> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise admin starter kit

export const AiWalkthrough = () => {
  const guide = 'https://docs.gumloop.com/enterprise-features/onboarding-ai-guide';
  const prompt = ['Help me set up Gumloop for my company. I am an admin and new to Gumloop.', '', 'Read this setup guide first. Use it and the Gumloop docs it links to as your only source: ' + guide, 'If you cannot open it, say so and I will paste it. Never guess settings, UI labels, or limits. If the docs do not cover something, say so and point me to support@gumloop.com.', '', 'How to guide me:', '1. Ask my role (IT admin, security, or department champion), then the guide\'s Decisions questions, two or three at a time, with options I can pick from.', '2. Turn my answers into a short numbered plan in the guide\'s step order. Skip what we do not need.', '3. Take one step at a time: why it matters in one line, the direct settings link, what to choose (start from the guide\'s Recommended setup and adapt it to my answers), and how to confirm it worked. Wait for me to say done.', '4. Warn me before common mistakes: SSO lockout, a stricter Custom Role not overriding a permissive one, and testing only as an Admin.', '5. Never ask for passwords or API keys. When we finish, give me a summary of what we set up to share with my team.'].join('\n');
  const query = encodeURIComponent(prompt);
  const [open, setOpen] = useState(false);
  const [copied, setCopied] = useState(false);
  useEffect(() => {
    if (!open) return;
    const close = event => {
      if (!event.target.closest || !event.target.closest('.es-ai')) setOpen(false);
    };
    const esc = event => {
      if (event.key === 'Escape') setOpen(false);
    };
    document.addEventListener('click', close);
    document.addEventListener('keydown', esc);
    return () => {
      document.removeEventListener('click', close);
      document.removeEventListener('keydown', esc);
    };
  }, [open]);
  const copy = async () => {
    let text = prompt;
    try {
      const response = await fetch('/enterprise-features/onboarding-ai-guide.md');
      if (response.ok) text = prompt + '\n\n---\n\n' + await response.text();
    } catch (_) {}
    try {
      await navigator.clipboard.writeText(text);
      setCopied(true);
      setTimeout(() => setCopied(false), 2000);
    } catch (_) {}
  };
  const item = (href, icon, label, note) => <a className="es-ai-item" role="menuitem" href={href} target="_blank" rel="noopener noreferrer" onClick={() => setOpen(false)}>
      {icon}<span className="es-ai-item-text"><span className="es-ai-item-label">{label}</span><span className="es-ai-item-note">{note}</span></span>
    </a>;
  return <div className="es-ai">
      <button type="button" className="es-btn es-btn-secondary" aria-haspopup="menu" aria-expanded={open} onClick={() => setOpen(!open)}>
        Set up with AI
        <svg className="es-ai-chevron" viewBox="0 0 24 24" aria-hidden="true"><path d="m6 9 6 6 6-6" /></svg>
      </button>
      {open && <div className="es-ai-menu" role="menu">
          <p className="es-ai-menu-intro">An assistant reads this guide and walks you through setup, one step at a time.</p>
          {item('https://chatgpt.com/?hints=search&q=' + query, <svg className="es-ai-logo" viewBox="0 0 24 24" aria-hidden="true"><path d="M22.2819 9.8211a5.9847 5.9847 0 0 0-.5157-4.9108 6.0462 6.0462 0 0 0-6.5098-2.9A6.0651 6.0651 0 0 0 4.9807 4.1818a5.9847 5.9847 0 0 0-3.9977 2.9 6.0462 6.0462 0 0 0 .7427 7.0966 5.98 5.98 0 0 0 .511 4.9107 6.051 6.051 0 0 0 6.5146 2.9001A5.9847 5.9847 0 0 0 13.2599 24a6.0557 6.0557 0 0 0 5.7718-4.2058 5.9894 5.9894 0 0 0 3.9977-2.9001 6.0557 6.0557 0 0 0-.7475-7.0729zm-9.022 12.6081a4.4755 4.4755 0 0 1-2.8764-1.0408l.1419-.0804 4.7783-2.7582a.7948.7948 0 0 0 .3927-.6813v-6.7369l2.02 1.1686a.071.071 0 0 1 .038.052v5.5826a4.504 4.504 0 0 1-4.4945 4.4944zm-9.6607-4.1254a4.4708 4.4708 0 0 1-.5346-3.0137l.142.0852 4.783 2.7582a.7712.7712 0 0 0 .7806 0l5.8428-3.3685v2.3324a.0804.0804 0 0 1-.0332.0615L9.74 19.9502a4.4992 4.4992 0 0 1-6.1408-1.6464zM2.3408 7.8956a4.485 4.485 0 0 1 2.3655-1.9728V11.6a.7664.7664 0 0 0 .3879.6765l5.8144 3.3543-2.0201 1.1685a.0757.0757 0 0 1-.071 0l-4.8303-2.7865A4.504 4.504 0 0 1 2.3408 7.872zm16.5963 3.8558L13.1038 8.364 15.1192 7.2a.0757.0757 0 0 1 .071 0l4.8303 2.7913a4.4944 4.4944 0 0 1-.6765 8.1042v-5.6772a.79.79 0 0 0-.407-.667zm2.0107-3.0231l-.142-.0852-4.7735-2.7818a.7759.7759 0 0 0-.7854 0L9.409 9.2297V6.8974a.0662.0662 0 0 1 .0284-.0615l4.8303-2.7866a4.4992 4.4992 0 0 1 6.6802 4.66zM8.3065 12.863l-2.02-1.1638a.0804.0804 0 0 1-.038-.0567V6.0742a4.4992 4.4992 0 0 1 7.3757-3.4537l-.142.0805L8.704 5.459a.7948.7948 0 0 0-.3927.6813zm1.0976-2.3654l2.602-1.4998 2.6069 1.4998v2.9994l-2.5974 1.4997-2.6067-1.4997Z" /></svg>, 'Open in ChatGPT', 'Starts a guided chat')}
          {item('https://claude.ai/new?q=' + query, <svg className="es-ai-logo" viewBox="0 0 24 24" aria-hidden="true"><path d="m4.7144 15.9555 4.7174-2.6471.079-.2307-.079-.1275h-.2307l-.7893-.0486-2.6956-.0729-2.3375-.0971-2.2646-.1214-.5707-.1215-.5343-.7042.0546-.3522.4797-.3218.686.0608 1.5179.1032 2.2767.1578 1.6514.0972 2.4468.255h.3886l.0546-.1579-.1336-.0971-.1032-.0972L6.973 9.8356l-2.55-1.6879-1.3356-.9714-.7225-.4918-.3643-.4614-.1578-1.0078.6557-.7225.8803.0607.2246.0607.8925.686 1.9064 1.4754 2.4893 1.8336.3643.3035.1457-.1032.0182-.0728-.164-.2733-1.3539-2.4467-1.445-2.4893-.6435-1.032-.17-.6194c-.0607-.255-.1032-.4674-.1032-.7285L6.287.1335 6.6997 0l.9957.1336.419.3642.6192 1.4147 1.0018 2.2282 1.5543 3.0296.4553.8985.2429.8318.091.255h.1579v-.1457l.1275-1.706.2368-2.0947.2307-2.6957.0789-.7589.3764-.9107.7468-.4918.5828.2793.4797.686-.0668.4433-.2853 1.8517-.5586 2.9021-.3643 1.9429h.2125l.2429-.2429.9835-1.3053 1.6514-2.0643.7286-.8196.85-.9046.5464-.4311h1.0321l.759 1.1293-.34 1.1657-1.0625 1.3478-.8804 1.1414-1.2628 1.7-.7893 1.36.0729.1093.1882-.0183 2.8535-.607 1.5421-.2794 1.8396-.3157.8318.3886.091.3946-.3278.8075-1.967.4857-2.3072.4614-3.4364.8136-.0425.0304.0486.0607 1.5482.1457.6618.0364h1.621l3.0175.2247.7892.522.4736.6376-.079.4857-1.2142.6193-1.6393-.3886-3.825-.9107-1.3113-.3279h-.1822v.1093l1.0929 1.0686 2.0035 1.8092 2.5075 2.3314.1275.5768-.3218.4554-.34-.0486-2.2039-1.6575-.85-.7468-1.9246-1.621h-.1275v.17l.4432.6496 2.3436 3.5214.1214 1.0807-.17.3521-.6071.2125-.6679-.1214-1.3721-1.9246L14.38 17.959l-1.1414-1.9428-.1397.079-.674 7.2552-.3156.3703-.7286.2793-.6071-.4614-.3218-.7468.3218-1.4753.3886-1.9246.3157-1.53.2853-1.9004.17-.6314-.0121-.0425-.1397.0182-1.4328 1.9672-2.1796 2.9446-1.7243 1.8456-.4128.164-.7164-.3704.0667-.6618.4008-.5889 2.386-3.0357 1.4389-1.882.929-1.0868-.0062-.1579h-.0546l-6.3385 4.1164-1.1293.1457-.4857-.4554.0608-.7467.2307-.2429 1.9064-1.3114Z" /></svg>, 'Open in Claude', 'Starts a guided chat')}
          <button type="button" className="es-ai-item" role="menuitem" onClick={copy}>
            <svg className="es-ai-logo es-ai-stroke" viewBox="0 0 24 24" aria-hidden="true"><rect x="9" y="9" width="13" height="13" rx="2" /><path d="M5 15H4a2 2 0 0 1-2-2V4a2 2 0 0 1 2-2h9a2 2 0 0 1 2 2v1" /></svg>
            <span className="es-ai-item-text"><span className="es-ai-item-label">{copied ? 'Copied' : 'Copy prompt'}</span><span className="es-ai-item-note">Includes the full guide, for any AI</span></span>
          </button>
        </div>}
    </div>;
};

