OKY for organizations

Everything an owner or admin needs to run OKY for a company: creating the organization, bringing people in, verifying domains, roles, policies and single sign-on.

An OKY organization gives every employee the same protection they would get on a personal account — but signed in with a work identity, managed by your admins, and visible as one picture on the corporate dashboard. This manual walks through setup in the order you will actually do it.

Start here

Single sign-on walkthroughs

SSO is optional. Every organization works on day one with work e-mail codes; add your identity provider when you want your own MFA, device rules and off-boarding to apply. Each guide ends with the exact fields to paste into OKY and a troubleshooting list.

Terms used in this manual

TermMeaning
OrganizationYour company's account in OKY. Has a name, a short slug (used in URLs), one or more e-mail domains, members, a policy and a plan.
SlugThe short identifier chosen when the organization is created, e.g. acme. It appears in your SSO redirect URI: https://api.oky.ai/auth/oidc/acme/callback.
MemberA person who belongs to the organization with a role: owner, admin or employee.
Verified domainAn e-mail domain you have proven you control with a DNS record. Unlocks auto-join and blocks personal-Google sign-in for that domain.
Work e-mail codeThe default sign-in: a 6-digit code and a one-click link mailed to the work address, valid for ten minutes.
OIDC / SSOSign-in through your identity provider using OpenID Connect (Google Workspace, Microsoft Entra ID, Keycloak, Okta or any compliant provider).
CoverageWhether a member actually has the protection in place: browser extension installed, mobile app installed, work mailbox connected.
Managed memberAn account created through the organization (invite, SSO or auto-join). Removing it suspends the account after 30 days unless the person re-homes it as personal.

Where things live

Owners and admins open oky.ai/dashboard and use the Organization section in the left navigation:

  • Overview — threats today / 7 days / 30 days, coverage, pending invites, plan status.
  • Threats — the org-wide feed with filters and CSV export.
  • Members — list, roles, coverage per person, invite, remove, promote.
  • Policies — setting packs, required extension / mobile app, mailbox policy.
  • Sign-in & domains — domains and verification, login method, SSO configuration, Test login.
  • Billing (owner) — plan, seats, trial or active status.
  • Audit log — who did what, when.

Employees see their own dashboard as usual, with an organization badge and any locked settings shown as “Managed by <your organization>”.

Prefer a guided setup? Write to sales@oky.ai — we onboard pilot organizations by hand, including domain verification and the first invites.