Skip to main content

Plan Your Organization Setup

Set the tenant identity and plan in Organization General, then review feature availability and reusable content in Organization Settings before broad onboarding. The wider Organization setup also decides how people join, which public features are allowed, how API keys and webhooks are controlled, whether recordings are available, and which identity provider owns user lifecycle.

Decisions Before Inviting Users

  • Who is the organization owner and who can approve security or access changes.
  • Whether users join by manual invitation, SSO, Microsoft Entra synchronization, approved domains, or a mixed rollout.
  • Which teams need separate access boundaries for agents, workflows, connections, data, and Memory.
  • Which connection types should be allowed tenant-wide and which should be disabled until reviewed.
  • Whether public chat, public sharing, webhooks, API keys, and recordings are allowed.
  • Which model connections need token limits by organization, team, or user.
  • Where admins will review incidents: Tool Executions, Audit Log, conversation history, workflow history, and connected-system logs.

Organization Tabs To Review

TabWhat to decideAdmin note
GeneralPlan, subscription, organization identity, and token consumptionConfirm the tenant name and billing owner before production rollout
Api KeysNamed keys for external integrationsKeys should map to a real system and owner; delete keys after tests
SettingsDefault agent, module availability, apps, extensions, and content importsEnable only the surfaces approved for the organization
SecuritySSO, Entra team sync, sharing, integration policy, AI safety, and retentionTest sign-in before syncing users and treat public sharing as an explicit approval

Identity Setup Pattern

For a small pilot, manual invitations are usually enough. For a managed organization, use SSO and Entra synchronization so user lifecycle follows the identity provider. For multi-domain organizations, document which email domains are allowed before enabling domain-based association.

Use this rollout order:

  1. Configure SSO metadata and test one admin sign-in.
  2. Create a pilot team manually.
  3. Invite or sync a small group.
  4. Verify their team membership, role, and visible agents.
  5. Expand synchronization or invitations only after the pilot users land in the correct organization.

Security Switches

Organization security controls can block features even when an agent or page is configured. If a user reports that public chat, webhooks, API keys, or recordings are unavailable, check organization policy before debugging the agent.

FeatureUse it whenKeep disabled when
Public ChatAn approved agent should be reachable outside the internal appPrompts, data, privacy link, or public access are not reviewed
WebhooksExternal systems should trigger Siesta AI workflowsThere is no API key owner or replay/failure handling plan
API KeysBackend systems or developer integrations need server-side accessThe integration is still exploratory or credentials would be copied into clients
RecordingsMeeting or voice workflows require stored recordingsRetention, sharing, or consent requirements are unclear

Token Budget Planning

Token limits are configured on model connections. Use them when a shared model connection powers high-volume agents, workflows, research, or automation. Start with organization-level defaults, then add team or user limits for groups that need a different budget or should be temporarily disabled.

Common Mistakes

  • Inviting a full department before SSO and team boundaries are tested.
  • Leaving test API keys or webhooks active after a pilot.
  • Enabling public chat before the agent prompt, privacy link, uploads, and feedback settings are reviewed.
  • Sharing model connections without token limits for high-volume workflows.
  • Syncing Entra groups before confirming group ownership and membership.
  • Treating Organization Security as a troubleshooting afterthought instead of a launch gate.

After the tenant defaults are agreed, create the pilot teams and assign their users.