> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting started as an enterprise admin

> Set up your enterprise workspace, invite your team, and configure security and app policies.

As a workspace owner or admin, you are responsible for setting up your enterprise workspace for your team. Learn the key tasks to get everything configured and ready.

<Card title="Before you start" icon="circle-check">
  Make sure your Base44 account manager has confirmed that your enterprise workspace is created and that you have owner or admin access to it.
</Card>

<Tip>
  **Have the following ready before you begin:**

  * Your organization's domain name
  * Your identity provider details (if you plan to set up SSO)
  * Email addresses for your team members
</Tip>

***

## 1. Invite your team

Start by adding your team members to the workspace. You can invite people individually or upload a CSV to invite in bulk. Each person is assigned a role that controls what they can do.

| Role       | What they can do                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------ |
| **Admin**  | Manages members and workspace settings. Does not handle billing.                                             |
| **Editor** | Builds and edits apps, uses credits from the workspace pool, and has read-only access to the **Groups** tab. |
| **Viewer** | Has read-only access to specific apps and does not consume credits.                                          |

**To invite members:**

1. Click your workspace name at the bottom left.
2. Click **Settings**.
3. Click **Members and groups**.
4. Click **Invite Members**, then select **Invite by email** to add someone individually or **Bulk invite (CSV)** to upload a CSV.

<Frame caption="Inviting members to your enterprise workspace">
  <img src="https://mintcdn.com/base44/NW3dYIEuS7xwTurl/images/invitemembers1.png?fit=max&auto=format&n=NW3dYIEuS7xwTurl&q=85&s=06201ad3a7581275ec97840388bdf3ec" alt="Members settings with the Invite Members button for adding people to the workspace" width="1721" height="464" data-path="images/invitemembers1.png" />
</Frame>

<Note>
  If you plan to use SCIM provisioning to sync members automatically from your identity provider, you can skip manual invites for those users. See step 5.
</Note>

For full details on roles and credit limits, see [Managing enterprise workspace members](/Enterprise/managing-enterprise-members).

***

## 2. Connect your workspace domain

Connect your organization's domain to your workspace for a branded address and domain-based access control. Your domain also enables domain-based access rules with SSO, so people who sign in with your approved email domain can join your workspace automatically. If your organization uses more than one email domain, you can connect several domains to the same workspace.

<Tip>
  This is also a good time to decide your data residency region. You can choose where your workspace app data is stored: US, EU, or UK. See [Privacy and security](/Community-and-support/Privacy-and-security) for details.
</Tip>

Learn how to [connect your workspace domain](/Enterprise/Enterprise-workspace-domain).

***

## 3. Set up Single Sign-On

Enable SSO so your team signs in with their existing company credentials. Once enabled, anyone with your approved email domain is added to the workspace automatically when they first sign in, using the default role you set for SSO (Viewer by default).

Learn how to [set up SSO for your workspace](/Enterprise/SSO-for-enterprise-workspace).

***

## 4. Configure workspace policies

Control how apps, Superagents, connectors, and external access behave for everyone in the workspace.

* **[Require SSO for all workspace members](/Enterprise/SSO-for-enterprise-workspace#require-sso-for-all-workspace-members):** Require every workspace member to sign in through your SSO provider to access the workspace
* **[Enforce SSO for all apps](/Enterprise/Enterprise-SSO-and-app-visibility#managing-sso-for-app-access):** Require app users to authenticate through your SSO provider
* **[Publishing permissions](/Enterprise/Enterprise-SSO-and-app-visibility#publishing-permissions):** Control who can publish apps and which visibility levels each role can use
* **[Connector management](/Enterprise/workspace-connectors):** Control which external services are available in your workspace, and whether apps can use shared credentials, app user credentials, or both
* **[Disable Superagents](/Enterprise/Enterprise-SSO-and-app-visibility#managing-superagents):** Hide Superagents from all workspace members if your organization has not approved AI agents for use
* **[External collaborators](/Account-and-billing/Managing-your-workspaces#controlling-guest-invitations):** Control whether any member or only admins can invite people from outside the workspace to collaborate on apps
* **[App transfers](#7-move-existing-apps-optional):** Choose who can move apps out of the workspace: **Workspace admins and owners**, **Workspace owners only**, or **Disabled**

***

## 5. Set up automated provisioning (optional)

If your organization uses Okta or Microsoft Entra ID, set up SCIM to automatically sync workspace membership. When someone joins or leaves your organization in your identity provider, their Base44 access updates automatically.

Learn how to [set up automated provisioning with SCIM](/Enterprise/SCIM-provisioning).

***

## 6. Set credit limits (optional)

Set a default monthly credit limit that applies to all workspace members, with the option to override the limit for specific individuals. This is useful for preventing any one member from consuming a disproportionate share of the workspace credit pool.

Learn how to [set credit limits for your members](/Enterprise/managing-enterprise-members#credit-limits).

***

## 7. Move existing apps (optional)

If you or your team have apps in another workspace that you want to bring into the enterprise workspace, you can move them from the app's dashboard. Because the app owner needs the right role in the enterprise workspace before the move, this is often a 2-step process between you and each app owner.

