Organization Settings
Organization settings control global behavior for policy scanning, tag management, authentication, and more.

Policy Scan Settings
| Setting | Description | Default |
|---|---|---|
| Scan frequency | How often policies run (see Billing and tiers) | Tier-dependent |
| Auto-resolve misses | Consecutive non-detections before a finding auto-resolves | 2 |
| Cooldown hours | Time window after an action during which repeat actions are suppressed | 24 |
| Default timezone | Timezone used for new schedules | UTC |
Tag Settings
Source Tag Import
Control how tags from your cloud provider are imported:
| Mode | Behavior |
|---|---|
| All | Import all cloud resource tags |
| Whitelist | Import only specified tag keys |
| None | Don't import cloud tags |
When using whitelist mode, specify the tag keys to import (e.g., environment, team, cost-center).
Custom Tag Templates
Define organization-wide tag templates that standardize tagging across workspaces:
| Field | Description |
|---|---|
| Key | Tag name |
| Description | Help text for users |
| Allowed values | Dropdown options. Leave empty for free text input. |
Tag templates appear as options when users apply custom tags to workspaces.
Authentication Settings
| Setting | Description |
|---|---|
| Password login | Enable/disable email + password authentication |
| Microsoft SSO | Enable/disable Microsoft Entra ID login |
| SSO (Enterprise) | Enable SAML/OIDC SSO |
| Directory sync | Enable automatic user provisioning |
| Guest users | Allow SSO guest access |
Enterprise Settings
Enterprise tier organizations can access the Admin Portal to configure:
- SAML/OIDC SSO connections
- Directory sync for automatic user provisioning
- Domain verification
See the Enterprise SSO and SCIM guide for the full setup walkthrough.
Related
- Concept: Workspace tags uses the tag settings defined here
- Reference: Billing and tiers for scan frequency and feature availability
- Guide: Enterprise SSO and SCIM