You never manage a spreadsheet of secrets. Every method below ends the same way: the person signs in with a work identity and appears in Members with a role.
Choose a method
| Method | Best for | Requires |
|---|---|---|
| Invite | Specific people, specific roles (admins, a pilot group, contractors on your domain). | Nothing — works even before the domain is verified. |
| Auto-join by domain | Everyone at the company. Zero admin work per person. | Verified domain and Join policy: auto-join. |
| SSO just-in-time | Companies with an identity provider; roles can come from groups. | SSO configured and tested; a group→role map if you want admins from groups. |
Invitations
- Open Organization → Members → Invite
Paste one address, or many — one per line, comma-separated, or a CSV column. Only addresses on your organization's domains are accepted.
- Pick the role
Employee for most people, admin for those who will run security. Owners are promoted later by an existing owner (see Roles).
- Send
Each person receives an e-mail from OKY with a link. The invite is valid for 14 days. Pending invites are listed on the Overview and in Members, with Resend and Revoke.
- They accept
The link takes them to sign-in. They prove the address (work e-mail code, or your SSO if it is on) and land in their dashboard already a member with the pre-set role.
An invite proves intent for that one address, so invites work on an unverified domain. Auto-join does not — see below.
Auto-join by domain
With auto-join on, anyone who signs in with an address on a verified domain of your organization becomes an employee automatically — no invite, no waiting. Switch it on under Organization → Policies → Join policy: choose Auto-join by verified domain (or keep Invite only). The option is greyed out until at least one domain is verified.
- New joiners always get the employee role; promote admins in Members.
- Auto-join respects the seat limit. A join beyond it is refused with a message and the owner is notified.
- You can run both: auto-join for the crowd, invites for people who need admin from day one.
SSO just-in-time
When SSO is configured, the first successful login through your identity provider creates the membership. If you set a group → role map (for example oky-admins → admin) the role is taken from the groups claim on every login; people without a matching group are employees. See the SSO guides: Google Workspace, Microsoft Entra ID, Keycloak, Okta.
People who already had a personal OKY account
If someone already used OKY with the same work address, joining the organization links that account rather than creating a new one — their history and settings stay. Linking by address only happens for verified domains (you control the domain, so it is safe). Such members are marked linked rather than managed; removing them ends the membership but keeps their personal account.
Seats
Your plan has a seat limit shown under Organization → Billing. Every member — owner, admin or employee — uses one seat. Pending invites do not. When you hit the limit, new joins are refused and the owner receives a notification; raise the seat count or remove inactive members.
Troubleshooting
The invite e-mail did not arrive
Check spam and any company mail gateway rules for messages from oky.ai. Use Resend in Members. Invites cannot be sent to consumer addresses (gmail.com, outlook.com …) or to domains that are not on your organization.
“This address belongs to an organization — sign in through your organization”
The person tried personal Google sign-in with an address on your verified domain. Ask them to use the e-mail box on the sign-in page (work e-mail code) or your SSO button instead.
“No seats available”
The seat limit is reached. An owner can raise it under Billing, or remove members who left.
Someone joined with the wrong role
Members → change role. Admin ↔ employee can be done by any admin; making someone an owner needs an owner.