Layer8 Systems is built for a team, not just an individual — with organizations, roles, and single sign-on for the identity provider you already run.
Invite your team
Under Settings → Organization, invite teammates by email and assign a role:
- Owner / Admin — manage members, billing, and app access.
- Member — use the apps; see what's shared with them.
Sharing is explicit: maps, notes, and assets are private to their creator until shared with a specific person at a specific permission level. There's no ambient org-wide access.
Single sign-on (SSO)
Layer8 Systems authenticates through Clerk, which supports enterprise SSO out of the box:
- Microsoft Entra ID (formerly Azure AD) — SAML or OIDC.
- Google Workspace — OIDC / "Sign in with Google".
- Okta, OneLogin, and any SAML 2.0 IdP.
Because identity is delegated to your IdP, offboarding is immediate: disable a user in Entra or Workspace and their Layer8 Systems access ends with the next token refresh — no separate account to remember to remove.
Setting it up: SSO connections are configured per-organization on Team plans. Once your IdP is connected, users signing in with a matching email domain are routed to your identity provider automatically.