Enterprise covers what an admin needs to operate Compound for an organization: managing the team, federating identity with your IdP, automating user provisioning, auditing activity, and integrating Compound into your security review.
Team administration lives in the Organization group of Settings tabs. To open it, click your name at the bottom of the left sidebar, then Settings. The tabs are Members (people, invites, and roles), Security (domain verification, SSO, SCIM, and the audit log), Billing (plan and seats), Groups and Project Drives (team managers and above), and Organization Knowledge (shared conventions and files every agent can use). What you can see and do on each depends on your role.
Team administration
Roles
Every team member has one of four roles:
- Owner: full control of the team, including billing, SSO, SCIM, member removal, and team deletion. There is always exactly one Owner, and you can transfer ownership at any time.
- Admin: can invite and remove members, manage billing, and view the audit log. Cannot transfer ownership.
- Manager: can manage groups, project drive properties, Organization Knowledge files, and view and export the audit log. Cannot invite or remove members or change billing.
- Member: standard team access. Can create agents, give them tasks, and collaborate in agents shared with them.
Members and invitations
Settings > Organization > Members lists everyone on the team with their role. Admins and the Owner also see usage and pending invites, and a seat column appears for enterprises with more than one billing account. Use this page to:
- Change a member’s role from the role dropdown.
- Click Remove from Team to revoke access, then confirm with Remove in the dialog.
- Click Invite to send new invitations to one or more email addresses. Invitees join as Members; change their role from the roster once they’ve accepted. Invites expire after 7 days if not accepted. To resend, invite the same address again. When SCIM provisioning is on, invitations are disabled and your IdP manages membership.
Single Sign-On (SSO)
Compound supports SAML 2.0 and OpenID Connect (OIDC) so your team can sign in through your existing identity provider (Okta, Entra ID, Google Workspace, OneLogin, etc.).
- Set up SSO for Compound: overview, prerequisites, domain verification, and supported protocols.
- Set up Okta OIDC SSO: step-by-step guide for OIDC with Okta. This is the recommended starting point.
- Set up Okta SAML SSO: step-by-step guide for SAML 2.0 with Okta.
Only Team Owners can configure SSO. Once SSO is active, anyone signing in with your verified domain is routed through your identity provider automatically.
SCIM provisioning
SCIM 2.0 syncs your team membership from your identity provider. Assigning someone to the Compound app in your IdP adds them to your team, and unassigning them removes them.
- SCIM provisioning: overview, prerequisites, and how it interacts with SSO.
- Set up Okta SCIM provisioning: step-by-step setup with Okta.
SCIM requires an active SSO configuration. Enable SSO first, then add SCIM.
Audit log
The audit log, reached from Settings > Organization > Security, records who did what and when, for use in security reviews and compliance audits. The log captures member events (invites, joins, removals, role changes), SSO, SCIM, and domain configuration changes, SCIM provisioning events, sharing changes, and file and audit-log exports.
You can export the log as CSV with the Export button at the top of the page.
Security and privacy
Compound’s data handling, retention, and compliance posture are documented at Security. For specific questions, such as data residency, retention windows, sub-processors, or vendor security questionnaires, contact your account team.
Enterprise plans include data isolation guarantees, custom retention windows, and a security review process. If your organization needs any of these, talk to us before rolling Compound out widely.
What to read next
- Account, plans and billing: billing, plans, and per-user account settings.
- Collaboration: how agents are shared with teammates.
- Set up SSO for Compound: the entry point for IdP integration.