01 / ORGANIZATIONS
Organization & team managementAvailable
Create your organization from Settings -> Organization. The creator becomes the primary owner. Roles: owner (full control), admin (invite members, export audit log), member (read-only org access). Invite teammates by email. Enterprise starts at 25 seats, counted as joined members only. Pending invites do not consume a seat, so you can have more outstanding invitations than seats; the limit is enforced at the moment each invite is accepted. Invitation emails are not sent yet: share the sign-up link with invitees directly.
02 / SINGLE SIGN-ON
SAML SSOConfig storage — login flow in progress
Store your SAML configuration now (provider, IdP metadata URL, ACS URL, entity ID) so your identity-provider side is ready when the login flow ships. Saving the config does not yet change how your team signs in.
Okta
Applications -> Create App Integration -> SAML 2.0. Set the ACS URL and SP Entity ID, Name ID = EmailAddress, copy the app's Metadata URL from the Sign On tab, assign users.
Azure AD (Entra ID)
Enterprise applications -> New application -> non-gallery -> Single sign-on: SAML. Set Identifier + Reply URL, add an email claim, copy the App Federation Metadata Url, assign groups.
Google Workspace
Apps -> Web and mobile apps -> Add custom SAML app. Download the IdP metadata XML, set ACS URL + Entity ID, Name ID = primary email, turn the app on for your org units.
JumpCloud
SSO Applications -> Custom Application -> Manage SSO (SAML). Set SP Entity ID + ACS URL, NameID = email, activate, copy the IdP Metadata URL, bind user groups.
Full walkthroughs with the exact field values are not published on the web yet. Ask your CanaryVaults contact for the PDF, or write to hello@canaryvaults.com.
03 / CUSTOM DOMAIN
Custom domainsScaffold — no verifier yet
Set a subdomain such as vaults.acme.com in Settings -> Organization and the API returns the two DNS records it will eventually want: a CNAME and a TXT challenge proving domain control. Do not create them yet. The CNAME target is a placeholder with nothing serving behind it, nothing in the product reads the stored domain, and no verifier exists — so a domain stays at pending verification indefinitely. Treat this card as a scaffold and talk to your CanaryVaults contact before planning any DNS change around it.
04 / AUDIT LOG EXPORT
Audit-log export (CSV)Available
Owners and admins can export the organization's account-activity audit trail (logins, plan changes, canary triggers, privacy actions) as CSV — up to 365 days, 10,000 rows per export. The file includes member IP addresses; handle it as confidential.