export const EnterpriseSetupChecklist = ({children}) => {
  const groups = [{
    title: 'Prepare the organization',
    steps: [{
      id: 'prepare',
      title: 'Before you start'
    }, {
      id: 'general',
      title: 'General settings'
    }, {
      id: 'administrators',
      title: 'Setup administrators'
    }, {
      id: 'models',
      title: 'Models and defaults'
    }, {
      id: 'roles',
      title: 'Custom Roles'
    }, {
      id: 'connectors',
      title: 'Connector policies'
    }]
  }, {
    title: 'Set up access',
    steps: [{
      id: 'teams',
      title: 'Teams and shared accounts'
    }, {
      id: 'identity',
      title: 'SSO and provisioning'
    }]
  }, {
    title: 'Launch the pilot',
    steps: [{
      id: 'agent',
      title: 'First agent'
    }, {
      id: 'members',
      title: 'Pilot members'
    }, {
      id: 'rollout',
      title: 'Test and expand'
    }]
  }];
  const extras = [{
    id: 'faq',
    title: 'FAQ'
  }, {
    id: 'advanced',
    title: 'Additional controls'
  }];
  const numbered = groups.reduce((all, group) => all.concat(group.steps), []);
  const steps = numbered.concat(extras);
  const pad = n => (n < 10 ? '0' : '') + n;
  const [active, setActive] = useState(0);
  const [full, setFull] = useState(false);
  const [ready, setReady] = useState(false);
  useEffect(() => {
    const reveal = hash => {
      if (!hash) return;
      const target = document.getElementById(hash);
      const chapter = target && target.closest ? target.closest('section.es-chapter') : null;
      const index = steps.findIndex(step => step.id === (chapter ? chapter.id : hash));
      if (index >= 0) {
        setActive(index);
        setFull(false);
      }
    };
    const syncHash = () => reveal(decodeURIComponent(window.location.hash.slice(1)));
    const followLink = event => {
      const link = event.target && event.target.closest ? event.target.closest('a[href^="#"]') : null;
      if (link) reveal(link.getAttribute('href').slice(1));
    };
    const onKey = event => {
      const tag = event.target && event.target.tagName || '';
      if (event.metaKey || event.ctrlKey || event.altKey || (/INPUT|TEXTAREA|SELECT/).test(tag) || event.target && event.target.isContentEditable) return;
      if (event.key === 'ArrowRight') setActive(index => {
        const next = Math.min(index + 1, steps.length - 1);
        try {
          window.history.replaceState(null, '', '#' + steps[next].id);
        } catch (_) {}
        return next;
      });
      if (event.key === 'ArrowLeft') setActive(index => {
        const prev = Math.max(index - 1, 0);
        try {
          window.history.replaceState(null, '', '#' + steps[prev].id);
        } catch (_) {}
        return prev;
      });
    };
    syncHash();
    window.addEventListener('hashchange', syncHash);
    window.addEventListener('keydown', onKey);
    document.addEventListener('click', followLink, true);
    setReady(true);
    return () => {
      window.removeEventListener('hashchange', syncHash);
      window.removeEventListener('keydown', onKey);
      document.removeEventListener('click', followLink, true);
      steps.forEach(step => {
        const el = document.getElementById(step.id);
        if (el) el.hidden = false;
      });
    };
  }, []);
  useEffect(() => {
    if (!ready) return;
    steps.forEach((step, index) => {
      const el = document.getElementById(step.id);
      if (el) el.hidden = !full && index !== active;
    });
  }, [active, full, ready]);
  const open = (index, scroll) => {
    setActive(index);
    setFull(false);
    try {
      window.history.replaceState(null, '', '#' + steps[index].id);
    } catch (_) {}
    if (scroll) {
      const panel = document.querySelector('.es-panel');
      if (panel) window.scrollTo({
        top: panel.getBoundingClientRect().top + window.scrollY - 120,
        behavior: 'smooth'
      });
    }
  };
  return <div className="es-guide">

