Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free

DOCS / ENTERPRISE

Enterprise: SSO, custom domains, organizations

Enterprise is quoted, not self-serve. Once your plan is provisioned, this is where you set up your organization, stage your identity-provider configuration, and export your audit trail. Read the status badge on each card: two of the four are still scaffolding.

Contact sales ->

01 / ORGANIZATIONS

Organization & team managementAvailable

Create your organization from Settings -> Organization. The creator becomes the primary owner. Roles: owner (full control), admin (invite members, export audit log), member (read-only org access). Invite teammates by email. Enterprise starts at 25 seats, counted as joined members only. Pending invites do not consume a seat, so you can have more outstanding invitations than seats; the limit is enforced at the moment each invite is accepted. Invitation emails are not sent yet: share the sign-up link with invitees directly.

02 / SINGLE SIGN-ON

SAML SSOConfig storage — login flow in progress

Store your SAML configuration now (provider, IdP metadata URL, ACS URL, entity ID) so your identity-provider side is ready when the login flow ships. Saving the config does not yet change how your team signs in.

Okta

Applications -> Create App Integration -> SAML 2.0. Set the ACS URL and SP Entity ID, Name ID = EmailAddress, copy the app's Metadata URL from the Sign On tab, assign users.

Azure AD (Entra ID)

Enterprise applications -> New application -> non-gallery -> Single sign-on: SAML. Set Identifier + Reply URL, add an email claim, copy the App Federation Metadata Url, assign groups.

Google Workspace

Apps -> Web and mobile apps -> Add custom SAML app. Download the IdP metadata XML, set ACS URL + Entity ID, Name ID = primary email, turn the app on for your org units.

JumpCloud

SSO Applications -> Custom Application -> Manage SSO (SAML). Set SP Entity ID + ACS URL, NameID = email, activate, copy the IdP Metadata URL, bind user groups.

Full walkthroughs with the exact field values are not published on the web yet. Ask your CanaryVaults contact for the PDF, or write to hello@canaryvaults.com.

03 / CUSTOM DOMAIN

Custom domainsScaffold — no verifier yet

Set a subdomain such as vaults.acme.com in Settings -> Organization and the API returns the two DNS records it will eventually want: a CNAME and a TXT challenge proving domain control. Do not create them yet. The CNAME target is a placeholder with nothing serving behind it, nothing in the product reads the stored domain, and no verifier exists — so a domain stays at pending verification indefinitely. Treat this card as a scaffold and talk to your CanaryVaults contact before planning any DNS change around it.

04 / AUDIT LOG EXPORT

Audit-log export (CSV)Available

Owners and admins can export the organization's account-activity audit trail (logins, plan changes, canary triggers, privacy actions) as CSV — up to 365 days, 10,000 rows per export. The file includes member IP addresses; handle it as confidential.

CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS