Inviting people

Three ways to bring people into your organization: invitations with a role, auto-join by verified domain, and just-in-time membership through SSO.

You never manage a spreadsheet of secrets. Every method below ends the same way: the person signs in with a work identity and appears in Members with a role.

Choose a method

MethodBest forRequires
InviteSpecific people, specific roles (admins, a pilot group, contractors on your domain).Nothing — works even before the domain is verified.
Auto-join by domainEveryone at the company. Zero admin work per person.Verified domain and Join policy: auto-join.
SSO just-in-timeCompanies with an identity provider; roles can come from groups.SSO configured and tested; a group→role map if you want admins from groups.

Invitations

  1. Open Organization → Members → Invite

    Paste one address, or many — one per line, comma-separated, or a CSV column. Only addresses on your organization's domains are accepted.

  2. Pick the role

    Employee for most people, admin for those who will run security. Owners are promoted later by an existing owner (see Roles).

  3. Send

    Each person receives an e-mail from OKY with a link. The invite is valid for 14 days. Pending invites are listed on the Overview and in Members, with Resend and Revoke.

  4. They accept

    The link takes them to sign-in. They prove the address (work e-mail code, or your SSO if it is on) and land in their dashboard already a member with the pre-set role.

An invite proves intent for that one address, so invites work on an unverified domain. Auto-join does not — see below.

Auto-join by domain

With auto-join on, anyone who signs in with an address on a verified domain of your organization becomes an employee automatically — no invite, no waiting. Switch it on under Organization → Policies → Join policy: choose Auto-join by verified domain (or keep Invite only). The option is greyed out until at least one domain is verified.

  • New joiners always get the employee role; promote admins in Members.
  • Auto-join respects the seat limit. A join beyond it is refused with a message and the owner is notified.
  • You can run both: auto-join for the crowd, invites for people who need admin from day one.

SSO just-in-time

When SSO is configured, the first successful login through your identity provider creates the membership. If you set a group → role map (for example oky-admins → admin) the role is taken from the groups claim on every login; people without a matching group are employees. See the SSO guides: Google Workspace, Microsoft Entra ID, Keycloak, Okta.

People who already had a personal OKY account

If someone already used OKY with the same work address, joining the organization links that account rather than creating a new one — their history and settings stay. Linking by address only happens for verified domains (you control the domain, so it is safe). Such members are marked linked rather than managed; removing them ends the membership but keeps their personal account.

Seats

Your plan has a seat limit shown under Organization → Billing. Every member — owner, admin or employee — uses one seat. Pending invites do not. When you hit the limit, new joins are refused and the owner receives a notification; raise the seat count or remove inactive members.

Troubleshooting

The invite e-mail did not arrive

Check spam and any company mail gateway rules for messages from oky.ai. Use Resend in Members. Invites cannot be sent to consumer addresses (gmail.com, outlook.com …) or to domains that are not on your organization.

“This address belongs to an organization — sign in through your organization”

The person tried personal Google sign-in with an address on your verified domain. Ask them to use the e-mail box on the sign-in page (work e-mail code) or your SSO button instead.

“No seats available”

The seat limit is reached. An owner can raise it under Billing, or remove members who left.

Someone joined with the wrong role

Members → change role. Admin ↔ employee can be done by any admin; making someone an owner needs an owner.