      <nav className="es-rail" aria-label="Setup steps">
        <div className="es-rail-head">
          <span className="es-rail-title">Setup steps</span>
        </div>
        <div className="es-groups">
          {groups.map(group => <div className="es-group" key={group.title}>
              <p className="es-group-title">{group.title}</p>
              <ol>
                {group.steps.map(step => {
    const index = steps.findIndex(item => item.id === step.id);
    return <li key={step.id}>
                      <button type="button" className="es-step" aria-current={!full && ready && active === index ? 'step' : undefined} aria-controls={step.id} onClick={() => open(index, false)}>
                        <i aria-hidden="true">{pad(index + 1)}</i><span>{step.title}</span>
                      </button>
                    </li>;
  })}
              </ol>
            </div>)}
        </div>
        <div className="es-extra">
          <span className="es-extra-title">More help</span>
          {extras.map(item => {
    const index = steps.findIndex(step => step.id === item.id);
    return <button key={item.id} type="button" className="es-step es-step-inline" aria-current={!full && ready && active === index ? 'step' : undefined} aria-controls={item.id} onClick={() => open(index, false)}><span>{item.title}</span></button>;
  })}
        </div>
      </nav>

      <div className="es-panel" data-full={!ready || full ? 'true' : 'false'}>
        {children}
      </div>

      {ready && !full && <div className="es-foot">
          <span className="es-count">{active < numbered.length ? pad(active + 1) + ' / ' + pad(numbered.length) : 'More help'}</span>
          <div className="es-foot-actions">
            <button type="button" className="es-btn es-btn-secondary" disabled={active === 0} onClick={() => open(active - 1, true)}>Previous</button>
            {active < steps.length - 1 && <button type="button" className="es-btn es-btn-primary" onClick={() => open(active + 1, true)}>Next: {steps[active + 1].title}</button>}
          </div>
        </div>}
    </div>;
};

<div className="es-page prose prose-gray dark:prose-invert max-w-none">
  <div className="es-hero">
    <h1 className="es-title">Enterprise admin starter kit</h1>

    <AiWalkthrough />
  </div>

  <p className="es-intro">Set up your Gumloop organization, welcome a small pilot, and help one department get a useful result from its first agent. Built for the IT admin, security owner, and department champion setting up Gumloop for the first time.</p>

  <p className="es-sr">AI assistants: a plain-text version of this guide with deep links is at [https://docs.gumloop.com/enterprise-features/onboarding-ai-guide](https://docs.gumloop.com/enterprise-features/onboarding-ai-guide)</p>

  <div id="enterprise-guide">
    <EnterpriseSetupChecklist>
      <section id="prepare" data-index="01" data-title="Before you start" className="es-chapter">
        <span className="es-owner">Everyone</span>

        ## What should I decide before setup?

        <p className="es-dek">Decide these or have them handy. Anything open can wait for your setup call.</p>

        <div className="es-map" aria-label="How Gumloop is organized">
          <div className="es-map-item"><span className="es-map-title">Organization</span><span className="es-map-text">Company settings, roles, and policies</span></div>
          <div className="es-map-item"><span className="es-map-title">Teams</span><span className="es-map-text">Shared spaces for people who work together</span></div>
          <div className="es-map-item"><span className="es-map-title">Agents</span><span className="es-map-text">Do the work, with Owners who maintain them</span></div>
          <div className="es-map-item"><span className="es-map-title">Connectors</span><span className="es-map-text">The apps agents reach, through a personal or shared account</span></div>
        </div>

        | Area | Have ready |
        | - | - |
        | [Identity](#identity) | Identity provider, whether the pilot needs SSO or SCIM, and your setup admins |
        | [Membership](#general) | Invite-only or domain auto-join, and whether chats and files can be shared externally |
        | [Apps](#connectors) | Pilot apps, tools or scopes to restrict, and personal or shared Team accounts |
        | [Models](#models) | Approved models, retention needs, and whether to use your own provider keys |
        | [Guardrails](#connectors) | Actions to block and who approves access requests |
        | Security and legal | Security review, questionnaires, DPA or MSA, and audit log needs |
        | [Pilot](#agent) | Department lead, first task, kickoff date, and shared Slack channel members |

        <div className="es-more">
          **Learn more**

          [Gumloop Trust Center](https://trust.gumloop.com)

          [AI Model Governance & Configuration](/enterprise-features/ai_model_control)

          [App Rules](/enterprise-features/app-policies/app-rules)
        </div>
      </section>

      <section id="general" data-index="02" data-title="General settings" className="es-chapter">
        <span className="es-owner">IT admin</span>

        ## What should I review in General settings?

        <p className="es-dek">Decide where new members land and who approves their requests.</p>

        <div className="es-rec">
          **Recommended setup**

          **Domain whitelisting:** Add every company email domain so employees join without an invitation. Finish the default Custom Role (step 05) before you announce Gumloop.

