> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise setup guide for AI assistants

> A plain-text version of the Enterprise admin starter kit, written for ChatGPT, Claude, and other AI assistants that walk an admin through Gumloop setup.

This page is the source an AI assistant should use to walk a new admin through setting up a Gumloop organization. The human-facing version is the [Enterprise admin starter kit](https://docs.gumloop.com/enterprise-features/onboarding). Each linked page also has a Markdown version: add `.md` to its URL.

## How to run the session

* Ask the admin's role first (IT admin, security, or department champion). Then ask the "Decisions" questions two or three at a time, with options to pick from.
* Propose a short numbered plan in the step order below, skipping anything the admin does not need.
* Guide one step at a time. For each step, give the direct settings link, what to choose (start from that step's Recommended setup and adjust it to their answers), and how to confirm it worked. Wait for the admin to confirm before moving on.
* Use only facts from this page and the linked Gumloop docs. Do not invent settings, UI labels, limits, prices, or timelines. If the docs do not cover something, say so and suggest the admin contact their Gumloop team or [support@gumloop.com](mailto:support@gumloop.com).
* Never ask for passwords, API keys, or other secrets. When setup is done, summarize what was configured so the admin can share it.
* Organization settings require the organization **Admin** role (some pages also allow **Security**).

## How Gumloop is organized

* **Organization:** company-wide settings, organization roles, Custom Roles, and policies.
* **Teams:** shared spaces for people who work together. Team members get User access to team agents by default.
* **Agents:** do the work. Owners maintain an agent; Users run it.
* **Connectors:** the apps an agent reaches, through each person's own account or a shared Team account.
* **Organization roles** (Admin, Manager, Security, Developer, Analytics, Member) grant administrative authority. **Custom Roles** control which apps, tools, scopes, models, and features each group can use, plus usage caps.

## Decisions

| Area | Ask the admin |
| - | - |
| Identity | Identity provider (Okta, Microsoft Entra ID, Google Workspace, JumpCloud, Ping Identity, or another SAML or OIDC provider). Is SSO required for the pilot? Is SCIM needed? Who are the setup admins? |
| Membership | Invite-only, or automatic joining for the company email domain? May chats and generated files be shared outside the organization? |
| Apps | Which apps will the pilot use? Any tools or scopes to restrict, such as Gmail read access without sending? Personal accounts or a shared Team account? |
| Models | Approved providers and models, hosting or retention requirements, and whether to use their own provider keys. |
| Guardrails | Actions to block, such as emails to external domains, and who approves access requests. |
| Security and legal | Does a security review need to finish first? Questionnaires, documents (for example SOC 2 report, subprocessor list, penetration test summary), DPA or MSA, and audit log or SIEM expectations. Start with the [Gumloop Trust Center](https://trust.gumloop.com). |
| Pilot | Department lead (champion), first useful task, kickoff date, and who joins the shared Slack channel with the Gumloop team. |

## Setup steps

### 1. General settings

Owner: IT admin. Settings: [https://www.gumloop.com/settings/organization/general](https://www.gumloop.com/settings/organization/general) (headed **Organization Overview**).

Recommended setup:

* Domain whitelisting: Add every company email domain so employees join without an invitation. Finish the default Custom Role (step 05) before you announce Gumloop.
* Default Team: Your pilot Team, once you create it in step 07.
* Approval assignees: Your IT admin for every request type.

Details:

* Review **Organization Name** and the **Organization ID** used for support.
* **Default Team:** where new members land, or **No default team**. Revisit after creating the pilot Team.
* **Domain whitelisting:** **Add domain** lets matching new users join automatically without an invitation. It does not enforce SSO, and removing a domain does not remove existing members. Enable new domains only after the default role, models, connector restrictions, and default Team are ready.
* **Approval assignees:** choose who handles **Feature access**, **Credit limits**, **Model access**, **App access**, and **Organization roles** requests.
* Done when: the admin knows where new members land and who approves requests.
* Docs: [https://docs.gumloop.com/core-concepts/teams](https://docs.gumloop.com/core-concepts/teams)

### 2. Setup administrators

Owner: IT admin. Settings: [https://www.gumloop.com/settings/organization/members](https://www.gumloop.com/settings/organization/members)

Recommended setup:

* Admin: Two or three IT admins, so setup never depends on one person.
* Security: Your security owner.
* Everyone else: Member only.

