---
title: "Set up your team & SSO"
summary: "How to invite teammates, assign roles and job families, connect single sign-on, and run access reviews as a Zovos owner."
updated: "2026-10-07"
section: "Get started"
url: "https://zovos.ai/docs-team-setup.html"
---

# Set up your team & SSO

Team administration lives on the **Team and roles** screen, listed as **Team** in the Administration group of the sidebar. This guide is for the owner setting up access. It covers bringing teammates in, deciding what they can do, connecting single sign-on, and producing the access evidence an examiner will ask for. For what each role means, read [Roles and permissions](docs-roles-permissions.html).

## How access works

Zovos signs people in through your institution's identity provider using single sign-on. There is no Zovos-specific password, which means your existing joiner, mover and leaver process stays the control of record. When someone leaves your directory, they lose the workspace with everything else.

There are two supported ways for a person to arrive in your workspace, and one separate path for regulators.

## Invite a teammate

On **Team and roles**, choose **Invite member**. You provide an email address and an initial role. You can also add a job title and job families, either one by one or from a preset. Then choose **Send invitation**.

The invitee receives an invitation email and appears in the member list as **Invite pending**. That email is sent by WorkOS, our identity partner, from its own sending domain rather than from a Zovos address. Tell your mail team before you start, so the first invitations do not sit in quarantine. Their access turns on when they sign in for the first time. That sign-in is what accepts the invitation, and it cannot be done for them from the admin screen. A pending row carries **Re-invite** and **Cancel** actions and nothing else.

Every system role except Examiner, including Risk Approver, comes with a directory mapping, so you can invite into it straight away. A custom role you create has no mapping, and an invitation into it is refused until an owner adds one on the **Access & SSO** tab in Settings.

Get a second approver signed in early. Maker-checker means the person who submits a decision cannot approve it, and critical decisions need two distinct signers, so a workspace with one signed-in person cannot complete them. An invitation is not enough. The second person has to sign in themselves.

## Members provisioned by your directory

Directory synchronization is enabled with us during onboarding. There is no self-serve switch for it in the product. Once it is on, membership and roles flow from your identity provider instead. You add the person to the directory group, or assign the role directly in your provider. They are then provisioned into Zovos on the next sync and sign in with your organization's normal SSO button. No separate invitation is involved.

A directory-managed member's row shows **Role from your identity provider** in place of the role editor, because their role is resolved from your directory at every sign-in. Change it in your provider, not here. An unmapped directory group is refused rather than defaulted to a role, so a brand-new person who cannot sign in usually needs a group or role assignment on your side.

## Assign and change roles

For members who are not directory-managed, edit the roles on the member row. A member can hold several roles and access groups, within the combination rules that [Roles and permissions](docs-roles-permissions.html) describes. The change takes effect on the member's next request and is written to the audit trail with your name against it.

Each row also carries lifecycle actions:

- **Suspend.** Access is turned off and membership is retained. Use this for leave or an investigation.
- **Offboard.** This is the departure state, and it keeps the historical record intact.
- **Reactivate.** This restores a suspended member.

Two guards keep the workspace from being emptied by accident. You cannot suspend yourself. The product also refuses to suspend, offboard or demote the last active member who holds settings access, including through a role change, so there is always somebody left who can administer the workspace. You also cannot remove settings access from your own role or from the last role that holds it.

## Set job families and titles

Job families say what a person does, and they personalize the workspace for that person. They order the sidebar, choose the dashboard panels, and give a business-line owner a My work home. They never grant a permission and never change the price. [Roles and permissions](docs-roles-permissions.html) lists the families and presets and explains exactly what they change.

Each member row on **Team and roles** shows the person's title and job families beside their role. Choose **Families** on the row to edit them. You can pick several families, start from a preset such as Chief risk officer or Director, and set a job title. Editing families needs the permission to manage the team, which the Owner role holds. Every change is written to the audit trail. Settings also lists each member's families, read-only, on the **Access & SSO** tab.

If directory synchronization is on, an owner can map directory groups to access groups on the Directory Sync panel under Integrations in Settings, and a group's job families come with it. When a person joins a mapped directory group, they receive the access group. When they leave it, they lose the group and every role and family it granted. Families set on the person directly stay until you edit them on the Team screen.

## Add an external examiner or auditor

Regulators are not invited as teammates. An owner grants an examiner a time-boxed, scope-limited session for a named examination, read-only apart from a few fieldwork actions, and the examiner role cannot be handed out through single sign-on or directory sync. The examination workflow is covered in [Exam management and audit readiness](docs-exam-management.html).

An outsourced internal-audit firm or an independent AML/CFT tester is different. Give that firm's staff a custom role built from the **External auditor** starting point, which [Roles and permissions](docs-roles-permissions.html) describes.

## Access reviews and evidence

The Team and roles screen carries a periodic access review, so recertification is a recorded exercise rather than a spreadsheet emailed around the compliance team. You can also export access-control evidence as CSV or PDF straight into an exam binder. The export covers the member list, roles, statuses and the review record.

Every membership, role and status change is in the append-only [audit trail](docs-audit-trail.html), which is the artifact an examiner asks for when they ask how you control access.

## Notes and limits

- Connecting your identity provider is done outside the product, on the one-time setup link we send during onboarding, and so is turning on directory synchronization. Mapping your directory groups and role slugs to Zovos roles is different. That is an owner-editable panel on the **Access & SSO** tab in Settings, and you change it yourself whenever your directory changes. See [Onboarding your institution](docs-onboarding.html).
- Everyone signs in at the same address, https://app.zovos.ai/login, with one SSO button and no institution picker. A session ends after 30 minutes without activity, and in any case at the end of its lifetime. The lifetime is eight hours unless an owner sets it between one and twelve hours under **Session lifetime** on the **Access & SSO** tab, and a change applies from the next sign-in. An owner can end a member's sessions early from the **Sessions** panel on their row on the Team screen. No separate Zovos password exists to expire.
- An owner can optionally restrict the workspace to a list of your own IP ranges, per tenant, IPv4 or IPv6. It is maker-checker gated. A change is staged and only takes force once a second approver signs it off. Examiner sessions are exempt, because regulators come from networks you do not control. Take the lockout warning seriously. If the allowlist excludes your own address, recovering it needs Zovos support.
- A member who has been invited but has never signed in cannot approve anything, and the product will not let an administrator mark them active.
- Seat usage in settings is drawn live from your active members and shown beside your contracted number. It is informational. The figure is there for your own planning and for a renewal conversation, and the product does not enforce it as a cap.