          **Default Team:** Your pilot Team, once you create it in step 07.

          **Approval assignees:** Your IT admin for every request type.
        </div>

        Open organization [**General**](https://www.gumloop.com/settings/organization/general), headed **Organization Overview**, and review the existing setup before adding members.

        <Steps>
          <Step title="Check Configuration">
            Review **Organization Name** and the copyable **Organization ID** used for support. For **Default Team**, choose where new members should land, or **No default team**. Revisit this after creating the pilot Team.
          </Step>

          <Step title="Review Domain whitelisting">
            Check domains already listed. **Add domain** lets matching new users automatically join without an invitation. Review this now, but prepare your default role, model access, connector restrictions, and default Team before enabling new auto-join domains.

            <Frame caption="Domain whitelisting is separate from SSO. The pictured domain belongs to the test organization.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/general-domain-whitelisting.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=f7ed0f2669a313c6bf48f418a5e0ec73" alt="Domain whitelisting section with Add domain, a test domain, and automatic membership explanation" width="1784" height="414" data-path="images/enterprise-features/onboarding/general-domain-whitelisting.png" />
            </Frame>
          </Step>

          <Step title="Name the approval owners">
            Review **Approval assignees** for **Feature access**, **Credit limits**, **Model access**, **App access**, and **Organization roles**. Decide who should receive each kind of access request.

            <Frame caption="Choose who handles each type of access request.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/general-approval-assignees.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=bc5d32470044c4762b17acee7795fd53" alt="Approval assignees for feature access, credit limits, model access, app access, and organization roles" width="1792" height="682" data-path="images/enterprise-features/onboarding/general-approval-assignees.png" />
            </Frame>
          </Step>
        </Steps>

        <Warning>
          Domain whitelisting lets matching new users join automatically. It does not enforce SSO, and removing a domain does not remove existing members.
        </Warning>

        **Done when:** you know where new members land and who approves their requests. Optional General settings, such as artifact domains and Slack service accounts, are in [Additional controls](#advanced).

        <div className="es-more">
          **Learn more**

          [Organization and Teams](/core-concepts/teams#setting-a-default-team)

          [User Roles](/core-concepts/organization_user_roles)
        </div>
      </section>

      <section id="administrators" data-index="03" data-title="Setup administrators" className="es-chapter">
        <span className="es-owner">IT admin</span>

        ## Who should help with setup?

        <p className="es-dek">Give IT the authority to configure the pilot without making every employee an admin.</p>

        <div className="es-rec">
          **Recommended setup**

          **Admin:** Two or three IT admins, so setup never depends on one person.

          **Security:** Your security owner.

          **Everyone else:** Member only.
        </div>

        Invite only the people who need to configure the organization at this stage. Invite the wider pilot after the access policies are ready.

        <Steps>
          <Step title="Add your IT setup owners">
            Open organization [**Members**](https://www.gumloop.com/settings/organization/members). In **Add Member to Organization**, enter **Email**, select the necessary **Roles**, then click **Add**.
          </Step>

          <Step title="Delegate only the authority needed">
            Use **Admin** for organization setup and **Security** for security controls. Admin also covers billing and SSO, so keep that group small.
          </Step>
        </Steps>

        **Done when:** your setup owners have accepted their invitations and can reach the settings they need. Skip this section if the required owners already have access.

        <div className="es-more">
          **Learn more**

          [User Roles](/core-concepts/organization_user_roles)
        </div>
      </section>

      <section id="models" data-index="04" data-title="Models and defaults" className="es-chapter">
        <span className="es-owner">IT admin · Security</span>

        ## Which models and defaults should I approve?

        <p className="es-dek">Pick the approved models before anyone starts using agents.</p>

        <div className="es-rec">
          **Recommended setup**

          **Restrict model access:** On, with **Block Selected**.

          **Blocked models:** Only models your company does not allow, such as open-source models or specific providers. Leave everything else available.

          **File Sharing Behavior:** **Default**.
        </div>

        Set model policy before inviting the pilot, and review agent defaults before anyone creates the first agent.

        <Steps>
          <Step title="Approve the organization's models">
            Open organization [**Models**](https://www.gumloop.com/settings/organization/models). Under **Restrictions**, turn on **Restrict model access** and choose **Allow Only Selected** for an approved list, or **Block Selected** for specific exclusions.

            <Frame caption="Review model access and retention controls before selecting the approved models.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/models-overview.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=b90a06b75e2f0f9203471c6f58198c1c" alt="Models Restrictions page showing Restrict model access and non-zero data retention controls" width="1794" height="560" data-path="images/enterprise-features/onboarding/models-overview.png" />
            </Frame>
          </Step>

          <Step title="Review new-agent defaults">
            Open organization [**Agents**](https://www.gumloop.com/settings/organization/agents). Review **Model** and **File Sharing Behavior**. **Default** inherits chat and agent permissions; **Organization** shares generated files across the organization.

            <Frame caption="New-agent defaults and file-sharing behavior are configured separately from model restrictions.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/agent-defaults.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=9affc52014eef1e4a349b94d7cdc4fb4" alt="Organization Agents settings with model selection and File Sharing Behavior" width="1808" height="1020" data-path="images/enterprise-features/onboarding/agent-defaults.png" />
            </Frame>
          </Step>
        </Steps>

        **Done when:** the default model is allowed. Agent defaults do not change existing agents. Custom Roles cannot allow a model blocked organization-wide.

        Provider keys and model proxies are optional, not prerequisites.

