# Create and manage an organisation

An organisation lets you manage multiple teams from one place. You can manage users and billing across teams, apply security settings, and control access to your organisation's resources.

You can create an organisation from your user dashboard, or convert an existing team into an organisation.

## Create an organisation

> [!note]
>
> [Click here](https://app.northflank.com/s/context/orgs/new) to create a new organisation.

1. From your Northflank dashboard, press CMD+K or click the search icon.

2. Click **Create new**, then select **Organisation**.

3. Enter a name for your organisation.

4. Enter a contact and billing email.

5. Choose a plan.

6. Invite teammates if needed.

7. Click **Create organisation**.

Your organisation is now ready to use. You can add teams, invite members, configure security, and manage billing from your organisation.

> [!note]
>
> You can also [schedule a call](https://cal.com/team/northflank/northflank-enterprise) to discuss onboarding your organisation and choosing the right plan for your needs.

## Convert a team to an organisation

If you already have a team, you can convert it to an organisation. Your existing team will become a team within the new organisation.

> [!note]
>
> You cannot convert a team into an organisation if you are already a member of an organisation.

> [!note]
>
> [Click here](https://app.northflank.com/s/account/settings) to access your team settings page.

1. In your team dashboard, click the **Team** icon.

2. Click **Settings** in the sidebar.

3. Under **Organisation**, click **Convert to organisation**.

4. Enter the organisation name.

5. Click **Convert to organisation**.

## Manage organisation security

### Restrict teams and members

You need permission to manage organisation settings to use these controls on the organisation settings page:

- **Disable members joining external teams:** Organisation members cannot join teams that do not belong to the organisation.

- **Disable inviting external users to organisation teams:** Users who are not members of the organisation cannot be invited to its teams.

- **Use template draft system:** Teams in the organisation must use the template draft system instead of editing templates directly.

- **Disable team cluster creation**: Block new team-owned clusters. Existing clusters are not affected. Teams can still deploy onto organisation clusters with the required access.

- **Disable PaaS deployments:** Teams in the organisation cannot create projects in Northflank PaaS regions. Projects can only be created on BYOC clusters.

- **Disable PaaS registry:** Teams in the organisation cannot use the Northflank PaaS registry. Projects must use a self-hosted registry.

- **Restrict secret groups by default:** Changes the default value of the **Restrict secret group** option when a team in the organisation creates a new secret group. This does not enforce the restriction, and the setting can still be changed when creating the secret group. Existing secret groups are not affected.

### Multifactor Authentication

You can enable **require MFA** from your organisation's security page to enforce multifactor authentication for your organisation members. Organisation members will be prompted to [set up an authenticator application for their Northflank account](https://northflank.com/docs/v1/application/secure/single-sign-on-multi-factor-authentication#multi-factor-authentication) before they can access Northflank, and they will need to enter their one-time passcode on every log in attempt.

You can also set a maximum login session duration in hours, which will automatically log organisation members out and require them to re-authenticate after the time period.

### Clear member login sessions

You can **clear member login sessions** from your organisation's security page to immediately log out all user accounts from your organisation.

### Encryption keys

Enterprise organizations can [use their own KMS](https://northflank.com/docs/v1/application/secure/manage-encryption) to protect secrets stored by Northflank. Configure encryption in Settings → Encryption. Contact Northflank support to enable access. The configuration applies to the organization and does not automatically configure its teams.

## Create organisation roles

You can [manage user roles on an organisational level](https://northflank.com/docs/v1/application/secure/use-role-based-access-control#create-organisation-roles) to ensure compliance with your security policies, restrict users to specific teams, and grant organisational permissions.

## Manage organisation billing

You can add your payment method and tax ID for an organisation to [manage billing for all teams](https://northflank.com/docs/v1/application/billing/pricing-on-northflank) in the organisation.

As well monitoring spend by project and resource type, you can also monitor spend by team.

Invoices for each team's usage can be downloaded from the team billing page.

You can receive [organisation billing notifications](https://northflank.com/docs/v1/application/observe/configure-notification-integrations#organisation-notifications) through a notification integration.

## Configure single sign-on (SSO)

> [!note] Unlock SSO and directory sync
>
> Contact [support@northflank.com](mailto:support@northflank.com) or [schedule a meeting](https://cal.com/team/northflank/northflank-enterprise) to enable single sign-on and directory sync for your organisation.

You can connect your identity provider to Northflank so organisation members can sign in using single sign-on (SSO).

