Skip to content

Organization settings

Four settings, on one page, that apply to your whole organization. You’ll set them once and mostly forget them — but two of them are the difference between “our sign-in works” and “anyone at a company we’ve never heard of can sign in”.

Organization settings: time zone, ticket numbering, sign-in providers, and the Google domain and Entra tenant allowlists.

The organization default. It applies to anyone who hasn’t set a personal override in their profile, and — the part that’s easy to miss — to background jobs running in your organization’s context.

That second one matters more than it sounds. Digests, nightly syncs and the “which week is this?” arithmetic behind reports all run against this zone. Get it wrong and your reports are cut on the wrong day boundary for everyone, including the people who did set a personal override.

Ticket numbers look like PREFIX-CC-YYMMDD-NNNN.

Part What it is
PREFIX Yours to set — 2–10 letters or digits
CC A two-digit code assigned when your organization was created
YYMMDD The date the ticket was raised
NNNN A counter

The prefix is the only part you control, and it’s worth choosing something short that a customer can read back over the phone. The page shows a live preview of what the next number will look like.

This is the part to read slowly, because the two halves look redundant and aren’t.

Sign-in providers — Google and Microsoft Entra ID — decide which buttons appear on the staff sign-in page. That is all they do.

The allowlists below decide who actually gets in. Turning a provider on without filling in its allowlist gives you a button that refuses everybody.

  • Trusted Workspace domains — Google sign-in resolves an email only when its domain is on this list. One per line.
  • Trusted Entra tenants — a Microsoft sign-in is refused unless the token’s tenant id is on this list. One GUID per line.

Google is different because Google asserts that an address is verified, so a domain match is meaningful there in a way it isn’t for Entra. That asymmetry is also why an emailed invitation can only be accepted with Google.

Separately, Admin → Agents lets you register an automation as its own actor — so a script’s writes appear under the script’s name rather than under whichever person’s credentials it borrowed.

An agent can’t sign in. It authenticates by API key only and can never hold a session, which means registering one is not a back door into the UI. If you have anything writing to this app on a schedule, give it an agent rather than a person’s account; the day you need to work out what changed, you’ll be glad the audit trail says Nightly importer instead of a colleague who was asleep.