Skip to main content
This page covers organization-wide admin — users, teams, groups, security (SSO, SCIM, domain policies), API keys, and audit. Per-team options (channels, SLAs, labels) live in Team settings.

Organization settings

Access organization settings by switching to the Organization workspace in the sidebar’s workspace switcher, then selecting Settings.
Only Org Admins can access organization settings.

Users

Manage everyone in your organization:
  • View all users and their org roles (Member or Admin), split across Users and Deactivated tabs
  • Invite new users
  • Deactivate users one at a time, or select several and deactivate them in bulk
  • Change organization roles

Teams

Create and manage teams:
  • Create new teams with a name and prefix
  • View team membership
  • Delete teams

Groups

Organize users into groups for easier management: Org groups are managed once for the whole organization. Each team then chooses which groups it uses for ticket ownership and routing.

Branding

Personalize how Serval looks and what it calls its AI assistant across your organization. Open Organization SettingsBranding. Organization URL The read-only sign-in URL for your organization, with a copy button so you can share it with your team. Help Desk Agent Set the name and logo for the AI assistant that appears in tickets and conversations. A Let teams set their own agent name toggle lets individual teams replace the organization name with their own. Turning it off returns every team to your organization’s name, and each team’s choice is remembered, so turning it back on restores their previous names. Application branding Set the name shown next to the logo in the sidebar, on the sign-in screen, and in the end-user portal (it defaults to Serval), and upload light and dark mode logos. If you upload only one logo, Serval uses it for both themes. Changes take effect once you save. Serval never removes your ability to clear a field and return to the default.

New Request page

Choose which cards employees see on the New Request page, where they start a request in the web app. Open Organization SettingsNew Requests, then toggle each card:
  • Request access card shows the entry point for requesting role-based access to applications.
  • Service catalog card shows the catalog of predefined services and forms employees can submit.
  • Knowledge base card shows the link to browse published knowledge articles.
Each toggle saves immediately. Hiding a card removes it from the New Request page for everyone in your organization.

Security: SSO, SCIM, and domains

A guided in-product setup for both SCIM and SSO is found within Organizations → Security.
Serval connects identity providers using SAML 2.0 via WorkOS, including Okta, Google Workspace, Azure AD (Microsoft Entra ID), OneLogin, JumpCloud, PingFederate, and other SAML 2.0 compliant providers.

SSO

  • Connect and review SSO for your identity provider (SAML via WorkOS).
  • Confirm domain verification and overall SSO configured status from the card.
  • Use Require SSO when everyone must sign in through your IdP.
If your sign-in domain belongs to more than one organization that enforces SSO, you choose which organization to sign in to, then Serval redirects you to that organization’s identity provider.

SCIM

SCIM keeps your IdP and Serval in sync for users and groups, via WorkOS Directory Sync. Supported providers include Okta, Microsoft Entra ID (Azure AD), Google Workspace, JumpCloud, OneLogin, Rippling, and other SCIM-capable IdPs. What SCIM controls:
  • Creates and deactivates Serval user accounts as people are added to or removed from your IdP.
  • Imports your IdP’s group list into Org Settings → Groups.
  • Sets each user’s organization-level role — Org Admin or Org Member — based on the WorkOS role slug computed for them. The most common pattern is to map a dedicated IdP group (such as serval-admins) to the admin role in the WorkOS dashboard for the directory connection. See WorkOS Directory Sync — Roles for the dashboard steps.
SCIM controls identity. Serval controls team assignment. SCIM keeps your user list in sync and decides who is an Org Admin vs. Org Member. Team membership and team-level roles (Manager, Agent, Builder, Viewer, Drafter, etc.) are configured in Serval — most commonly by adding a synced group to a team with a specific role under Team Settings → Team Members → Add group. Every member of that group then inherits the chosen role on that team, and adds/removes in your IdP flow through automatically.

User Sync Domain Allowlist

  • Turn domain filtering on or off for your organization.
  • Add allowed domains so only matching email addresses stay in scope when users sync from connected directories and integrations.
Enforce domain filter
After allowed domains are saved, Enforce Domain Filter appears at the bottom of the domain allowlist card.
  1. Click Check Users to run a dry run. Serval lists which users would be deactivated because their email does not match the allowlist.
  2. Review the dialog. The admin running the check is never included in deactivation.
  3. Confirm to deactivate all non-matching users in one step.
Users deactivated by enforcement remain deactivated while domain filtering stays enabled. Reactivation rules follow your domain policy until it changes.

External Requester Domain Allowlist

This allowlist controls who can become an external requester — someone outside your organization who reaches your help desk and does not yet have a Serval account. It applies on every channel that creates a requester on first contact: email intake, Slack, Microsoft Teams, and connected ticketing integrations such as Jira, Linear, Zendesk, ServiceNow, Freshservice, and Salesforce. When filtering is on, a first-time sender from an unlisted domain gets no guest account, and therefore no ticket. This applies even if a team marks that domain as trusted in its own email settings, so the org policy is the outer boundary. The check runs once, when the account is created. Requesters who already have a guest account keep filing tickets even if you later remove their domain, and removing a domain never deactivates anyone. To cut off an existing requester, deactivate the user directly under Org Settings → Users.
Organization members are not affected by this allowlist. They are governed by the User Sync Domain Allowlist above.

