# Verified domains

Verify company email domains and choose whether SSO admits new members automatically.

**Verified domains** associate company email addresses with your organization. Proving control of a domain lets withHuman direct its users to your [single sign-on](/docs/web-app/sign-in-and-directory) connection. Verified domains are part of the hosted edition.

## Domain verification

A domain claim starts as **Pending**. withHuman provides a DNS TXT record for your domain administrator to publish. **Verify** checks for that record and changes the claim to **Verified** when it matches.

Use the record name and value shown for your claim. DNS changes can take time to appear; if verification fails, check the published value and try again after it has propagated.

A verified domain belongs to one organization on the deployment. Public email providers such as Gmail and Outlook cannot be claimed.

## Sign-in routing

With both a verified domain and an active SSO connection, people entering an email address on that domain are directed to your identity provider. On hosted withHuman, those addresses also cannot create separate organizations through self-service signup.

Domain verification alone does not turn on SSO. The connection must be active for this routing to apply.

## Automatic admission

**Admit new members automatically** lets someone join when your SSO provider confirms a verified email address on the domain. This is also called just-in-time admission: membership is created at sign-in, without an invitation.

The selected **Admission permissions** set the new member's initial access. Choose only the access everyone joining through that domain should receive. Sensitive permissions, such as organization ownership, cannot be granted this way.

With automatic admission off, a new person needs an invitation or directory provisioning. Existing members can still sign in through SSO.

Automatic admission adds people when they arrive. It does not remove people when they leave your company. [Directory sync](/docs/web-app/directory-sync) handles those membership changes.

### Example: A company domain

We'll verify `example.com` and connect our SSO provider. If we want only invited or provisioned colleagues to join, we'll leave automatic admission off. If everyone with a verified work identity should join, we'll enable it with the minimum permissions they need.

## Changes and release

Changing admission permissions affects future admissions. Manage existing members' access through [Permissions](/docs/web-app/permissions) or their directory-managed teams.

**Release** removes the domain claim and its automatic-admission settings. It does not remove existing members or disconnect the organization's SSO connection.

Viewing domains requires access to view connections. Claiming, verifying, releasing and changing admission require access to manage connections. You can assign only admission permissions you are allowed to grant. Changes appear in [Audit log](/docs/web-app/audit-log).
