared account); a Team connection is not selected automatically. Deny unnecessary tools and use Ask for writes/deletes for sensitive ones.
- In Access, set Who Can Use to Team, add the lead as an Owner, and set Task Visibility to Their tasks only for the pilot (new team agents default to Team tasks). Review File Sharing, Create Triggers, and Make a copy, then Save.
- Owners can see every task on the agent, and authorized administrators keep administrative visibility. Instructions do not enforce data access, so restrict the account and tools too.
- Docs: https://docs.gumloop.com/core-concepts/agents, https://docs.gumloop.com/core-concepts/agent_access, https://docs.gumloop.com/core-concepts/credentials
9. Pilot members
Owner: IT admin. Settings: https://www.gumloop.com/settings/organization/members Recommended setup:- Pilot group: A small group from one department.
- Assignment: The pilot Team and the default Custom Role.
- Invite the pilot once the first agent works and sign-in is ready.
- In Add Member to Organization, enter Email, select Custom Roles and Teams, then Add. Every member has the baseline Member role.
- For someone already in the organization, right-click the Team and choose Invite to Team. If SCIM manages membership, check the identity provider assignment instead.
- Done when: a test member has the expected Team, Custom Roles, and model access. Do not test only as an Admin.
10. Test and expand
Owner: champion and IT admin. Recommended setup:- Testing: Use a non-admin account.
- Expanding: One team at a time, after the department lead signs off.
- Test as an ordinary member: sign-in lands in the right organization, Team, and roles; the approved model and intended account work; answers cite approved sources; unavailable data and unnecessary tools are blocked; Users cannot edit the agent or browse others’ tasks.
- Review Insights (https://www.gumloop.com/settings/organization/insights) for adoption and spend, and Audit Logging (https://www.gumloop.com/settings/organization/audit-logging) for administrative changes. Audit logs are available by API and can stream to S3, Datadog, or a custom endpoint.
- Share the agent link, supported tasks, and a contact person, then expand in stages.
- Docs: https://docs.gumloop.com/enterprise-features/organization_insights and https://docs.gumloop.com/enterprise-features/audit_logging
Offboarding
Remove a member from the three-dot menu on https://www.gumloop.com/settings/organization/members, or let SCIM deprovision them. Their active triggers turn off; nothing else is deleted. Docs: https://docs.gumloop.com/core-concepts/organization_user_rolesOptional controls
- Budgets: Usage & Limits (https://www.gumloop.com/settings/organization/limits) and https://docs.gumloop.com/core-concepts/credits
- Shared agent guidance: https://docs.gumloop.com/core-concepts/organization_skills
- Custom servers and private networks: https://docs.gumloop.com/enterprise-features/hosted_mcps, https://docs.gumloop.com/enterprise-features/proxied_mcps, https://docs.gumloop.com/enterprise-features/managed_tunnels, https://docs.gumloop.com/enterprise-features/static_egress_ips
- Exports and events: https://docs.gumloop.com/enterprise-features/organization_data_export and https://docs.gumloop.com/enterprise-features/organization_webhooks
- Slack and Microsoft Teams: https://docs.gumloop.com/core-concepts/agents_slack, https://docs.gumloop.com/core-concepts/agents_teams, https://docs.gumloop.com/enterprise-features/slack_agent_access
- Full docs index: https://docs.gumloop.com/llms.txt