AI Response Domain Allowlist

This allowlist controls which external requesters Serval AI replies to, separately from whether they can file at all. When filtering is on, a requester from an unlisted domain still gets a ticket, and your team still gets notified — Serval simply withholds the AI response and routes the ticket to a human. Unlike the requester allowlist, this is checked live on every message, so edits take effect on the requester’s next message with no sweep. Use the two together to admit a domain but keep Serval quiet with them: add the domain to the External Requester Domain Allowlist and leave it off the AI Response Domain Allowlist.
Organization members always receive AI responses. This allowlist applies only to external requesters.

API keys

Manage programmatic access to Serval:
  • Create API keys with a name and an expiration (1, 7, 30, 60, 90, or 180 days, or 1 year). Every key must expire, and 1 year is the maximum.
  • Optionally scope a key to specific permission bundles (for example, tickets:read or workflows:run) so it can only reach the endpoints those bundles cover. A key created with no scopes has full access.
  • Optionally restrict a key to specific teams so it can only reach resources on those teams. Leave the team list empty to allow all teams.
  • Review a key’s configuration, and revoke keys you no longer need
Team Managers can also create team-scoped keys from Team SettingsAPI Keys without an org admin. A manager-minted key is limited to the teams they manage and to the scope bundles their own role can grant: full access and admin-only actions (such as ticket deletion) stay org-admin only.

AI Provider Keys

Use AI Provider Keys when your organization wants Serval to call supported LLM providers with keys that you own and manage. If no organization key is configured for a provider, Serval uses its platform key. When you add an organization key, Serval uses that key for LLM calls made on behalf of your organization for that provider. Before configuring a key, create an API key in the provider’s console and make sure the provider account has billing, model access, and rate limits that support your expected Serval usage. Serval currently supports organization overrides for OpenAI and Anthropic.
1

Open AI Provider Keys

Go to Organization SettingsAI Provider Keys. Only Org Admins can view or manage organization LLM keys.
2

Add a provider key

Choose Set override for OpenAI or Anthropic, paste the provider API key, then save. Serval runs a healthcheck before storing the key. If the healthcheck fails, the key is not saved.
3

Configure a custom endpoint, if needed

Leave API base URL blank to use the provider’s default endpoint. Set it only when traffic should go through a compatible proxy or gateway, such as an OpenAI-compatible gateway. Serval healthchecks the endpoint before saving the override.
4

Verify the configuration

Use Test now to run a live healthcheck against the saved key and endpoint. The card shows whether the override is active and displays only the key ending, not the full key.
Keys are encrypted at rest. Updating a key replaces the stored value, and Serval never shows the full key after it is saved.

Audit logs

View a record of actions taken in your organization:
  • Filter by user, action type, or date range
  • Export logs for compliance
Audit logs capture activity across the platform, including:
  • Approvals: approve, deny, timeout, automatic conclusion, and cancellation of approval requests
  • Access reviews: reviewer decisions (certify, revoke, skip) and review reopen or cancel
  • Knowledge: knowledge document and ingestion-configuration changes (create, update, publish, archive, delete)
  • Identity and directory sync: SCIM directory sync, MFA changes, and team-group role bindings
Use the action type filter to narrow the log to a specific category.

Stream audit logs to a SIEM

Stream your organization’s audit events to an external security information and event management (SIEM) system, such as Splunk or Datadog. After you connect a destination, Serval forwards every audit event it records to that destination. Each event includes the action, who performed it, what it affected, when it happened, and context such as the IP address and user agent. Serval streams audit events through WorkOS. You add and manage the destinations in a WorkOS-hosted portal, so the supported destinations and their setup fields come from WorkOS rather than Serval.

The SIEM Logging section in Organization Settings → Security

SIEM Logging uses the same WorkOS organization that Serval provisions when you set up SSO. Set up SSO first so that organization exists, or the Configure SIEM button can’t open the portal.
1

Open the Security settings

Go to Organization SettingsSecurity and find the SIEM Logging section. Only Org Admins can view or configure SIEM Logging.
2

Open the WorkOS portal

Select Configure SIEM. Serval opens a WorkOS-hosted portal in the same browser tab and returns you to the Security page when you finish.
3

Add one or more destinations

In the portal, add and configure each log stream destination that receives your audit events. You can connect more than one destination.
Streaming continues even if you turn off Require SSO or disable SSO login, so audit events keep reaching your SIEM during an incident.

SIEM streaming metadata

Each streamed event carries the action, actor, targets, and request context, plus a metadata object with the event’s security dimensions. A key appears only when the event carries that dimension; the set of keys is additive-only — new keys may be added over time, but existing keys keep their name, meaning, and value format. Metadata values longer than WorkOS’s 500-character limit are truncated (ending in ). field_changes is the exception: it is never cut mid-string — whole trailing entries are dropped until the array fits, so the value always remains valid JSON. Any event whose metadata had to be cut down carries an extra truncated: "true" key — so your pipeline can distinguish a complete record from a shortened one.

Support tokens

Enable time-bound access for Serval support engineers to assist with your tenant:
  • Generate tokens — Users can create time-limited support tokens from the profile menu (Get support).
  • Automatic expiration — Tokens expire after the configured duration with no manual cleanup required.
  • Full audit trail — All access performed via support tokens is logged for compliance and transparency.
For steps, security details, and how to revoke access, see Support → Support tokens.

Quick reference

Steps that use Team Settings are documented in Team settings.