Enterprise
Run several organizations under one enterprise — enforced policies, members, verified domains, OIDC single sign-on, SCIM provisioning, managed users, and enterprise billing.
"An enterprise owns multiple organizations under one contract, inherits its plan to them, and can enforce audit / read-access policies org-wide." Enterprises also bring verified company domains, single sign-on, and SCIM provisioning.
Create an enterprise
- Open the account menu and choose Enterprises.
- Under Create an enterprise, enter a name (for example
Acme Inc) and click Create.
The enterprise appears under Your enterprises with your role. Click it to open its console. "Billing for a new enterprise is provisioned by sales — contact us to activate the contract." See Billing for the ways to activate it.
The enterprise console
Only enterprise owners and admins can open the console; anyone else sees "Only enterprise owners and admins can view this console." The header shows the enterprise's name, its Plan, and its billing status.
The console's tabs:
- Policies, Organizations, Members
- Identity & provisioning: Domains, SSO, Provisioning (SCIM), Managed users, Join requests
- Enterprise: Audit log, Billing
SSO, Provisioning (SCIM), Managed users, and Join requests need an active enterprise subscription. Until billing is active they show a lock, and opening one shows "… requires an active enterprise subscription" with an Activate enterprise billing button.
Policies
Enforced policies (org-wide): "When enforced, every member org has this ON and cannot turn it off."
| Policy | Forces on, in every member organization |
|---|---|
| Require audit | Enterprise Audit |
| Require read-ACL | File / Code Access Control |
| Require 2FA | Emailed sign-in codes for email + password sign-ins |
Click Enforce to turn a policy on, or Enforced — turn off to release it. Only enterprise owners can change policies; admins can view them.
Organizations
The Organizations tab lists the enterprise's member organizations.
- To add one, enter its organization id (it looks like
org_…) and click Attach. "You must own an org to attach it." - To remove one, click its delete icon. "Detaching removes the enterprise's policy ceiling from that org."
Member organizations inherit the enterprise's plan and its enforced policies.
Members
The Members tab lists Enterprise members with their roles: owner, admin, or member.
- To add someone, enter their user id (it looks like
usr_…), pick a role, and click Add. - Change a role with the drop-down, or remove someone with the delete icon.
Only owners can make changes, and the last owner can't be removed.
Domains
Verify your company's email domains to enable SSO sign-in and domain-based joining.
- Enter the domain (for example
company.com) and click Add domain. It's listed as pending. - The console shows a file address on your domain and a token: "Publish this file on the domain, then click Verify", "containing exactly:" the token. Publish a file at that address whose entire content is the token.
- Click Verify. The domain changes to verified.
For a verified domain, pick a Join policy:
| Join policy | What happens |
|---|---|
| off | No domain-based joining |
| request | Users request to join; approve them on the Join requests tab |
| auto | Users are added to the chosen organization automatically when they sign up |
For request and auto, also pick the target organization.
Single sign-on (SSO)
The SSO tab configures OpenID Connect (OIDC) single sign-on with your identity provider (IdP).
- Copy the Redirect / callback URL (paste into your IdP) shown in the console and register it in your IdP.
- Check Enable SSO sign-in.
- Enter your IdP's Issuer URL (for example
https://idp.example.com), Client ID, and Client secret. - Click Save SSO config.
The client secret is never shown again. Once saved, the field says "(stored — leave blank to keep)"; leave it blank to keep the stored secret, or type a new one to replace it.
Email-based SSO sign-in needs at least one verified domain. Until you have one, the tab reminds you: "Verify a domain on the Domains tab to enable email-based SSO sign-in for your members."
Members then sign in with Enterprise single sign-on on the sign-in page. See Security and 2FA.
Provisioning (SCIM)
The Provisioning (SCIM) tab lets your IdP create and manage accounts automatically.
- Copy the SCIM base URL (configure in your IdP) shown in the console into your IdP.
- Click Generate SCIM token and copy it into your IdP. "Copy this token now — it is shown only once."
- Active tokens lists each token with when it was created and, if set, when it expires. Revoke a token with its delete icon.
Group mappings lists the groups your IdP pushes. Link a group to an organization to grant its members membership of that organization. Set it back to "— not linked —" to revoke the membership that group granted, unless another linked group still grants it.
Managed users
Accounts your IdP provisions through SCIM appear on the Managed users tab with their status. Click Deactivate to suspend an account.
A managed user can only access organizations that belong to their enterprise.
Join requests
When a domain's join policy is request, people from that domain appear on the Join requests tab. Click Approve to add them to the target organization, or Deny to reject the request.
Audit log
The Audit log tab shows the newest events across all of the enterprise's organizations. See Audit logs.
Billing
"The enterprise holds one consolidated subscription; member orgs inherit the enterprise tier and its enforced policies. Premium features (SSO, SCIM provisioning, managed users) require an active subscription."
There are two ways to pay:
| Path | How it works |
|---|---|
| Card (self-serve) | Click Activate enterprise billing and complete the Stripe checkout on the same page. After "Checkout complete — your subscription will activate once Stripe confirms.", manage it with Manage billing, which opens Stripe's portal to update the card, change the plan, download invoices, or cancel. |
| Contract (purchase order) | "This enterprise is billed on a contract (purchase order)." Your agreement, invoices, and renewal are handled by your account team. Contact sales to activate, renew, or change seats, tier, or billing details. |
Only enterprise owners can start the card checkout.
Billing and plans
GitDB plans and prices, how to subscribe and manage your subscription, Team seats, the daily MCP allowance, and what happens when you hit a rate limit.
Security and 2FA
Protect your gitdb.co sign-in with emailed one-time codes, understand how GitHub and Google sign-ins and organization requirements interact with it, and sign in with enterprise SSO.