Skip to content

Organization security

Owners and admins manage sign-in and auto-provisioning for their organization from one page: Organization → Skills, Tools & Integrations → SSO.

Single sign-on

Kwirker authenticates every sign-in the same way, so this section is read-only status, not a place to configure a new identity provider yourself:

  • A badge shows whether SSO is active for your organization, plus the realm it authenticates against.
  • Below that, every configured identity provider is listed with its type (e.g. Okta, Microsoft, Google, or a generic OIDC provider) and whether it's currently enabled.

Only owners and admins can see this section. If you need a new identity provider connected, reach us at support@kwirker.com.

Auto-provisioning rules

Instead of inviting every teammate by hand, you can add a rule that auto-provisions anyone who signs in with a matching email into your organization on their first login — no separate invite step.

Each rule pairs an email pattern with the role a matching sign-in receives:

  • Pattern — a domain match, for example *@acme.com.
  • Auto-role — the role granted automatically: Guest, Member, Admin, or Owner.

Add a rule with the pattern and role, then Add rule. Existing rules are listed with a Remove action. A pattern can only be used once per organization — adding the same pattern twice is rejected.

Choose the auto-role carefully

Anyone who signs in with a matching email gets that role immediately, with no manual approval step. Granting Admin or Owner by pattern hands out elevated access automatically — reserve those roles for tightly scoped patterns you're confident about, and prefer Member or Guest for broader ones.

Default skill visibility for new agents

Also on this page, admins set the default scope newly created agents in your organization inherit for skill visibility:

  • Private only — skills stay private to the agent unless someone explicitly makes one public.
  • Tenant allowed — skills are visible tenant-wide by default.

This only sets the default for agents created after the change — existing agents keep whatever scope they already have. Change it any time from Save default; each agent's own skill visibility can still be adjusted individually afterward. See Authoring skills for how visibility works at the individual skill level.

Prompt analytics

To help improve the product and show you how your organization uses it, Kwirker turns your users' prompts into numeric embeddings and groups them into topics. Embeddings are generated by a model that runs inside the platform — your prompt text is never sent to an outside AI vendor for analytics.

This is on by default. Owners and admins can opt the whole organization out from Organization → Security → Prompt analytics:

  • While opted out, no new prompts from your organization are embedded.
  • Opting out also permanently deletes the embeddings already stored for your organization.
  • Opting back in only resumes embedding from that point forward; nothing is recovered.

Only owners and admins can change this setting, and every change is recorded in your organization's audit log.

See also