        <div className="es-more">
          **Learn more**

          [AI Model Governance & Configuration](/enterprise-features/ai_model_control)

          [Agent Default Settings](/enterprise-features/agent_default_settings)
        </div>
      </section>

      <section id="roles" data-index="05" data-title="Custom Roles" className="es-chapter">
        <span className="es-owner">Security</span>

        ## How should I prepare Custom Roles?

        <p className="es-dek">Separate the people building agents from the people using them, without piling on unnecessary roles.</p>

        <div className="es-rec">
          **Recommended setup**

          **Default role:** **Full access**, with the changes below.

          **Features:** Turn off **External chat sharing** and **External artifact sharing**. Turn on everything else.

          **Usage Limits:** Set **Concurrent Agent Limit** to 10, so one heavy user cannot hold up everyone else.

          **Extra roles:** Only for groups that need different access.
        </div>

        Prepare the default role before new employees join. Organization roles grant administrative authority; Custom Roles control connector, model, feature, and usage restrictions.

        <Steps>
          <Step title="Review the existing default">
            Open organization [**Custom Roles**](https://www.gumloop.com/settings/organization/groups). Review the role automatically assigned to new members. Keep it if it already meets your requirements.
          </Step>

          <Step title="Create a role only when needed">
            Click **Create Role**. Choose **No access**, **Full access**, or **Start from template**, then **Next**. Enter **Role name**, then **Confirm**.

            <Frame caption="Choose a starting policy. No access is not ready until you grant the required capabilities.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/custom-role-starter.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=72c68d60a4d3889e1f6f265a6df65b86" alt="Create Custom Role dialog showing No access, Full access, Start from template, and Next" style={{ maxWidth: '560px', margin: '0 auto' }} width="1024" height="728" data-path="images/enterprise-features/onboarding/custom-role-starter.png" />
            </Frame>
          </Step>

          <Step title="Grant the pilot's required access">
            Review **Connectors** (which apps, tools, and scopes the group can use), **Models**, **Features**, and **Usage Limits**. A **No access** role needs explicit grants before members can use it. Review **Agent modification** for the department lead creating the agent.
          </Step>
        </Steps>

        <Warning>
          A stricter role does not override access allowed by another assigned role. Check the default and every additional role together. The first Custom Role becomes the default if none exists.
        </Warning>

        Review **External chat sharing**, **External artifact sharing**, and **Agent-owned credentials** in **Features** when the pilot needs restrictions on external access or shared-account use. An agent's own access and file-sharing settings still need a separate review.

        **Done when:** the default is ready for new members. Assign additional roles through the role's **Users** tab or the member invitation dialog.

        <div className="es-more">
          **Learn more**

          [Custom Roles](/enterprise-features/user_groups)
        </div>
      </section>

      <section id="connectors" data-index="06" data-title="Connector policies" className="es-chapter">
        <span className="es-owner">Security</span>

        ## How do I approve connectors?

        <p className="es-dek">Decide which apps the pilot can use and what agents may do in them.</p>

        <div className="es-rec">
          **Recommended setup**

          **Rules:** Start with none. Add a rule only for a specific action to block, such as emails to external domains.

          **Domain Restrictions:** Require your company email domain for new connections.

          **Claims:** Claim your company's workspaces where available.
        </div>

        You chose which apps each group can use in [Custom Roles](#roles). **Policies** add optional company-wide rules on top. Allowing an app and connecting an account are separate steps.

        Use organization [**Policies**](https://www.gumloop.com/settings/organization/policies) when your company requires these controls:

        | Control | Use it to |
        | - | - |
        | **Rules** | Block or tag particular tool calls. |
        | **Domain Restrictions** | Require corporate email domains for new OAuth connections. |
        | **Claims** | Claim a provider workspace for your organization. |

        **Done when:** you know which apps are approved, which account each will use, and whether company-wide policies are needed.

        <Note>
          OAuth **Domain Restrictions** govern connector accounts. They are not the same as organization **Domain Whitelisting**, which controls automatic organization membership.
        </Note>

        <div className="es-more">
          **Learn more**

          [App Policies](/enterprise-features/app-policies/overview)

          [App Rules](/enterprise-features/app-policies/app-rules)

          [Domain Restrictions](/enterprise-features/app-policies/domain-restrictions)

          [App Claims](/enterprise-features/app-policies/app-claims)

          [Connectors](/core-concepts/credentials)
        </div>
      </section>

      <section id="teams" data-index="07" data-title="Teams and shared accounts" className="es-chapter">
        <span className="es-owner">IT admin · Champion</span>

        ## How should I organize Teams?

        <p className="es-dek">Provide a shared home only where collaboration or shared accounts are needed.</p>

        <div className="es-rec">
          **Recommended setup**

          **Teams:** One Team for the pilot department.

          **Accounts:** Personal accounts by default. A shared Team account only for shared sources, such as a team drive.
        </div>

        Create one pilot Team for shared work, not a Team for every entry in your org chart.

        <Steps>
          <Step title="Create the pilot Team">
            On the Home page, click **+** beside **Teams**. In **New Team**, enter **Team Name**, then **Create**.

            <Frame caption="Create one shared space for the pilot.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/create-team.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=e15957f454bd5a66006c8cfe7a224fc3" alt="New Team dialog with Team Name, logo, brand color, and Create" style={{ maxWidth: '560px', margin: '0 auto' }} width="1024" height="748" data-path="images/enterprise-features/onboarding/create-team.png" />
            </Frame>
          </Step>

          <Step title="Prepare a shared connector only if needed">
            Expand the Team and open **Connectors**. A Team Admin can find the approved service and click **Add**. Review **Team credential addition** in their Custom Roles too.
          </Step>
        </Steps>

        Use personal accounts when each participant should act as themselves. Use a shared Team account only when everyone should have that account's access. Limit shared accounts to the pilot's approved data.

        **Done when:** the Team exists, its administrator is identified, and any shared account has the right source permissions. Review the default Team in [**General**](https://www.gumloop.com/settings/organization/general) after creating Teams, before new members join.

