Add organization domains and finish SSO setup
Last updated: September 26, 2026
Available on: Web admin portal for administration; Mac, Windows, iOS and Android for SSO sign-in.
Organization admins can request company email domains for the correct Flow organization, verify ownership and finish SSO setup so eligible teammates can join and sign in.
Request domain changes
Adding, changing or removing domains requires Wispr assistance; the portal lists linked domains read-only. Each active domain belongs to one organization.
List every domain separately: mail.example.com is not covered by example.com. Capitalization and surrounding spaces do not affect matching.
Use an organization admin account. The signed-in account determines which organization you manage.
Include the organization name and the email associated with its admin.
Name your identity provider if setting up SSO.
Explain the change. Say whether you are adding domains after a rebrand/acquisition, replacing or removing one, or consolidating organizations. Mention domains planned for later.
There is no published domain-count limit in this guidance; send the complete list and support can confirm any restrictions.
Warning: Removing a domain hides it from settings, stops automatic joining for that domain and removes it from your SSO configuration. You cannot remove the last active domain. Re-adding or restoring a domain is safe to repeat.
Sign in to the Flow admin portal with the intended organization account.
Email enterprise@wispr.ai with the domain list and request details above.
Follow any verification or sales-assistance instructions provided for your organization.
Wait for confirmation before testing affected users.
Adding or removing domains updates the active domains in an existing SSO configuration. If that update fails, the Flow change still applies; support can retry the SSO update.
Restricted or sales-assisted domains
A domain already owned by another organization cannot be added. Supply a non-empty domain; support must resolve any availability-check failure before adding it.
Educational, government, military and treaty-organization domains—including .edu, .gov, .mil, .int, .ac.in and country variants such as .gov.uk and .edu.au—require assistance unless pre-approved. Pre-approval applies to the exact public/country-variant domain, not separate university or free-email restrictions; do not assume an exception.
University restrictions can apply to exact domains with other endings. Free and disposable email domains, including their subdomains, cannot normally be attached as company domains.
The web portal shows Cannot create organization with a public domain for restricted domains. Commercial domains can separately require sales-assisted onboarding; contact your sales/customer-success representative or talk to sales. Send the exact domain and message to support or the sales contact shown.
Verify domain ownership
Organization admins can verify linked domains under Settings → Organization → Domain capture (Optional). Non-admin members cannot view verification status.
Select Start verification, or Continue verification for an unfinished check.
Publish the DNS TXT record at _wispr-verify.<domain> with the exact value wispr-verify=<token> provided by Flow.
Select Check verification.
Success shows Domain verified successfully. If you see TXT record not found yet. Try again in a minute., check the value and retry manually; DNS changes can take an hour or longer.
Tokens do not expire, checks are not automatic, and the TXT value is shown only while unverified. Start verification before checking. Support cannot bypass the exact DNS TXT match.
Only verified domains offer the domain-capture policy dropdown. Domain capture is optional; teammates can continue using Flow without verifying a domain. This does not remove the verification prerequisite for attaching domains during SSO setup.
Finish the SSO connection
Note: SSO setup requires the Enterprise plan and an Admin, SuperAdmin or IT Admin role. Other members cannot use the controls. Lower plans show a disabled SSO / SAML Authentication row with Upgrade to Enterprise plan to use this feature, not Configure SSO.
SSO setup does not register domains. It attaches only registered, DNS-verified domains, excluding older unverified domains. If none are verified, an existing SSO link is reused. Continue from a saved identity-provider configuration rather than starting over.
Open Settings → Organization → User management → SSO / SAML Authentication.
Choose Configure SSO (new), Finish setup (in progress), or Manage SSO (connected).
Follow the identity-provider instructions in the separate setup portal window.
Configure the SAML application and assign the users or groups that should have access.
Complete test authentication if offered.
Select Refresh beside Changed your SSO configuration? Refresh your SSO connection. in Flow.
Successful refresh shows Single sign-on is active., Manage SSO and Enforce SSO for all members. Members can use SSO without enforcement. The page also checks once per organization load without notifications, so it may already show the connection.
Warning: Enforcing SSO blocks other sign-in methods for covered email domains; communicate the change first. Enforcement requires active billing and does not block sign-in if the domain/organization cannot be identified or an unexpected error prevents the check.
Enable Enforce SSO for all members only if required; it appears only after SSO becomes active.
Configure SCIM is separate and remains disabled until SSO is connected and active. See SCIM provisioning for directory setup.
Check membership and billing effects
Domain linking does not change account emails, merge individual account data or purchase additional seats. Organization privacy and data policies apply to members regardless of which linked domain they use.
Seats follow memberships. Pending invitations are not billed until accepted, but count against a seat cap. Separate billing groups can have separate subscriptions and billing owners, so one organization does not always mean one invoice. Review team seats and billing and cost centers before enabling automatic joins.
Registration alone does not guarantee automatic joining: organization membership, automatic-add settings and billing conditions also apply. SCIM-managed organizations skip domain-based automatic joining; IT must add users through the identity provider, not manual membership controls. Exact-domain mismatches, seat caps or membership in another organization can prevent addition.
In multi-team organizations, an automatically added or directory-managed user may need to choose a team in the desktop picker before membership and seat updates. Each person can have only one active team membership per organization.
Desktop and mobile apps do not provide domain-management controls — desktop routes admins to the admin portal instead.
Test member access
Confirm a user with each exact email domain can follow the expected join and sign-in route. Members enter their full work email address for SSO.
Mac and Windows: Select Sign in via browser.
Android: Select Continue with SSO.
iOS: Select More Options → Continue with SSO.
Flow also supports sign-in from an identity-provider dashboard.
SSO setup is unfinished or the connection fails
Setup failures show Failed to set up SSO. Please try again. Connection failures show Unable to connect to your SSO provider. Check your SSO configuration and try again.
Confirm the provider configuration belongs to the same organization and includes a linked, verified domain.
Complete remaining portal instructions using Finish setup when the connection is inactive.
Select Refresh again.
Stop when Flow shows Single sign-on is active. A completed connection can also be recognized during sign-in without a manual refresh. If the domain is already linked to another organization in the SSO configuration, contact support.
A member is directed to another sign-in method
SSO Requires Being A Part Of An Organization means the email's exact domain is not linked to an organization. Use another sign-in method or contact your administrator; ask support to confirm the exact email domain is linked to the intended organization.
Your Organization Has Not Configured SSO requires an admin to finish the connection using the recovery steps above.
Use the displayed account method unless your organization requires SSO, in which case the SSO redirect takes precedence; ask IT to resolve an enforcement mismatch. If SSO is required, sign in with SSO. If accounts are managed through directory sync, ask IT to add the account.
Membership-related sign-in errors can also occur. Organizations can restrict sign-in to members only while billing is active; unexpected errors leave sign-in allowed.
Other access restrictions
For too many sign-in attempts: Wait before retrying. Repeated attempts can prolong a rate limit.
Your network isn't allowed is a separate restriction that can block access even with valid SSO credentials. Use an approved network or VPN and follow network access troubleshooting; changing a domain does not bypass the allowlist.
On desktop and iOS, the blocked screen offers Retry and Sign Out. Retry after switching to an approved network; retrying from a disallowed network blocks again.
Still need help?
Contact support if a domain conflicts with another organization or access still fails after verification and connection checks. Include the error if contacting support.
If access still fails, send support the organization, full domain list, affected email, identity provider, platform and exact error. Include your device and the steps you tried.