Details:

* In **Add Member to Organization**, enter **Email**, select **Roles**, then **Add**.
* Use **Admin** for organization setup and **Security** for security controls. Admin also covers billing and SSO, so keep that group small. Ordinary employees need neither.
* Done when: setup owners have accepted and can reach the settings they need.
* Docs: [https://docs.gumloop.com/core-concepts/organization\_user\_roles](https://docs.gumloop.com/core-concepts/organization_user_roles)

### 3. Models and defaults

Owner: IT admin or Security. Settings: [https://www.gumloop.com/settings/organization/models](https://www.gumloop.com/settings/organization/models) and [https://www.gumloop.com/settings/organization/agents](https://www.gumloop.com/settings/organization/agents)

Recommended setup:

* Restrict model access: On, with **Block Selected**.
* Blocked models: Only models your company does not allow, such as open-source models or specific providers. Leave everything else available.
* File Sharing Behavior: **Default**.

Details:

* Under **Restrictions**, turn on **Restrict model access**, then choose **Allow Only Selected** or **Block Selected**.
* Every model Gumloop serves runs under zero data retention except Anthropic's Claude Fable family, which keeps prompts and outputs for 30 days to check for misuse and does not train on them. **Allow non-zero data retention models** controls whether those models are available.
* In organization **Agents**, review the default **Model** and **File Sharing Behavior** for new agents. Defaults do not change existing agents.
* Custom Roles cannot allow a model blocked organization-wide. Provider keys and model proxies (**API Keys & Proxies**, [https://www.gumloop.com/settings/organization/api-keys](https://www.gumloop.com/settings/organization/api-keys)) are optional.
* Docs: [https://docs.gumloop.com/enterprise-features/ai\_model\_control](https://docs.gumloop.com/enterprise-features/ai_model_control) and [https://docs.gumloop.com/enterprise-features/agent\_default\_settings](https://docs.gumloop.com/enterprise-features/agent_default_settings)

### 4. Custom Roles

Owner: Security. Settings: [https://www.gumloop.com/settings/organization/groups](https://www.gumloop.com/settings/organization/groups)

Recommended setup:

* Default role: **Full access**, with the changes below.
* Features: Turn off **External chat sharing** and **External artifact sharing**. Turn on everything else.
* Usage Limits: Set **Concurrent Agent Limit** to 10, so one heavy user cannot hold up everyone else.
* Extra roles: Only for groups that need different access.

Details:

* Review the default role automatically assigned to new members. The first Custom Role becomes the default if none exists.
* **Create Role**, then choose **No access**, **Full access**, or **Start from template**. A **No access** role needs explicit grants.
* Review **Connectors**, **Models**, **Features**, and **Usage Limits**. In **Features**, review **Agent modification**, **External chat sharing**, **External artifact sharing**, and **Agent-owned credentials**.
* Common mistake: a stricter additional role does not override access allowed by another assigned role. Check the default and every additional role together.
* Docs: [https://docs.gumloop.com/enterprise-features/user\_groups](https://docs.gumloop.com/enterprise-features/user_groups)

### 5. Connector policies

Owner: Security. Settings: [https://www.gumloop.com/settings/organization/policies](https://www.gumloop.com/settings/organization/policies)

Recommended setup:

* Rules: Start with none. Add a rule only for a specific action to block, such as emails to external domains.
* Domain Restrictions: Require your company email domain for new connections.
* Claims: Claim your company's workspaces where available.

Details:

* Which apps each group can use was set in Custom Roles (step 4). Policies add optional company-wide rules on top. Allowing an app and connecting an account are separate steps.
* **Rules:** block or tag specific tool calls, for example block emails to external domains.
* **Domain Restrictions** (`?tab=domain-restrictions`): require corporate email domains for new OAuth connections. This is not the same as organization Domain whitelisting.
* **Claims** (`?tab=app-claims`): claim a provider workspace for the organization.
* Docs: [https://docs.gumloop.com/enterprise-features/app-policies/overview](https://docs.gumloop.com/enterprise-features/app-policies/overview), [https://docs.gumloop.com/enterprise-features/app-policies/app-rules](https://docs.gumloop.com/enterprise-features/app-policies/app-rules), [https://docs.gumloop.com/enterprise-features/app-policies/domain-restrictions](https://docs.gumloop.com/enterprise-features/app-policies/domain-restrictions), [https://docs.gumloop.com/enterprise-features/app-policies/app-claims](https://docs.gumloop.com/enterprise-features/app-policies/app-claims)

### 6. Teams and shared accounts

Owner: IT admin or champion. Settings: [https://www.gumloop.com/settings/organization/teams](https://www.gumloop.com/settings/organization/teams)

Recommended setup:

* Teams: One Team for the pilot department.
* Accounts: Personal accounts by default. A shared Team account only for shared sources, such as a team drive.