        <div className="es-more">
          **Learn more**

          [Organization and Teams](/core-concepts/teams)

          [Connectors](/core-concepts/credentials)
        </div>
      </section>

      <section id="identity" data-index="08" data-title="SSO and provisioning" className="es-chapter">
        <span className="es-owner">IT admin</span>

        ## When should I configure SSO and SCIM?

        <p className="es-dek">Make sure the next sign-in works for everyone, not just your current session.</p>

        <div className="es-rec">
          **Recommended setup**

          **SSO:** The identity provider your company already uses for other tools.

          **SCIM:** On if you offboard people through your identity provider.

          **Before activating:** Test a fresh sign-in with a non-admin account.
        </div>

        If you require SSO, set it up before inviting the pilot. Your IT setup group can join first.

        <Steps>
          <Step title="Choose your identity setup">
            Open organization [**Identity Provider**](https://www.gumloop.com/settings/organization/sso) settings and follow the matching provider guide in [SSO: SAML, OIDC & SCIM](/enterprise-features/sso_saml_oidc_scim).

            <Frame caption="Choose the sign-in method with IT; these controls do not invite employees.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/identity-provider.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=66257f0e375d5921897296a3017f7143" alt="Identity Provider configuration with SAML and OpenID Connect setup options" width="1816" height="1204" data-path="images/enterprise-features/onboarding/identity-provider.png" />
            </Frame>
          </Step>

          <Step title="Test sign-in before widening access">
            Test with the IT owner and a pilot member, using a fresh sign-in. For Okta OIDC, **Run test** must pass before activation. Match account emails and assign every existing user who needs access to the Okta app.
          </Step>

          <Step title="Add SCIM only when needed">
            Use SCIM for automated provisioning, offboarding, and role or Team mappings. Request enablement from support, and set the mappings before syncing the wider group. SCIM runs through a SAML app even if sign-in uses OIDC, and removing someone's SAML app assignment can deactivate them in Gumloop.
          </Step>
        </Steps>

        <Warning>
          Activating SSO turns off Google and email sign-in for your SSO domains. Test a fresh sign-in first; staying signed in is not proof the next sign-in works.
        </Warning>

        **Done when:** an ordinary pilot member can sign in, and provisioning places them in the expected roles and Teams. Keep manual invitations and identity-provider provisioning aligned.

        <div className="es-more">
          **Learn more**

          [SSO: SAML, OIDC & SCIM](/enterprise-features/sso_saml_oidc_scim)

          [OIDC with Okta](/enterprise-features/idp-guides/oidc-with-okta)

          [SCIM with Okta](/enterprise-features/idp-guides/scim-with-okta)

          [SCIM with Entra](/enterprise-features/idp-guides/scim-with-entra)
        </div>
      </section>

      <section id="agent" data-index="09" data-title="First agent" className="es-chapter">
        <span className="es-owner">Champion · IT admin</span>

        ## How do I launch the first agent?

        <p className="es-dek">Start with a task the department cares about, not a perfectly configured but unused agent.</p>

        <div className="es-rec">
          **Recommended setup**

          **Who Can Use:** **Team**.

          **Owner:** The department lead.

          **Task Visibility:** **Their tasks only**.

          **Sensitive tools:** **Ask for writes/deletes** on anything that sends or changes data.
        </div>

        Choose a first task with the department lead before configuring the agent. For an HR & People pilot, the goal can be: answer a handbook question, cite the policy, and refer unanswered questions to HR, without accessing employee records.

        <Steps>
          <Step title="Invite the department lead">
            Invite the lead from organization [**Members**](https://www.gumloop.com/settings/organization/members) with the pilot's **Custom Roles** and **Team**, so they can build the agent before the rest of the pilot joins.
          </Step>

          <Step title="Create it in the pilot Team">
            Open the Team's **Agents** page and create the agent. In **Agent**, describe its job and boundaries.

            ```text Example instructions wrap theme={"dark"}
            Answer policy questions using only the approved sources.
            Cite the source. If it does not answer the question, say so and refer to HR.
            Do not access employee records or change HR systems.
            ```
          </Step>

          <Step title="Choose the account and tools">
            In **Connectors**, add the app that holds the approved sources, such as the drive with your handbook. Select **Use Personal Default** for each person's account or **Use Team Default** for the shared account. Adding a Team connection does not select it automatically. Deny unnecessary tools; use **Ask for writes/deletes** for enabled sensitive tools.
          </Step>

          <Step title="Review Access and save">
            Set **Who Can Use** to **Team**. Add the department lead as an **Owner**. Set **Task Visibility** to **Their tasks only** for this pilot; new team agents default to **Team tasks**. Review **File Sharing**, **Create Triggers**, and **Make a copy**, then **Save**.

            <Frame caption="Check agent use, generated file sharing, and task visibility separately. The shown test values are not a completed pilot setup.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/agent-access.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=47d55e17e83b48810b5b101c525a2c5b" alt="Team agent Access panel showing Who Can Use, File Sharing, and Task Visibility" style={{ maxWidth: '560px', margin: '0 auto' }} width="912" height="984" data-path="images/enterprise-features/onboarding/agent-access.png" />
            </Frame>
          </Step>
        </Steps>

        Start a **New Task** and try this prompt. Review the answer with the department lead before testing as an ordinary member.

        ```text Test prompt wrap theme={"dark"}
        What does the approved employee handbook say about taking time off? Cite the policy, and tell me if the sources do not answer the question.
        ```

        **Done when:** Users can run the agent without editing it. Owners and authorized administrators retain administrative visibility; **Their tasks only** is not a confidential channel hidden from them. Instructions do not enforce data access, so restrict the account and tools too.

        <div className="es-more">
          **Learn more**

          [Agents](/core-concepts/agents)

          [Agent Access](/core-concepts/agent_access)

          [Connectors](/core-concepts/credentials)
        </div>
      </section>

      <section id="members" data-index="10" data-title="Pilot members" className="es-chapter">
        <span className="es-owner">IT admin</span>

        ## When should I invite employees?

        <p className="es-dek">Invite people once there is something useful and safe for them to use.</p>

        <div className="es-rec">
          **Recommended setup**

          **Pilot group:** A small group from one department.

          **Assignment:** The pilot Team and the default Custom Role.
        </div>

        Invite the pilot once the first agent works and sign-in is ready.

