All organization-level configuration for Claude Enterprise lives in Organization settings (the gear icon or initial letter in the bottom-left corner). The table below is a quick orientation map for Bluemarq admins — each item has its own detailed article elsewhere in this document.

| Area | What it controls |
|---|---|
| Organization / General | Organization name, organization instructions, default model, support contact information. |
| Members | Invite/remove members, assign roles, export member list as CSV; Admins can manage this, but only Owner/Primary Owner can access Billing. |
| Roles & Groups | Default roles (Primary Owner, Owner, Admin, User) and custom roles on Enterprise, assigned by group; see the separate Roles & Permissions section. |
| Billing | Payment method, number of seats, invoices — accessible only to Owner/Primary Owner. |
| Data & Privacy | Custom data retention period (minimum 30 days) and audit log export (most recent 180 days). |
| Authentication / SSO | SSO configuration (Okta, Entra ID, etc.), JIT or SCIM provisioning. |
| Capabilities / Integrations | Enable/disable features at the organization level (Claude Design, connectors, Claude in Chrome, etc.) before assigning permissions by role. |
| Organization and access | List of verified domains, enable/disable organization discovery. |
| Analytics / Usage | Usage metrics by member/group; Enterprise Admins can see all metrics except Spend. |
Claude Enterprise follows an "enable at the organization level first, then scope with custom roles" model: a feature (e.g. Claude Design, a connector) must be enabled in Organization settings > Capabilities before it can be assigned to individual groups via a custom role. If the organization-level switch is off, no one can access it regardless of what their role allows. Permissions are additive: a member belonging to multiple groups receives the union of all granted permissions.

Organization discovery (under Organization and access) lets colleagues with an email on a matching verified domain find and request to join the organization at sign-up, instead of creating separate individual accounts. Admins choose one of two modes: auto-approve (members join immediately, seats expand and are billed automatically) or manual approval (admin approves each request, billed upon approval). This feature is off by default on Enterprise and unavailable if SSO is already enabled.
For organizations with a parent/child structure: SSO/SCIM configuration and groups are managed centrally at the parent organization level and shared across all child orgs; whereas role assignment and spend limits by group are configured independently at each child org — changes in one child do not affect other children. When SCIM is resynced at one child, the resync will cascade to every other child org under the same parent.
Source: Roles and permissions, Find and join a Team or Enterprise organization, How SCIM sync works for Enterprise organizations, Set up role-based permissions on Enterprise plans
