Details:

* Create one pilot Team: on the Home page, click **+** beside **Teams**, enter **Team Name**, then **Create**.
* Add a shared connector only if needed: expand the Team, open **Connectors**, find the approved app, and click **Add**.
* Use personal accounts when each person should act as themselves. Use a shared Team account only when everyone should have that account's access.
* Afterward, set the **Default Team** in General.
* Docs: [https://docs.gumloop.com/core-concepts/teams](https://docs.gumloop.com/core-concepts/teams) and [https://docs.gumloop.com/core-concepts/credentials](https://docs.gumloop.com/core-concepts/credentials)

### 7. SSO and provisioning

Owner: IT admin. Settings: [https://www.gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso) (**Identity Provider**)

Recommended setup:

* SSO: The identity provider your company already uses for other tools.
* SCIM: On if you offboard people through your identity provider.
* Before activating: Test a fresh sign-in with a non-admin account.

Details:

* If SSO is required, set it up before inviting the pilot. The IT setup group can join first.
* Follow the provider guide. For Okta OIDC, **Run test** must pass before activation, and every existing user who needs access must be assigned to the Okta app.
* Common mistake: activating SSO turns off Google and email sign-in for the SSO domains. Test a fresh sign-in first; staying signed in is not proof the next sign-in works.
* SCIM automates provisioning, offboarding, and role or Team mappings. Request enablement from support, and set mappings before syncing the wider group. SCIM runs through a SAML app even if sign-in uses OIDC, and removing someone's SAML app assignment can deactivate them in Gumloop.
* With OIDC sign-in, Gumloop matches an existing account by email on first sign-in.
* Docs: [https://docs.gumloop.com/enterprise-features/sso\_saml\_oidc\_scim](https://docs.gumloop.com/enterprise-features/sso_saml_oidc_scim), [https://docs.gumloop.com/enterprise-features/idp-guides/oidc-with-okta](https://docs.gumloop.com/enterprise-features/idp-guides/oidc-with-okta), [https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-okta](https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-okta), [https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-entra](https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-entra), [https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-google](https://docs.gumloop.com/enterprise-features/idp-guides/saml-with-google), [https://docs.gumloop.com/enterprise-features/idp-guides/scim-with-okta](https://docs.gumloop.com/enterprise-features/idp-guides/scim-with-okta), [https://docs.gumloop.com/enterprise-features/idp-guides/scim-with-entra](https://docs.gumloop.com/enterprise-features/idp-guides/scim-with-entra)

### 8. First agent

Owner: champion, with the IT admin.

Recommended setup:

* Who Can Use: **Team**.
* Owner: The department lead.
* Task Visibility: **Their tasks only**.
* Sensitive tools: **Ask for writes/deletes** on anything that sends or changes data.

Details:

* Invite the department lead from [https://www.gumloop.com/settings/organization/members](https://www.gumloop.com/settings/organization/members) with the pilot's Custom Roles and Team, so they can build the agent before the rest of the pilot joins.
* Agree on one useful first task with the department lead. Example for HR: answer handbook questions, cite the policy, and refer unanswered questions to HR, without accessing employee records.
* Create the agent from the pilot Team's **Agents** page and describe its job and boundaries.
* In **Connectors**, add the app that holds the approved sources. Choose **Use Personal Default** (each person's account) or **Use Team Default** (the shared account); a Team connection is not selected automatically. Deny unnecessary tools and use **Ask for writes/deletes** for sensitive ones.
* In Access, set **Who Can Use** to **Team**, add the lead as an **Owner**, and set **Task Visibility** to **Their tasks only** for the pilot (new team agents default to **Team tasks**). Review **File Sharing**, **Create Triggers**, and **Make a copy**, then **Save**.
* Owners can see every task on the agent, and authorized administrators keep administrative visibility. Instructions do not enforce data access, so restrict the account and tools too.
* Docs: [https://docs.gumloop.com/core-concepts/agents](https://docs.gumloop.com/core-concepts/agents), [https://docs.gumloop.com/core-concepts/agent\_access](https://docs.gumloop.com/core-concepts/agent_access), [https://docs.gumloop.com/core-concepts/credentials](https://docs.gumloop.com/core-concepts/credentials)

### 9. Pilot members

Owner: IT admin. Settings: [https://www.gumloop.com/settings/organization/members](https://www.gumloop.com/settings/organization/members)

Recommended setup:

* Pilot group: A small group from one department.
* Assignment: The pilot Team and the default Custom Role.

