> ## Documentation Index
> Fetch the complete documentation index at: https://docs.granola.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise admin settings

> A reference for Granola Enterprise workspace settings — what each control does, where to find it, and what's adjustable in-app versus configured by the Granola team.

## In this guide

1. [SSO, SCIM & provisioning](#sso-scim-provisioning)
2. [Domain capture](#domain-capture)
3. [Sharing](#sharing)
4. [Transcript retention](#transcript-retention)
5. [Workspace membership](#workspace-membership)
6. [Consent & notice](#consent-notice)
7. [Data export permissions](#data-export-permissions)
8. [Analytics & usage](#analytics-usage)
9. [Connectors (API / MCP)](#connectors-api-mcp)
10. [Quick reference](#quick-reference)

***

<h2 id="sso-scim-provisioning">
  01 — SSO, SCIM, directory sync & JIT provisioning
</h2>

Enterprise-only configuration, with minimum of 50 Enterprise seats. Contact your CSM or [hey@granola.so](mailto:hey@granola.so) (Backend Configuration).

### Supported identity providers

* Okta
* Microsoft Entra ID
* Google SAML
* JumpCloud
* Other SAML / SCIM providers

### How to enable

Email your Granola contact with the provider you'd like to use and any required metadata (IdP metadata URL, ACS endpoint, signing cert). The team will configure it on the backend and confirm when it's ready to test.

### SSO-only login

Enterprise admins can require all users to sign in through SSO by disabling OAuth login methods (such as Google sign-in). Once OAuth login is disabled, users must authenticate through your configured identity provider to access Granola.

This is typically used alongside domain capture to ensure that all users on your domain both join the correct workspace and authenticate through your organization's identity provider.

### New user onboarding with SSO

When domain capture and SSO are enabled, there is no need to create user accounts manually. New users are created when they first sign into Granola through your identity provider. During onboarding, they are directed to join your Enterprise workspace.

### SCIM provisioning

SCIM (System for Cross-domain Identity Management) allows you to sync users between your identity provider and Granola. With SCIM enabled, user accounts are automatically created, updated, and deactivated based on changes in your identity provider.

SCIM syncs user groups but does not automatically provision users who were created in Granola before SCIM was enabled. Existing users need to be provisioned separately in your identity provider's SCIM configuration.

***

<h2 id="domain-capture">
  02 — Domain capture
</h2>

Enterprise-only configuration. Contact your CSM or [hey@granola.so](mailto:hey@granola.so) (Backend Configuration).

### What it does

Domain capture routes every signup from your verified domain into your enterprise workspace, so new hires don't end up in their own personal accounts.

Any user signing up with an `@yourcompany.com` address is automatically placed inside your enterprise workspace. Blocking the creation of new workspaces for your domain prevents shadow accounts and gives admins a single place to manage users.

### When to request

Set this up before rolling Granola out to the broader org. Once you have more than a handful of personal accounts on your domain, migrating them in is straightforward but takes coordination.

***

<h2 id="sharing">
  03 — Sharing
</h2>

Sharing controls determine how notes leave the workspace — both via shareable links and via outbound / inbound sharing with people on other accounts.

### Default link sharing (workspace-wide)

**Location:** **Settings → Workspace → General → Data security → Link access settings**

Sets the maximum access level for shareable links across the workspace. Changes apply retroactively to all existing notes and folders. Individual users cannot exceed this level, though they may choose a more restrictive default for new notes they create.

| Option                          | What it means                                                                                                                                  |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| **Allow public links**          | Anyone with the link can view the note, including people outside your workspace.                                                               |
| **Only people at your company** | Only signed-in Granola users on your verified email domain can open the link. Admins can add secondary domains for multi-domain organizations. |
| **Restricted access**           | Only explicitly invited people can view. Links won't work for anyone else.                                                                     |

For how this interacts with per-user defaults, see [Sharing controls](/help-center/consent-security-privacy/sharing-controls).

### Default link sharing (per user)

**Location:** **Settings → Preferences → Data & sharing → Default link sharing**

Sets each user's default when they create a new shareable link. Users can still change a link's access on a per-note basis, but cannot exceed the workspace-wide limit set by an admin.

### Adjacent sharing controls

**Location:** **Settings → Workspace → General → Data security**

**Allow external sharing:** When disabled, people in this workspace can only share notes and folders with email addresses on your verified domain. Turning this off forces all shares to stay internal.

**Allow inbound sharing:** When disabled, people outside your workspace cannot add people in this workspace to notes or folders. Turn this off to keep external content from landing in your tenant.

***

<h2 id="transcript-retention">
  04 — Transcript retention
</h2>

**Contact Granola**

Set how long raw meeting transcripts are kept before automatic deletion. Notes themselves are not affected — only the underlying transcript text.

### Setting a retention window

Contact your CSM or Granola at [hey@granola.so](mailto:hey@granola.so) with the retention period you'd like (e.g. 30, 60, 90 days, or 1 year). Once set, transcripts older than that window are deleted automatically across the workspace.

<Warning>
  Deletion is irreversible. Confirm with your security or legal team before requesting a short retention window. Once a transcript is deleted, Granola Chat can only reference the summarised note rather than the full meeting content — which may reduce the depth and accuracy of responses. Choose a retention period that balances compliance requirements with the value your team gets from AI-assisted meeting recall.
</Warning>

For more detail on how deletion works, see [Transcript auto-deletion](/help-center/consent-security-privacy/transcript-auto-deletion).