Northflank uses [WorkOS SSO](https://workos.com/single-sign-on) to connect your identity provider using SAML or OpenID Connect (OIDC).

> [!note]
>
> [Click here](https://app.northflank.com/s/context/settings/sso) to configure SSO.

1. In your organisation dashboard, click the **Organisation** icon.

2. Click **SSO** in the sidebar.

3. Under **Link your organisation**, click **Add domain** and enter the domain associated with your organisation, such as `example.com`.

4. Add any other domains used by your organisation.

5. If needed, enable **Allow port security SSO with external domains**. This allows users with external domains in your identity provider to access services that have this option enabled.

6. Click **Update**.

7. Under **SSO**, click **Set-up SSO**.

8. Follow the instructions provided by WorkOS to connect your identity provider.

9. Refresh connections to make sure SSO is working.

Once SSO is configured, users from your identity provider can sign up and sign in to Northflank using your organisation's SSO.

Users can sign in using **Log in with Organisation Single Sign On** on the Northflank login page, or directly at [app.northflank.com/sso-login](https://app.northflank.com/sso-login).

Some identity providers also support signing in directly from your organisation's external dashboard.

By default, Northflank uses just-in-time (JIT) provisioning. A user's Northflank account is created when they sign in for the first time using SSO.

When a user signs in for the first time using your organisation's SSO, they automatically become a member of the organisation. They cannot create teams or resources outside the organisation or leave the organisation without deactivating their account.

You can update your SSO configuration by clicking **Configure SSO**. To disable SSO, click **Disable SSO**.

### Configure SSO settings

After configuring SSO, you can control how users join your organisation.

- **SSO only:** Disables manual email invitations. Users must join through your organisation's SSO.

- **Require approval for SSO sign-ups:** Adds new SSO users to an approval queue until an organisation admin approves or rejects their request.

- **Restrict invites to domain:** Invites can only be sent to email addresses on the organisation’s domain. Requires at least one domain to be configured for this organisation.

> [!note]
>
> Do not enable **Require approval for SSO sign-ups** if you use directory sync to automatically provision organisation members.

### Convert an existing account to SSO

You can convert an existing organisation member's Northflank account to an SSO account.

> [!note]
>
> [Click here](https://app.northflank.com/s/context/settings/members) to access your organisation's members page.

1. Open your organisation's **Members** page.

2. Select the member you want to convert.

3. Click **Convert to SSO**.

The member can then sign in to Northflank using your organisation's SSO instead of their username and password.

> [!warning]
>
> Converting an account to SSO cannot be undone. The member must also leave or delete any teams outside your organisation before their account can be converted.

## Sync your directory

You can connect your organisation's user directory to Northflank to automatically manage organisation members based on directory groups.

Northflank uses [WorkOS Directory Sync](https://workos.com/directory-sync) to connect your directory.

> [!note]
>
> You must configure [single sign-on](#configure-single-sign-on) before you can set up directory sync.

### Set up directory sync

> [!note]
>
> [Click here](https://app.northflank.com/s/context/settings/sso) to configure directory sync.

1. In your organisation dashboard, click the **Organisation** icon.

2. Click **SSO** in the sidebar.

3. Under **Directory sync**, click **Set-up directory sync**.

4. Follow the instructions provided by WorkOS to connect your user directory.

5. Refresh connections to make sure directory sync is working.

### Configure directory sync settings

- **Automatically provision organisation members:** Automatically create Northflank accounts for users in your directory. You can restrict provisioning to specific directory groups.

- **Only sync users in specific directory groups:** Restrict automatic provisioning to selected directory groups, so only users in those groups are added to your organisation.

- **Sync roles with directory groups:** Automatically assign or remove Northflank roles based on a user's directory group membership.

## Next steps

- [Link your Git account: Integrate your Git accounts with Northflank to start building and deploying your code.](/v1/application/getting-started/link-your-git-account)
- [Create a project: Create a project to contain your services, persistent data, secrets, and more.](/v1/application/getting-started/create-a-project)
- [Add a card: Add a credit or debit card to your user or team account, and select the card to charge.](/v1/application/billing/add-a-card)
- [Configure role-based access control: Grant granular permissions and manage users with roles for teams and organisations.](/v1/application/secure/use-role-based-access-control)
- [Grant API access: Create API roles to grant access to the Northflank API, with granular permissions.](/v1/application/secure/grant-api-access)