Details:

* Invite the pilot once the first agent works and sign-in is ready.
* In **Add Member to Organization**, enter **Email**, select **Custom Roles** and **Teams**, then **Add**. Every member has the baseline Member role.
* For someone already in the organization, right-click the Team and choose **Invite to Team**. If SCIM manages membership, check the identity provider assignment instead.
* Done when: a test member has the expected Team, Custom Roles, and model access. Do not test only as an Admin.

### 10. Test and expand

Owner: champion and IT admin.

Recommended setup:

* Testing: Use a non-admin account.
* Expanding: One team at a time, after the department lead signs off.

Details:

* Test as an ordinary member: sign-in lands in the right organization, Team, and roles; the approved model and intended account work; answers cite approved sources; unavailable data and unnecessary tools are blocked; Users cannot edit the agent or browse others' tasks.
* Review **Insights** ([https://www.gumloop.com/settings/organization/insights](https://www.gumloop.com/settings/organization/insights)) for adoption and spend, and **Audit Logging** ([https://www.gumloop.com/settings/organization/audit-logging](https://www.gumloop.com/settings/organization/audit-logging)) for administrative changes. Audit logs are available by API and can stream to S3, Datadog, or a custom endpoint.
* Share the agent link, supported tasks, and a contact person, then expand in stages.
* Docs: [https://docs.gumloop.com/enterprise-features/organization\_insights](https://docs.gumloop.com/enterprise-features/organization_insights) and [https://docs.gumloop.com/enterprise-features/audit\_logging](https://docs.gumloop.com/enterprise-features/audit_logging)

## Offboarding

Remove a member from the three-dot menu on [https://www.gumloop.com/settings/organization/members](https://www.gumloop.com/settings/organization/members), or let SCIM deprovision them. Their active triggers turn off; nothing else is deleted. Docs: [https://docs.gumloop.com/core-concepts/organization\_user\_roles](https://docs.gumloop.com/core-concepts/organization_user_roles)

## Optional controls

* Budgets: **Usage & Limits** ([https://www.gumloop.com/settings/organization/limits](https://www.gumloop.com/settings/organization/limits)) and [https://docs.gumloop.com/core-concepts/credits](https://docs.gumloop.com/core-concepts/credits)
* Shared agent guidance: [https://docs.gumloop.com/core-concepts/organization\_skills](https://docs.gumloop.com/core-concepts/organization_skills)
* Custom servers and private networks: [https://docs.gumloop.com/enterprise-features/hosted\_mcps](https://docs.gumloop.com/enterprise-features/hosted_mcps), [https://docs.gumloop.com/enterprise-features/proxied\_mcps](https://docs.gumloop.com/enterprise-features/proxied_mcps), [https://docs.gumloop.com/enterprise-features/managed\_tunnels](https://docs.gumloop.com/enterprise-features/managed_tunnels), [https://docs.gumloop.com/enterprise-features/static\_egress\_ips](https://docs.gumloop.com/enterprise-features/static_egress_ips)
* Exports and events: [https://docs.gumloop.com/enterprise-features/organization\_data\_export](https://docs.gumloop.com/enterprise-features/organization_data_export) and [https://docs.gumloop.com/enterprise-features/organization\_webhooks](https://docs.gumloop.com/enterprise-features/organization_webhooks)
* Slack and Microsoft Teams: [https://docs.gumloop.com/core-concepts/agents\_slack](https://docs.gumloop.com/core-concepts/agents_slack), [https://docs.gumloop.com/core-concepts/agents\_teams](https://docs.gumloop.com/core-concepts/agents_teams), [https://docs.gumloop.com/enterprise-features/slack\_agent\_access](https://docs.gumloop.com/enterprise-features/slack_agent_access)
* Full docs index: [https://docs.gumloop.com/llms.txt](https://docs.gumloop.com/llms.txt)
