Enterprise

最終更新 2026年9月28日

Enterprise covers what an admin needs to operate Compound for an organization: managing the team, federating identity with your IdP, automating user provisioning, auditing activity, and integrating Compound into your security review.

Team administration lives in the Organization group of Settings tabs. To open it, click your name at the bottom of the left sidebar, then Settings. The tabs are Members (people, invites, and roles), Security (domain verification, SSO, SCIM, and the audit log), Billing (plan and seats), Groups and Project Drives (team managers and above), and Organization Knowledge (shared conventions and files every agent can use). What you can see and do on each depends on your role.

Team administration

Roles

Every team member has one of four roles:

  • Owner: full control of the team, including billing, SSO, SCIM, member removal, and team deletion. There is always exactly one Owner, and you can transfer ownership at any time.
  • Admin: can invite and remove members, manage billing, and view the audit log. Cannot transfer ownership.
  • Manager: can manage groups, project drive properties, Organization Knowledge files, and view and export the audit log. Cannot invite or remove members or change billing.
  • Member: standard team access. Can create agents, give them tasks, and collaborate in agents shared with them.

Members and invitations

Settings > Organization > Members lists everyone on the team with their role. Admins and the Owner also see usage and pending invites, and a seat column appears for enterprises with more than one billing account. Use this page to:

  • Change a member’s role from the role dropdown.
  • Click Remove from Team to revoke access, then confirm with Remove in the dialog.
  • Click Invite to send new invitations to one or more email addresses. Invitees join as Members; change their role from the roster once they’ve accepted. Invites expire after 7 days if not accepted. To resend, invite the same address again. When SCIM provisioning is on, invitations are disabled and your IdP manages membership.

Single Sign-On (SSO)

Compound supports SAML 2.0 and OpenID Connect (OIDC) so your team can sign in through your existing identity provider (Okta, Entra ID, Google Workspace, OneLogin, etc.).

Only Team Owners can configure SSO. Once SSO is active, anyone signing in with your verified domain is routed through your identity provider automatically.

SCIM provisioning

SCIM 2.0 syncs your team membership from your identity provider. Assigning someone to the Compound app in your IdP adds them to your team, and unassigning them removes them.

SCIM requires an active SSO configuration. Enable SSO first, then add SCIM.

Audit log

The audit log, reached from Settings > Organization > Security, records who did what and when, for use in security reviews and compliance audits. The log captures member events (invites, joins, removals, role changes), SSO, SCIM, and domain configuration changes, SCIM provisioning events, sharing changes, and file and audit-log exports.

You can export the log as CSV with the Export button at the top of the page.

Security and privacy

Compound’s data handling, retention, and compliance posture are documented at Security. For specific questions, such as data residency, retention windows, sub-processors, or vendor security questionnaires, contact your account team.

Note

Enterprise plans include data isolation guarantees, custom retention windows, and a security review process. If your organization needs any of these, talk to us before rolling Compound out widely.

What to read next