Custodos is live: every leading AI model, your data stored securely in Switzerland.Start free trial
Administration

Access and SSO

In the Access section, admins decide how people sign in to the workspace and who may be invited: with SSO through Google Workspace or Microsoft Entra, and with a restriction to the company domain.

Last checked on 28 September 2026

On this page

How sign-in works in Custodos

Custodos works without passwords. People sign in with a sign-in link that Custodos emails to them, or through Continue with Google and Continue with Microsoft. The two buttons only appear when these sign-in methods are set up. Details are under Signing in.

Without further settings, every invited person can choose their method. With Require SSO you decide that only sign-in through your company account counts for your workspace.

Requiring SSO

When Require SSO is on, everyone must sign in through your company's Google Workspace or Microsoft Entra organisation. Custodos binds the workspace to exactly the organisation the admin is signed in with when switching it on. Private Google accounts without Google Workspace and personal Microsoft accounts do not count as an organisation.

  1. 1

    Sign in with your company account

    Sign in through Continue with Google or Continue with Microsoft with your company account, not with the emailed sign-in link.
  2. 2

    Turn on the switch

    Open Settings, section Access, and turn on Require SSO.
  3. 3

    Check the organisation

    Below the switch you now see Organization: … with the bound organisation. The change appears in the activity log as Access changed.

What members experience afterwards

Anyone not signed in through the bound organisation sees the Sign in with SSO page with a Sign out button when they open the workspace. Chatting, uploading and changing anything only work again once they sign in afresh with their company account.

The same applies to new people: an invitation or an invitation link can only be accepted after signing in through Google or Microsoft. The same person's other workspaces are not affected; the emailed sign-in link keeps working there.

Restricting invitations to a domain

In the Restrict invitations to domain field, enter your company's domain, for example company.co.uk. The domain only, without @ and without a path. Leave the field empty to allow any address. The field saves as soon as you leave it.

  • Custodos refuses invitations to addresses on other domains.
  • Anyone joining through the invitation link must be signed in with an address on this domain.
  • Existing members with a different address stay in the workspace.
  • Someone who registers with an address on this domain and wants to create their own workspace may be shown your workspace's name with a note that their company already uses Custodos, and asked to request an invitation.

What Custodos does not offer for access

SSO in Custodos runs through sign-in with Google and Microsoft. With SSO, the sign-in rules your IT has set there apply, such as mandatory two-factor sign-in.

Read next

Still have a question? Write to us.