Layer8 is built for a team, not just an individual — with organizations, roles, and single sign-on for the identity provider you already run.
Invite your team
Under Settings → Organization, invite teammates by email and assign a role:
- Owner / Admin — manage members, billing, and app access.
- Member — use the apps; see what's shared with them.
Sharing is explicit: maps, notes, and assets are private to their creator until shared with a specific person at a specific permission level. There's no ambient org-wide access.
Single sign-on (SSO)
Layer8 authenticates through Clerk, which supports enterprise SSO out of the box:
- Microsoft Entra ID (formerly Azure AD) — SAML or OIDC.
- Google Workspace — OIDC / "Sign in with Google".
- Okta, OneLogin, and any SAML 2.0 IdP.
Because identity is delegated to your IdP, offboarding is immediate: disable a user in Entra or Workspace and their Layer8 access ends with the next token refresh — no separate account to remember to remove.
Setting it up: SSO connections are configured per-organization on Team plans. Once your IdP is connected, users signing in with a matching email domain are routed to your identity provider automatically.
Automated provisioning (SCIM)
For larger teams, SCIM provisioning keeps Layer8 membership in sync with your directory — users added to (or removed from) an Entra/Workspace group are created or deprovisioned in Layer8 automatically, so your member list is never stale.
Contact us to enable SCIM for your organization.