Skip to main content

Organization Settings

Organization settings control global behavior for policy scanning, tag management, authentication, and more.

The organization settings page

Policy Scan Settings

SettingDescriptionDefault
Scan frequencyHow often policies run (see Billing and tiers)Tier-dependent
Auto-resolve missesConsecutive non-detections before a finding auto-resolves2
Cooldown hoursTime window after an action during which repeat actions are suppressed24
Default timezoneTimezone used for new schedulesUTC

Tag Settings

Source Tag Import

Control how tags from your cloud provider are imported:

ModeBehavior
AllImport all cloud resource tags
WhitelistImport only specified tag keys
NoneDon't import cloud tags

When using whitelist mode, specify the tag keys to import (e.g., environment, team, cost-center).

Custom Tag Templates

Define organization-wide tag templates that standardize tagging across workspaces:

FieldDescription
KeyTag name
DescriptionHelp text for users
Allowed valuesDropdown options. Leave empty for free text input.

Tag templates appear as options when users apply custom tags to workspaces.

Authentication Settings

SettingDescription
Password loginEnable/disable email + password authentication
Microsoft SSOEnable/disable Microsoft Entra ID login
SSO (Enterprise)Enable SAML/OIDC SSO
Directory syncEnable automatic user provisioning
Guest usersAllow SSO guest access

Enterprise Settings

Enterprise tier organizations can access the Admin Portal to configure:

  • SAML/OIDC SSO connections
  • Directory sync for automatic user provisioning
  • Domain verification

See the Enterprise SSO and SCIM guide for the full setup walkthrough.