<Check>
  **Before anyone can move an app:**

  * App transfers must be enabled in the source workspace (**Settings** → **Governance** → **App transfers**).
  * On most plans, a workspace owner moves the app out of the source workspace.
  * In an Enterprise source workspace, workspace admins can also move apps out by default, unless the workspace owner restricts this to owners only.
  * The person performing the move must have an editor role or higher in the target workspace.
  * If someone else owns the app, the app owner must also have an editor role or higher in the target workspace.
  * Purchased apps cannot be moved.
</Check>

**Step 1: You invite the app owner (performed by the enterprise workspace admin)**

1. Click your workspace name at the bottom left.
2. Click **Settings** → **Members and groups** → **Invite Members** → **Invite by email**.
3. Enter the app owner's email address.
4. Assign a role. **Editor** or higher is recommended so the app owner can build and contribute in the workspace.
5. Click **Invite**.

**Step 2: The app owner accepts the invite, then the app is moved**

The app owner opens the invitation email from Base44 and clicks **Accept Invitation**. The move then happens from the app's current workspace and is performed by someone allowed to move apps out of it. On most plans that is a workspace owner; in an Enterprise source workspace, a workspace admin can also move apps out by default. If the app is in someone's personal workspace, that person is the workspace owner and can move it themselves.

1. Go to your app's dashboard.
2. Click **Overview**.
3. Click the **More Actions** <Icon icon="ellipsis" /> icon next to **View usage**.
4. Click **Move app**.
5. Select the enterprise workspace from the **Target Workspace** drop-down.
6. Click **Move App** to confirm.

<Note>
  Workspace owners and admins on the Enterprise plan can restrict who's
  allowed to move apps out of the workspace. Go to **Settings** →
  **Governance** → **App transfers** and choose **Workspace admins and
  owners**, **Workspace owners only**, or **Disabled**. By default, both
  owners and admins can move apps out. On other plans, only workspace
  owners can.

  After the move, the app uses the enterprise workspace's credit pool. The app owner and published app URL do not change. App data and media remain intact. Some workspace-owned connectors and integrations may need to be reconnected after the move.
</Note>

For full details on moving and transferring apps, see [Managing workspace apps](/documentation/using-your-workspaces/managing-your-workspace-apps).

***

## 8. Explore more enterprise features

Once the basics are in place, explore additional security and access controls.

* [IP allowlist](/documentation/enterprise/ip-allowlist): Restrict workspace access to approved IP addresses and networks
* [Workspace secrets](/Enterprise/workspace-secrets): Create and manage API keys for programmatic access to your workspace, including audit logs, the Monitoring API, SCIM, and app deployment
* [Connector management](/Enterprise/workspace-connectors): Manage connector availability across your workspace, review affected apps before disabling access, and control how apps connect to external services

***

## Setup checklist

<Card title="Setup checklist" icon="list-check">
  <Icon icon="circle-check" iconType="regular" /> **[Invite your team](#1-invite-your-team):** Add members by email and assign each the right role\
  <Icon icon="circle-check" iconType="regular" /> **[Connect your workspace domain](#2-connect-your-workspace-domain):** Give your workspace a branded address and domain-based access control\
  <Icon icon="circle-check" iconType="regular" /> **[Set up Single Sign-On](#3-set-up-single-sign-on):** Let your team sign in with your company's identity provider\
  <Icon icon="circle-check" iconType="regular" /> **[Configure workspace policies](#4-configure-workspace-policies):** Control publishing permissions, app visibility, Superagents, external collaborators, and app transfers\
  <Icon icon="circle-check" iconType="regular" /> **[Configure connector management](/Enterprise/workspace-connectors):** Choose which external services apps can use and how they connect\
  <Icon icon="circle-check" iconType="regular" /> **[Set up the IP allowlist](/documentation/enterprise/ip-allowlist):** Restrict workspace and app access to your trusted networks\
  <Icon icon="circle-check" iconType="regular" /> **[Manage workspace secrets](/Enterprise/workspace-secrets):** Create API keys for programmatic access to your workspace\
  <Icon icon="circle-check" iconType="regular" /> **[Set up automated provisioning](#5-set-up-automated-provisioning-optional):** Sync workspace membership from Okta or Entra with SCIM *(optional)*\
  <Icon icon="circle-check" iconType="regular" /> **[Set credit limits](#6-set-credit-limits-optional):** Set a monthly credit limit per member *(optional)*\
  <Icon icon="circle-check" iconType="regular" /> **[Move existing apps](#7-move-existing-apps-optional):** Bring apps from personal workspaces into the enterprise workspace *(optional)*
</Card>

<Tip>
  For a full overview of security features available in Base44, see [Security overview](/Setting-up-your-app/security-overview).
</Tip>

***

## Getting help

As an enterprise customer, you have access to dedicated support.

* **Dedicated account manager:** Your account manager is your main point of contact for guidance and ongoing support
* **Priority support:** Use the Help menu inside Base44 to open a support ticket and get prioritized responses
