Organization administration¶
A reference for organization admins: members and invitations, settings, single sign-on, SCIM provisioning, branding, GitHub integration, and data export.
Members and invitations¶
Org Admin → Users manages your organization's membership.
Inviting members¶
- Click Invite and enter the person's email and role:
- Interviewer — hiring team members who create tasks and review candidates.
- Org Admin — full administrative access, including billing and SSO.
- Candidate — assessment takers who belong to your org.
- The invitee receives an email link. If they don't have an account, they sign up through the link; the role and organization are applied automatically on acceptance.
- Invitations expire. Resend expired ones from the invitations list.
Common invitation issues:
- "Invalid or expired invitation" — resend the invite.
- Invite already used — the person already accepted; check the members list.
- Seat limit reached — adding members fails with an upgrade prompt when your plan's seat limit is hit. See Billing.
Candidate invitations can also carry a task assignment, so the assessment is ready on the candidate's dashboard when they accept — interviewers typically send these from the candidate management pages.
Roles and access¶
Roles come from the identity provider and are enforced on every request. Note:
- A member's effective role updates after they sign in again — if someone's new role "isn't working", have them log out and back in.
- Platform admin (SkillFoundry staff) can never be assigned by your organization or through SSO.
Organization settings¶
Org Admin → Settings:
| Setting | Effect |
|---|---|
| Organization profile | Name, website, description, industry, size, address |
| Allow AI assistance | Organization-wide default AI policy for tasks. Tasks can carry their own policy; keep them consistent to avoid candidate disputes. |
| Hiring-only mode | Hides gamification, learning, leaderboards, and behavioral-analysis pages for all members. Members hitting those URLs are silently redirected to their dashboard. |
| Default language | Applied to members who haven't chosen a language themselves |
| White-label branding | Custom logo, colors, and product name — replaces SkillFoundry branding throughout the app for your members. Plan-gated (Professional/Enterprise). Note that changing the product name changes browser tab titles, which can confuse users' bookmarks — communicate the change. |
Single sign-on (SSO)¶
Org Admin → SSO configures SAML SSO through your identity provider (Okta, Azure AD/Entra, Google Workspace, etc.).
Setup¶
- Enable SSO and provide your IdP metadata URL.
- Add the email domains that should route to your IdP. Users entering an email on the login page are checked against these domains and redirected to your IdP automatically.
- Configure role mappings: map IdP groups/attributes to SkillFoundry roles (candidate, interviewer, orgadmin).
- Exchange metadata with your IdP — the SSO page displays the service-provider metadata your IdP needs.
- Optionally enable Enforce SSO so members of your domains cannot use password login.
Common SSO issues¶
- "SSO is not configured for this email domain" — the user's email domain isn't in your configured domain list, or SSO is disabled. Add the domain or have the user sign in normally.
- User gets the wrong role after SSO login — check your role mappings and the group claims your IdP sends.
- Enforced SSO locks out an admin — another org admin (or SkillFoundry support) can disable enforcement.
SCIM provisioning¶
For automatic user provisioning and deprovisioning:
- On the SSO page, generate a SCIM token. The page shows the SCIM base URL.
- Configure both in your IdP's provisioning settings.
- Users created/deactivated in your IdP are synced to SkillFoundry automatically.
Regenerating the token invalidates the previous one — update your IdP when you rotate it.
GitHub integration¶
Org Admin → GitHub Integration connects your GitHub account/repositories, enabling:
- Task creation from pull requests and issues — individually or in bulk from a repository. See Creating and managing tasks.
- Private repository access for PR-derived tasks — the platform needs read access (OAuth connection or a stored personal access token) to snapshot private repos.
- Bring-your-own content repository — host your own documentation and code samples in a Git repository; they appear in your candidates' documentation portal. Validate the connection from the content-repo settings before relying on it.
Token issues (revoked/expired PATs) are the most common cause of failed PR imports — rotate the token from the GitHub settings page.
Dashboards and analytics¶
- Org Admin → Dashboard — headline metrics for your organization.
- Org Admin → Analytics — skill distribution across candidates, improvement trends, and code-quality metrics.
- Learning analytics — if your organization uses learning paths, org-level learning analytics are available too.
Data export¶
Organization admins can export their organization's data from the data-management tools (also available via API). Use this for compliance requests or migrations. For questions about what candidate data exists in the first place, see Monitoring and data collection.