Employees sign in with their work e-mail or your own single sign-on. You add people by domain, invite or SSO, set the policy once, and see who is protected and who is under attack — without ever seeing anyone's mail.
14-day full-strength trial for the whole organization · no card · per-seat pricing after
No agents to deploy, no mailbox migration. Create the organization, bring your people in, decide what they must run.
Sign in with your work e-mail, name the organization and add your company domain. You are the owner. Nothing about your personal Google account is involved.
Getting started →Paste a list of addresses with a role, or verify your domain with one DNS record and let anyone at @yourcompany join as an employee the first time they sign in.
Inviting people →Require the extension or the mobile app, decide whether members connect a work mailbox, lock a setting pack. Then see coverage and threats across the organization.
Policies →One login box for everyone. The domain of the e-mail decides how a person signs in — nobody picks a provider, and a personal Google account is never accepted for a company address.
Your employee types their work address and receives a 6-digit code and a one-click link at that address. Valid for ten minutes, single use. Works the moment your domain is verified — no identity provider needed.
Plug in the identity provider you already run. OKY uses standard OpenID Connect, so your MFA, device rules and off-boarding apply automatically. Map a group to the OKY admin role and you are done.
Any other OpenID Connect provider works too — you paste an issuer URL, a client ID and secret.
The corporate dashboard answers three questions: who is protected, who is being attacked, and what needs a decision. It does not open anyone's inbox.
Seats used, who has the extension, who has the mobile app, who connected a work mailbox — and who is still unprotected.
Threats blocked today, this week, this month across e-mail, links, apps and crypto. Filter by member, type or period. Export as CSV.
Everyone in the organization with their role, coverage and last activity. Invite, remove, promote. Pending invites in one list.
Every invite, role change, policy edit and sign-in method change, with who did it and when. Exportable.
Every membership carries one role. Owners run the company account, admins run security, employees are protected. Roles are scoped to your organization — nothing leaks between companies.
| Capability | Owner | Admin | Employee |
|---|---|---|---|
| Own dashboard, scans, connected accounts | ✓ | ✓ | ✓ |
| Organization overview, coverage, member list | ✓ | ✓ | — |
| Invite and remove members, admin ↔ employee | ✓ | ✓ | — |
| Domains, sign-in method (SSO), policies | ✓ | ✓ | — |
| See a member's threats (never clean mail or content) | ✓ | ✓ | — |
| Audit log and CSV exports | ✓ | ✓ | — |
| Promote or demote owners, billing and seats, delete organization | ✓ | — | — |
At least one owner always remains. Full detail in the roles guide →
Tell us your domain and who should own the account. We create the organization, verify the domain with you, invite the owner and stay on the line while the first employees sign in and install the extension. Public-sector and regulated teams: ask us about data residency and self-hosting.
Everything else is in the corporate docs.
Questions, ideas, or a threat you want checked? Reach out and we'll show you exactly how OKY fits into the way you already work — inbox, links, crypto and apps.