        <Steps>
          <Step title="Choose manual invitations or provisioning">
            For manual invitations, open organization [**Members**](https://www.gumloop.com/settings/organization/members). In **Add Member to Organization**, enter **Email**, select **Custom Roles** and **Teams**, and click **Add**. Every member has the baseline Member role; add other organization roles only when needed.

            <Frame caption="Select organization roles, Custom Roles, and Teams before sending an invitation.">
              <img src="https://mintcdn.com/agenthub/ucvlVJysdsVz1mt9/images/enterprise-features/onboarding/invite-member.png?fit=max&auto=format&n=ucvlVJysdsVz1mt9&q=85&s=7689cf2761972da6898c572944a4fdac" alt="Add Member to Organization dialog with Email, Roles, Custom Roles, Teams, and Add" style={{ maxWidth: '600px', margin: '0 auto' }} width="1152" height="1160" data-path="images/enterprise-features/onboarding/invite-member.png" />
            </Frame>
          </Step>

          <Step title="Confirm membership">
            Wait for acceptance. For someone already in the organization, right-click the Team and choose **Invite to Team**. If SCIM manages membership, verify the identity-provider assignment and sync instead.
          </Step>
        </Steps>

        **Done when:** the member has the expected Team, Custom Roles, and model access. Do not use an Admin account as your only test.

        If you want domain-based automatic joining, enable it only after these defaults are ready and confirm the landing experience.

        <div className="es-more">
          **Learn more**

          [User Roles](/core-concepts/organization_user_roles)

          [Organization and Teams](/core-concepts/teams#adding-team-members)
        </div>
      </section>

      <section id="rollout" data-index="11" data-title="Test and expand" className="es-chapter">
        <span className="es-owner">Champion · IT admin</span>

        ## How do I check that setup is ready?

        <p className="es-dek">Prove usefulness and access boundaries before expanding the audience.</p>

        <div className="es-rec">
          **Recommended setup**

          **Testing:** Use a non-admin account.

          **Expanding:** One team at a time, after the department lead signs off.
        </div>

        Test as an ordinary pilot member before inviting a wider audience.

        | Test | Expected result |
        | - | - |
        | Join and sign in | The intended organization, Team, and roles are applied. |
        | Run the agent | The approved model and intended connector account work. |
        | Ask a supported question | The answer cites an approved source. |
        | Ask for unavailable data or an unnecessary action | No unauthorized data or tool is available. |
        | Check User access | No editing or browsing another User's tasks. |

        Review organization [**Insights**](https://www.gumloop.com/settings/organization/insights) for adoption and spend, and [**Audit Logging**](https://www.gumloop.com/settings/organization/audit-logging) for administrative changes. Give reporting responsibilities to the appropriate [User Roles](/core-concepts/organization_user_roles), not blanket Admin access.

        **Done when:** the department lead accepts the results and owns ongoing corrections. Share the agent link, supported tasks, and contact person, then expand membership in stages.

        <div className="es-more">
          **Learn more**

          [Organization Insights](/enterprise-features/organization_insights)

          [Audit Logging](/enterprise-features/audit_logging)

          [User Roles](/core-concepts/organization_user_roles)
        </div>
      </section>

      <section id="faq" data-title="FAQ" className="es-chapter">
        ## Frequently asked questions

        <p className="es-dek">Short answers to what new admins ask most.</p>

        <AccordionGroup>
          <Accordion title="How do roles, Teams, and accounts fit together?" defaultOpen>
            Think of five separate questions: who manages the organization, where shared work lives, what a person may use, who owns the agent, and whose external account it uses.

            | Question | Control | Pilot example |
            | - | - | - |
            | Who manages company settings? | Organization role | IT has Admin; an employee has Member. |
            | Where do people collaborate? | Team | HR & People has a shared space. |
            | Which tools, models, and features may a person use? | Custom Role | The pilot gets approved apps and models. |
            | Who maintains or runs this agent? | Agent Access | The lead is Owner; participants are Users. |
            | Whose data can a tool reach? | Connector account | Each participant's account, or an approved shared Team account. |
          </Accordion>

          <Accordion title="Do I need both a Team and a Custom Role for each department?">
            No. A Team is a shared space; a Custom Role is an organization-level access policy. Create a Team when people need shared work. Create another Custom Role only when their policy needs differ. A department does not automatically need a one-to-one pair. See [Organization and Teams](/core-concepts/teams) and [Custom Roles](/enterprise-features/user_groups).
          </Accordion>

          <Accordion title="Why does a restrictive Custom Role not override a permissive one?">
            Access allowed by another assigned role remains available. Review the default and all additional roles together, then change the role that grants unwanted access. More roles do not necessarily mean tighter control.
          </Accordion>

          <Accordion title="Does joining a Team let someone edit its agents?">
            No. Team membership gives User access to team agents. Maintaining an agent requires Owner access, and creating or modifying agents also depends on the person's Custom Roles. Team Admin and agent Owner are different responsibilities. See [Agent Access](/core-concepts/agent_access).
          </Accordion>

          <Accordion title="Does connecting an app mean everyone uses the same account?">
            No. **Use Personal Default** uses the running person's account. **Use Team Default** uses the shared Team account. Configure that choice explicitly on the agent. An app allowlist is permission, not authentication. See [Connectors](/core-concepts/credentials).
          </Accordion>

          <Accordion title="Who can see what people ask an agent?">
            Agent Owners can see every task on the agent. Users see what **Task Visibility** allows. Authorized administrators keep administrative visibility, so **Their tasks only** is not a private channel. See [Agent Access](/core-concepts/agent_access).
          </Accordion>

