Teams & SSO
Last updated
Everything in Pro for every seat, plus the org-level controls: centralized billing, seat management, shared personas and config, SSO, and org-managed virtual keys.
What Teams adds
| Capability | What it means |
|---|---|
| Everything in Pro | Immediate model access, custom agents, custom models, multiple sessions, higher agent limits — per seat. |
| Centralized billing & seats | One subscription for the org; add or remove seats from the admin dashboard. |
| Shared rules, skills & personas | Your organization's rules, skills, personas and slash commands, in every member's agent. See Org rules & skills. |
| Admin controls & usage visibility | See spend and usage across the org, not just per account. |
| SSO (SAML/OIDC) | Okta, Azure AD, Google Workspace, and other identity providers. |
| Directory sync (SCIM) | People your directory gives access are added, and removed when access is taken away. See Directory sync. |
| Org-managed virtual keys | Pool provider keys centrally with per-member budget, rate, and model limits. |
| Group budgets & models | A monthly budget and a list of models per group of members, on top of each member's own. See Group budgets and models. |
| Org custom models | Owners and admins add your own OpenAI-compatible endpoints and their models on the Portal's Org keys page, for every seat and org virtual key. See Custom models. |
Getting a team set up
-
Get a quote
Teams starts at $35/seat/month with a 10-seat minimum. Reach out via the contact form and we follow up with a quote and a signup link sized to your team.
-
Sign up — you become the Owner
The person who signs up becomes the org Owner and can invite teammates from the admin dashboard afterward.
-
Configure SSO
On the Portal's Single sign-on page, verify your email domains with a DNS record, then connect your identity provider (SAML or OIDC) so members sign in with company credentials. Only an email on a verified domain can sign in with SSO, and you can require SSO for those accounts.
Directory sync (SCIM)
Connect your user directory and Tempr keeps your organization's members in step with it: when your identity provider gives someone access to Tempr they're added, and when it takes that away, or they leave, they're removed. It works with Okta, Entra ID, Google Workspace and any directory that speaks SCIM 2.0, and comes with Teams and the Gateway Enterprise plan.
On the Portal's Single sign-on page, choose Connect a directory. Your IT admin sets up the connection on the page that opens, then gives people access to Tempr in your identity provider as for any other app. Verify your email domains first: the directory only adds people whose email is on a verified domain.
| In your directory | In Tempr |
|---|---|
| Someone is given access | They're added as a member and emailed how to sign in with SSO, if their email is on a verified domain and a seat is free. An existing Tempr account is used, unless it already belongs to another organization. |
| Their access is taken away, or they leave | They're removed: their seat is freed and their sessions end. Their usage history stays. |
| They're given access again | A member the directory removed comes back. Someone an owner or admin removed in the Portal stays removed until they're invited again. |
| Every seat is taken | They aren't added. Owners and admins get an email, at most once a day, and Tempr tries again whenever the directory changes and at least daily. |
| The directory is disconnected | Members stay as they are; remove anyone who should go. |
Changes reach Tempr within a minute or two, and once a day Tempr compares the whole directory with your members to catch anything missed. Everyone the directory adds joins as a member: make admins on the Members page. The organization's owner is never removed by the directory. Each change is listed on the Single sign-on page and recorded in the audit log.
Directory groups
With a directory connected, owners and admins can mirror its groups on the Portal's Groups page, to give them Tool Packs, a budget and models. Only the groups you pick are mirrored. A mirrored group's members follow your directory, in the same minute or two as members do, and the daily comparison catches anything missed; it can't be edited in Tempr. Stop mirroring a group, delete it in the directory, or disconnect the directory, and its Tempr copy goes, with the packs it gave its members.
Org-managed virtual keys
Instead of every member pasting their own provider key, the org pools provider keys centrally and issues members scoped access: per-member budget, rate limits, and model allowlists, all managed from the admin dashboard. Members get the models they need; finance gets one provider bill and hard caps on per-seat spend. Make a member's budget or the org's hard cap strict, and requests running at the same time can't spend past it together. See the virtual keys cookbook for the pattern — org keys are the same model applied to people instead of environments.
Group budgets and models
A group, made on the Portal's Groups page or mirrored from your directory, can have a monthly budget and a list of models, for example "Contractors: $200 a month, no Opus". Owners and admins set them with Edit, or Budget & models for a directory group, on the Groups page, which also shows each group's spend this month. The Members page shows what limits each member and where it comes from. They apply to members' own requests in the IDEs, the CLI and agent runs on Tempr's servers, and can be set with the management API.
| Limit | How it works |
|---|---|
| The group's spend | The sum of its members' spend in the organization this calendar month (UTC). A member's spend counts toward every group they're in. |
| Hard cap | Once the group's spend reaches its budget, its members' requests are refused with 402 group_budget_exceeded, naming the group, until the month ends or the budget is raised. |
| Alert only | Owners and admins get an email when the group reaches 80% and 100% of its budget, each at most once a month. Requests keep working. |
| Models | A list of model ids, like openai/gpt-4o-mini, or anthropic/* for all of a provider's models. A group without a list allows every model. A model outside a member's models is refused with 403 model_not_allowed, saying which groups limit them. |
How they combine. Every budget on the way applies: the member's own, each of their groups' hard caps, and the organization's hard cap. The first one used up refuses the request. For models, a member may use the models of all their groups together, unless one of their groups has no list: then groups don't limit their models. Their own allowed models, when set, always limit them as well. See the errors members can get.
Prompt guardrail for members
The Gateway's pre-request guardrail can cover members' own turns too: chat and agent turns in the IDE extensions, the CLI, Tempr Code and agent runs on the server. Owners and admins set Prompt guardrail for members on the Members page or the organization's Gateway settings:
- Off, the default: members' turns aren't checked.
- Flag only: turns go as sent and matches are noted in Tempr's logs.
- Redact secrets: tokens, AWS keys and API secrets in the turn's messages, tool calls and tool results are replaced with placeholders such as
[REDACTED-AWS-KEY]before the model sees them, and the turn goes on. An agent that reads a.envfile keeps working; the keys in it never reach the provider. - Redact secrets and personal data: email addresses and card-like numbers too.
- Block: the turn ends with a message saying what was found.
A member's own setting, under Org keys, Member limits, wins over the organization's. Redaction works on a copy of what goes to the model, so the agent's own record of a tool's output stays as the tool returned it. It's pattern matching: it catches the common shapes, not every secret.
Members use all three products on the team license — Chat in the IDE, the CLI in the terminal, and the Gateway account. The Portal and the Gateway dashboard sign in with SSO, and so does the CLI's browser sign-in (tempr auth), which you approve in the Portal. The IDE extensions sign in with the member's team license key for now; removing a member from the organization ends those sessions too.