***

<h2 id="workspace-membership">
  05 — Workspace membership & invites
</h2>

Control how new people find and join your workspace — discoverability for matching domains, auto-join, and explicit invite links. By default users with domains outside of your main domain should be invited from **Settings → Members**, the shared link will not work.

**Location:** **Settings → Workspace → General → Workspace invites & members**

**Allow workspace to be discovered:** When users sign up with your company domain, the enterprise workspace is surfaced in the app so they know to join it.

**Allow teammates to join automatically:** Users with your domain are added to the enterprise workspace on signup, without needing approval or an invite link.

**Invite links:** Generate shareable links that drop a user directly into the workspace. Links won't work for users outside your verified domain — add those individuals directly from **Settings → Members**.

**Only admins can invite new users:** Locks invites to admin accounts only. Request enablement from the Granola team — not exposed in the standard settings UI.

***

<h2 id="consent-notice">
  06 — Consent & notice management
</h2>

The "Heads Up" surface prompts users to disclose recording or get explicit consent at the start of a meeting. All controls here require Granola to enable them for your workspace.

**Location:** **Settings → Workspace → General → Consent & notice management**

### What it controls

Whether (and how) users in your workspace are nudged to notify other attendees that a meeting is being captured. Use this when you have a legal or compliance requirement around recording disclosure.

### Enabling consent controls

None of the consent controls are visible to admins by default. Reach out to the Granola team with the behavior you need — e.g. "prompt users before every external meeting" — and they'll enable the matching option.

Depending on what's enabled for your workspace, controls may include automated notice emails, Heads Up pages, in-meeting notice, notice in meeting chat, and notice on video. See [Heads Up for Enterprise](/help-center/consent-security-privacy/heads-up-for-enterprise).

***

<h2 id="data-export-permissions">
  07 — Data export permissions
</h2>

Determines whether workspace members can export notes, transfer them to another account, or move them to a different workspace.

**Location:** **Settings → Workspace → General → Data security → Data export permissions**

**Allow exporting data:** Users can export their notes (Markdown, PDF, copy-out) from this workspace. Turn off to keep all content inside Granola.

**Allow transferring notes to other accounts:** Lets users move their own notes from this workspace to a different Granola account they own — e.g. taking notes with them when they leave.

**Allow moving notes to other workspaces:** Lets users move their own notes from this workspace into a different workspace they belong to.

<Note>
  These controls only affect user-initiated movement. Admin-level data export tools are separate and remain available regardless of these toggles.
</Note>

***

<h2 id="analytics-usage">
  08 — Analytics & usage data
</h2>

Workspace-level dashboards showing adoption, active users, and note volume. Useful for tracking rollout and seat utilization.

**Location:** **Settings → Analytics**

### What you'll see

Active users over time, notes created per period, and adoption rollups across teams. Pair these with your rollout milestones to spot pockets that haven't onboarded yet.

***

<h2 id="connectors-api-mcp">
  09 — Connectors (API & MCP)
</h2>

Controls whether workspace users can connect Granola to outside AI tools via the personal API or the Model Context Protocol (MCP).

**Location:** **Settings → Workspace → General → Apps & connectors**

**API access for members:** Choose which notes workspace members can access with personal API keys.

**MCP access for members:** Choose which notes workspace members can access through MCP.

### Enterprise admin access

These controls apply to non-admin workspace members. Enterprise admins can access both personal notes and public notes through MCP. If neither scope is enabled, members cannot retrieve notes through MCP until an admin grants access here.

For setup details, see [MCP](/help-center/sharing/integrations/mcp) and [Granola API](/help-center/sharing/integrations/granola-api).

***

<h2 id="quick-reference">
  Quick reference
</h2>

Where each setting lives, and who can change it.

| Setting                               | Where to find it                                             | Access          |
| ------------------------------------- | ------------------------------------------------------------ | --------------- |
| SSO / SCIM / JIT                      | Backend — Okta, Entra ID, Google SAML, JumpCloud             | Contact Granola |
| Domain capture                        | Backend — routes domain signups in                           | Contact Granola |
| Default link sharing (workspace)      | Settings → Workspace → General → Data security               | Self-serve      |
| Default link sharing (per user)       | Settings → Preferences → Data & sharing                      | Self-serve      |
| External / inbound sharing            | Settings → Workspace → General → Data security               | Self-serve      |
| Transcript retention period           | Settings → Workspace → General → Data security               | Contact Granola |
| Discoverability / auto-join / invites | Settings → Workspace → General → Workspace invites & members | Self-serve      |
| Admin-only invites                    | Workspace invites — requires flag                            | Feature flag    |
| Consent & notice ("Heads Up")         | Settings → Workspace → General → Consent & notice management | Feature flag    |
| Export / transfer / move notes        | Settings → Workspace → General → Data export permissions     | Self-serve      |
| Workspace analytics                   | Settings → Analytics                                         | Self-serve      |
| API / MCP access                      | Settings → Workspace → General → Apps & connectors           | Self-serve      |

Need a flag enabled or a backend change? Reach out at [hey@granola.so](mailto:hey@granola.so).
