> For the complete documentation index, see [llms.txt](https://docs.e6data.com/query-engine/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.e6data.com/query-engine/guides/security/authentication/domain-auto-join-and-jit.md).

# Domain auto-join and JIT provisioning

Let users join your organization automatically by email domain, and provision SSO users just-in-time on first sign-in.

Two features let people join your organization without per-person invitations: **domain auto-join** and **SSO just-in-time (JIT) provisioning**. Both create new members with the **Viewer** role, which you can change afterward.

## Domain auto-join

Let anyone with an email address on your company domain join automatically the first time they sign in.

1. Open **Settings** (requires the **Manage organization** permission).
2. In the **Auto-Join Domain** card, switch the toggle **on**. The domain is taken from your account - there's nothing to type.

After this, a new user who signs in with a matching email is added to your organization automatically with the **Viewer** role. Common public domains (such as `gmail.com`) cannot be used for auto-join. Auto-join and per-person invitations can be used together - invitations remain the way to add people on other domains, such as contractors.

## SSO just-in-time provisioning

When SSO is configured with domain routing, a user signing in through your identity provider with a matching email domain is provisioned **on first login** - no separate sign-up or invitation step:

1. The user enters their work email and is routed to your identity provider.
2. On a successful sign-in, e6data looks them up by email; if no account exists, it creates one.
3. A membership is added to your organization with the **Viewer** role.
4. The account propagates to each workspace automatically (typically within \~30 seconds).

Because the same email always resolves to one user globally, users moving between organizations don't produce duplicate accounts. Promote JIT-provisioned users from **Access Control → Users**. While SSO is enabled, manual invitations are disabled - the identity provider is the source of truth.

## See also

* [SSO setup](/query-engine/guides/security/authentication/sso-setup.md)
* [Organization setup](/query-engine/get-started/identity-access-setup/organization-setup.md)
* [Users, groups, and service accounts](/query-engine/guides/security/identity-and-rbac/users-groups-service-accounts.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.e6data.com/query-engine/guides/security/authentication/domain-auto-join-and-jit.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