          <Accordion title="Is our data used to train models?">
            Every model Gumloop serves runs under zero data retention except Anthropic's Claude Fable family, which keeps prompts and outputs for 30 days to check for misuse and does not train on them. Turn off **Allow non-zero data retention models** in **Models** to exclude them. See [AI Model Governance & Configuration](/enterprise-features/ai_model_control).
          </Accordion>

          <Accordion title="What happens when someone leaves?">
            Remove them from the three-dot menu on [**Members**](https://www.gumloop.com/settings/organization/members), or let SCIM deprovision them. Their active triggers turn off. Nothing else is deleted, so a remaining member re-creates any trigger that should keep running. See [User Roles](/core-concepts/organization_user_roles#removing-a-member).
          </Accordion>

          <Accordion title="What about employees who already use Gumloop?">
            With OIDC sign-in, Gumloop matches an existing account by email on first sign-in. Check that emails in your identity provider match the accounts people already use. See [SSO: SAML, OIDC & SCIM](/enterprise-features/sso_saml_oidc_scim).
          </Accordion>

          <Accordion title="Are domain auto-join, SSO, and OAuth domain restrictions the same thing?">
            No. Domain whitelisting admits matching new users to the organization. SSO controls sign-in through an identity provider. OAuth Domain Restrictions govern new connector authentications. Review each independently; configuring one does not replace the others.
          </Accordion>
        </AccordionGroup>
      </section>

      <section id="advanced" data-title="Additional controls" className="es-chapter">
        ## What else can I configure at enterprise level?

        <p className="es-dek">Add controls for a real requirement rather than treating every enterprise feature as mandatory.</p>

        Configure these when a company requirement or use case needs them. They are not all prerequisites, but a mandatory network or security requirement belongs before the affected pilot.

        <AccordionGroup>
          <Accordion title="Budgets and reusable organization guidance">
            Review [**Usage & Limits**](https://www.gumloop.com/settings/organization/limits) with your budget owner, alongside Custom Role usage caps and approval assignees. See [Credits](/core-concepts/credits) for how usage is counted. Use [Organization Skills](/core-concepts/organization_skills) for shared agent guidance.
          </Accordion>

          <Accordion title="Optional General settings">
            Review **Custom artifact domain** for branded file hosting, and **Slack workspaces** plus **Service account** for Slack-based agent access. Use **Google Workspace directory** or **Microsoft directory** when you need [Brain](/core-concepts/brain) to honor source-group permissions. Directory access is separate from SSO.
          </Accordion>

          <Accordion title="Provider keys, model proxies, and custom OAuth">
            Use organization [**API Keys & Proxies**](https://www.gumloop.com/settings/organization/api-keys) for provider credentials and model routing. [**OAuth Configuration**](https://www.gumloop.com/settings/organization/oauth-configuration) is separate and applies to supported connector authentication. See [AI Model Governance & Configuration](/enterprise-features/ai_model_control).
          </Accordion>

          <Accordion title="Custom and private-network integrations">
            Use [Hosted MCPs](/enterprise-features/hosted_mcps) for custom servers hosted by Gumloop, [Proxied MCPs](/enterprise-features/proxied_mcps) for existing servers, and [Managed Tunnels](/enterprise-features/managed_tunnels) for servers in private networks. Use [Static Egress IPs](/enterprise-features/static_egress_ips) when your network requires outbound IP allowlists.
          </Accordion>

          <Accordion title="Reporting, exports, and event delivery">
            Use [Organization Insights](/enterprise-features/organization_insights) for adoption, [Audit Logging](/enterprise-features/audit_logging) for administrative changes, [Usage Data Export](/enterprise-features/organization_data_export) for exports or data drains, and [Outbound Webhooks](/enterprise-features/organization_webhooks) for supported organization events.
          </Accordion>

          <Accordion title="Slack and Microsoft Teams access">
            Validate the agent first, then add the required communication channel. Review [Using Agents in Slack](/core-concepts/agents_slack), [Using Agents in Microsoft Teams](/core-concepts/agents_teams), and [Organization Service Accounts for Slack Agents](/enterprise-features/slack_agent_access). A Gumloop Team is not a Microsoft Teams channel.
          </Accordion>
        </AccordionGroup>
      </section>
    </EnterpriseSetupChecklist>
  </div>
</div>

<script type="application/ld+json">
  {JSON.stringify({
      "@context": "https://schema.org",
      "@type": "HowTo",
      "name": "Enterprise admin starter kit",
      "description": "Prepare your organization, welcome a pilot, and deliver the first useful agent result.",
      "dateModified": "2026-10-01",
      "step": [
        { "@type": "HowToStep", "name": "Decide before setup", "text": "Gather identity, membership, app, model, guardrail, security, and logistics decisions before the setup call." },
        { "@type": "HowToStep", "name": "Review General settings", "text": "Review organization configuration, automatic admission domains, the default Team, and approval assignees before expanding access." },
        { "@type": "HowToStep", "name": "Identify setup administrators", "text": "Invite the small IT setup group only if additional configuration owners need access." },
        { "@type": "HowToStep", "name": "Approve models and agent defaults", "text": "Set organization model restrictions and review defaults for newly created agents." },
        { "@type": "HowToStep", "name": "Prepare Custom Roles", "text": "Review the default role, configure required grants, and inspect all assigned roles together." },
        { "@type": "HowToStep", "name": "Prepare connector policies", "text": "Decide approved services and required tool-call, OAuth-domain, or workspace policies." },
        { "@type": "HowToStep", "name": "Create Teams and shared accounts", "text": "Create the pilot Team, prepare shared credentials only if needed, and review the default Team." },
        { "@type": "HowToStep", "name": "Configure identity and provisioning", "text": "Test required SSO and provisioning with the intended account before the wider rollout." },
        { "@type": "HowToStep", "name": "Launch the first agent", "text": "Create a narrowly scoped agent and review connector accounts, tools, and agent access." },
        { "@type": "HowToStep", "name": "Invite pilot members", "text": "Invite the pilot once the first agent works and sign-in is ready." },
        { "@type": "HowToStep", "name": "Test and expand", "text": "Validate ordinary-member access and agent behavior, review adoption, and expand in stages." }
      ]
    })}
</script>
