# Setting up domain access

Last updated 9 days ago

### Who can use this feature

- Supported on **Enterprise** plans
- Org admins and IT admins can configure domain access.

Domain access lets you claim domain(s) to be associated with your Writer organization, in order to enable seamless access for users from your company. Domain access is required before setting up domain discoverability, or setting up SSO and/or SCIM.

## What is domain access?

Domain access lets you claim domain(s) to be associated with your Writer organization, in order to enable seamless access for users from your company. With domain discoverability, coworkers who sign up for Writer with a company email address can join your Writer organization with the appropriate permissioning and controls. Claiming a domain is also required in order to set up SSO and SCIM.

Select the profile icon in the bottom right and then select the gear icon next to **Org settings**. From the **Admin settings** menu on the left select **Access & provisioning** and you’ll be taken to the domain access settings.

## Claiming domains

Claiming a domain lets Writer know that your organization owns that domain exclusively. Here are a few important things to note before claiming a domain:

- You can **only claim the domain of the email address you're signed in with.** So, if you're signed in with mary@writer.com, you'll be able to claim the "[writer.com](/content/site-root.html)" domain. To claim a domain that you are not signed in with, reach out to [support@writer.com](mailto:support@writer.com).
- You’ll need to claim a domain _before_ you can set up SSO and SCIM.
  - To learn more about setting up SSO, [click here.](https://support.writer.com/article/43-setting-up-saml-sso)
- If your organization has already claimed one domain, but you’re signed in with a different company email domain that is also valid, you can claim that domain too. So, if you’ve claimed "[writer.com](/content/site-root.html)" but you’re signed in as mary@qordoba.com, you can claim the qordoba.com domain as well. Follow the same steps as claiming a new domain.
- If you try to claim a domain that’s already claimed by another Writer organization, you’ll see a message letting you know. You can reach out to [support@writer.com](mailto:support@writer.com) in order to claim this domain across multiple organizations.
- If you’re signed in with a personal email (like Gmail or Yahoo), you’ll see a message saying the domain can’t be claimed.

### How to claim a domain & configure domain discoverability

Go to **Admin settings settings** > **Access & provisioning** > **Access**

If your domain hasn't been claimed yet, you'll see a button that says **Claim domain**.

Select Claim domain to open the domain discoverability settings.

When domain discoverability is toggled on, users logging in with an email address using your claimed domain will be asked to join your org:

Example of a user being prompted to join an existing organization

### Setting up default teams and roles

By default, new members joining through domain discoverability will be added to a specific team and role. You can always edit a user’s role later on. As a security best practice, we recommend setting the default role as “Team member". Learn more about access roles [here](https://support.writer.com/article/67-enterprise-plan-roles-and-permissions).

Select if new users should be added as Lite or Pro users. Lite seats get limited access to WRITER features. Learn about Lite seats [here.](https://support.writer.com/article/327-lite-seats)

**TIP:** Consider creating a _New Users_ team as a staging area to help org admins identify all new users and sort them into appropriate teams.

You can select multiple teams from the _Default team_ menu if you’d like new users to be added to more than one team.

Select **Save**.

## Password access

Password access determines whether new users joining with an email in your domain will require admin approval to join your organization or not.

To configure password access, navigate to **Admin > Access & Provisioning** and select the **Access** tab.

By default, password access is set to **on**, unless you have SSO configured.

If you let users sign in with a password, you can decide if new users can join your Writer org automatically, or if an org admin needs to approve the request first.

**NOTE:** These settings apply to **all** domains claimed by your organization.

From below the Access approval section you're able to prevent users from giving access to your WRITER org when they share content from within WRITER. Toggle the setting icon below **Sharing invitations** to turn this off. If enabled, users accepting invitations through shared content are added to your WRITER org as a Lite user. Learn more about Lite seats [here](https://support.writer.com/article/327-lite-seats).

If you'd like to prevent your users from being able to create personal orgs using your organization's email domain toggle the setting below **Personal organizations** off.

## Managing claimed domains

Once your domain is claimed, you can edit the previous options by selecting the icon in the upper right of the domain module. If you run into any issues, please reach out to support@writer.com.
