> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# Setting up your organisation

> The order to set up sign-in, roles, members, branding and security when you bring a team onto Flowsign.

This guide is for the admin setting Flowsign up for a whole organisation. Each step builds on the one before it, so working through them in order saves you from inviting people twice or re-assigning roles later. Every step links to the full guide for that settings page.

<Frame caption="Members, one of the settings pages you'll work through.">
  <img src="https://mintcdn.com/doc-a97e5290/PTzM8Xl3JBDj-Kc9/images/guides/organisation-setup.png?fit=max&auto=format&n=PTzM8Xl3JBDj-Kc9&q=85&s=6e5e372ad84a3408e6ead7fb363235bb" alt="The Members settings page listing active members and pending invitations." width="2880" height="1800" data-path="images/guides/organisation-setup.png" />
</Frame>

Steps marked **Enterprise** or **Business** need that plan. On a lower plan, skip them; the rest of the order still holds.

<Steps>
  <Step title="Check your company details and plan">
    In [Company](/guides/settings/company), set the organisation **Name**. It appears across Flowsign and on every email your recipients receive.

    In [Billing](/guides/settings/billing), confirm your plan and set the **Billing email** for receipts and invoices. Check the plan before going further: single sign-on, user provisioning, extra workspaces, API keys, webhooks and custom fields need **Enterprise**, and branding needs **Business** or higher. See [flowsign.app/pricing](https://flowsign.app/pricing) for what each plan includes. Your plan's seat limit also caps how many members you can invite or provision.
  </Step>

  <Step title="Add your branding (Business, optional)">
    In [Branding](/guides/settings/branding), upload your logo and pick a brand colour, then check the preview email. It's worth doing now, before anyone joins: invitation emails carry your branding, and each member's welcome screen shows your logo the first time they sign in. You can add it later, but people who have already joined won't see it there. It also brands every email your recipients get.
  </Step>

  <Step title="Verify your email domains (Enterprise)">
    Under **Verified domains** in [Organisation security](/guides/settings/security#verified-domains), add each domain your people sign in with, such as `yourcompany.com`, and verify it. Single sign-on can't be turned on until at least one domain is verified.
  </Step>

  <Step title="Turn on single sign-on (Enterprise)">
    If your organisation uses an identity provider, turn on **Enable SAML SSO** under [Single Sign-On (SAML)](/guides/settings/security#single-sign-on-saml).

    Test a sign-in with a member account on a verified domain before you go further. Once it works, turn on **Require SSO** so members on your verified domains can only sign in through your identity provider.

    <Note>
      Owners can still sign in with their password when **Require SSO** is on, so you can't lock yourself out if your identity provider is unavailable.
    </Note>
  </Step>

  <Step title="Create your workspaces">
    If you split work by office, region or team, create a workspace for each in [Workspaces](/guides/settings/workspaces). Each workspace has its own packages, templates, contacts and members. Extra workspaces need the **Enterprise** plan.

    Do this before inviting anyone: the invite dialog asks which workspace each person joins.
  </Step>

  <Step title="Set up roles and permissions">
    Review the system permission profiles in [Roles & Permissions](/guides/settings/roles-and-permissions). Where none fits, clone the closest one into a custom profile and adjust it.

    As with workspaces, do this before inviting anyone, because every invitation is sent with a permission profile.
  </Step>

  <Step title="Bring your people in">
    Choose one way to add members:

    * **User provisioning (Enterprise).** Generate a SCIM token under [User provisioning (SCIM)](/guides/settings/security#user-provisioning-scim) and paste it into your identity provider. It then adds, updates and deactivates members for you. People it adds, and people who first sign in through single sign-on, join the default workspace with the **Viewer** profile. See [Moving members to another workspace](#moving-members-to-another-workspace) below. Flowsign doesn't email people your identity provider adds, so let them know yourself and include your Flowsign sign-in link.
    * **Invitations.** In [Members](/guides/settings/members), use **Invite member** and choose each person's workspace and permission profile. Revoke an invitation from **Pending invitations** if it went to the wrong person.

    <Frame caption="The Invite member dialog, with workspace and permission profile to choose.">
      <img src="https://mintcdn.com/doc-a97e5290/PTzM8Xl3JBDj-Kc9/images/guides/organisation-setup/invite-member-dialog.png?fit=max&auto=format&n=PTzM8Xl3JBDj-Kc9&q=85&s=dc9f04fa51ed3b201e4a9530d1d6989c" alt="The Invite member dialog with fields for email address, workspace and permission profile." width="800" height="912" data-path="images/guides/organisation-setup/invite-member-dialog.png" />
    </Frame>

    Either way, each member counts towards your seat limit. Make a trusted colleague an owner too, so you are not the only one who can manage settings.
  </Step>

  <Step title="Create groups">
    With members in place, set up [Groups](/guides/settings/groups):

    * **User groups** organise your team.
    * **Signing groups** are for letting any one member of the group complete a recipient's step, for example a shared legal or HR inbox. You can set them up now; addressing a package to one is not available yet.
  </Step>

  <Step title="Set security and retention policies">
    Back in [Organisation security](/guides/settings/security), decide on:

    * **Session timeout**: how long members stay signed in when idle, and at most.
    * **IP allowlist**: the networks members and API keys may connect from. It applies to API keys and user provisioning too, so include the addresses of any servers that call the API and of your identity provider.
    * **Data retention**: how long completed documents are kept before they are permanently deleted.
  </Step>

  <Step title="Build your templates">
    Turn the documents your team sends often into templates, with roles, fields, reminders and expiry. See [Building a workflow](/guides/building-a-workflow). If you plan to use [custom fields](/guides/settings/custom-fields) (Enterprise), define them first so your templates can use them.
  </Step>

  <Step title="Connect your systems (optional)">
    To send from your own software or react to signing events, set up [API keys](/guides/settings/api-keys) (Enterprise), [Webhooks](/guides/settings/webhooks) (Enterprise) and [Integrations](/guides/settings/integrations). The [developer quickstart](/developers) walks through a first send from code.
  </Step>

  <Step title="Ask members to finish their own accounts">
    Point each member to [My account](/guides/account/my-account) to set their signature and initials, and turn on two-factor authentication if they sign in with a password. They choose which events reach them in [Notifications](/guides/account/notifications).
  </Step>
</Steps>

## Moving members to another workspace

Single sign-on and user provisioning apply to the whole organisation, so everyone they bring in starts in the default workspace. To put someone in a different workspace, add them there and then remove them from the default. Only owners can do this.

<Steps>
  <Step title="Add them to the new workspace">
    In [Members](/guides/settings/members), use **Invite member**, enter their email, and pick the new **Workspace** and the **Permission profile** they should have there. Because they're already in your organisation, they're added straight away and no email is sent.
  </Step>

  <Step title="Remove them from the default workspace">
    Switch to the default workspace, open **Members**, and choose **Remove** from their actions menu. This only takes away their access to the default workspace.
  </Step>
</Steps>

<Warning>
  Always add first, then remove. Removing someone from their only workspace deletes their account.
</Warning>

Permission profiles belong to each workspace, so someone can be a **Viewer** in one workspace and a **Sender** in another. Changes from your identity provider never put people back in the default workspace or reset a profile you've set.

## Related

* [Getting started](/getting-started)
* [Settings overview](/guides/settings/index)
* [Organisation security](/guides/settings/security)
