Single Sign-On
Cassidy supports SAML 2.0 SSO with any compatible identity provider, including Okta and Microsoft Entra ID. Your team signs in with existing credentials. SAML role mappings can grant privileges automatically, and SAML group mappings can place users into the right resource visibility groups.Set up SSO
Step-by-step SSO configuration guide.
Roles and privileges
Managed roles and custom roles give you fine-grained control over what each person can do in Cassidy. Use roles to control privileges like creating Agents, editing Workflows, adding to the Knowledge Base, recording meetings, inviting members, managing billing, or configuring SSO. Use groups to control which shared resources each team can access.Assign roles and groups
Configure roles, custom privileges, and visibility groups.
Knowledge Base access controls
Knowledge Base content is organized into collections, each with its own access settings. Collections can be open to the whole organization, restricted to specific groups or individuals, or kept private. Sensitive content can live in Cassidy without being accessible to everyone.Manage Knowledge Base permissions
Configure collection-level access controls.
Knowledge verification
Admins can flag Knowledge Base documents as potentially outdated and require them to be reviewed before Agents continue using them. This gives teams a lightweight governance layer to ensure the information powering your Agents stays accurate and current.Verify documents
Set up document verification.
Agent and Workflow controls
Agents and Workflows can be shared with specific groups, kept private, or made available to the whole organization. Both can be organized into folders with their own permission settings. Workflows support external deployment via webhooks and inbound email triggers for integration into other systems. Agents support draft and publish versioning with full version history, so changes can be reviewed before they go live.Share and manage Agents
Agent permissions, folders, and versioning.
Share and deploy Workflows
Workflow permissions, folders, and external deployment.
Meeting access controls
Meeting recordings default to private and can be shared with specific people, groups, or the whole organization. Admins can set up automated sharing rules that apply access settings based on defined conditions, so the right teams always have access without manual sharing.Manage meeting permissions
Configure meeting sharing and access rules.
Data retention
Enterprise customers can configure automated retention policies for Workflow run history. Set a custom retention window to automatically purge run data after a defined period, or retain it indefinitely. Manual deletion is always available. All data is permanently deleted when an account is closed.Configure data retention
Set up automatic data retention policies.
Global AI governance
Admins can set organization-wide instructions that apply to every Agent and Workflow across the organization. Use this to enforce tone, restrict certain language, add compliance disclaimers, or ensure consistent behavior regardless of how individual Agents are configured.Configure global instructions
Set organization-wide AI instructions.
Default Agent configuration
Admins control which Agents appear by default for team members when they open a new chat. This ensures new users land in the right context without needing to hunt for the right Agent.Configure default Agents
Set the default Agents for your organization.
Observability and AI usage monitoring
The usage dashboard surfaces credit consumption by user, Workflow run volumes, Knowledge Base storage, and meeting hours. Workflow run history logs every execution with inputs, outputs, and step-level results for auditing and debugging. Per-user credit limits and alert thresholds give admins proactive control over spend.Monitor usage
Track organization-wide usage and credits.
Set credit alerts and limits
Configure per-user credit limits and alerts.
Audit logs
Enterprise admins can review a searchable record of who viewed or changed resources in the organization. Audit logs track activity across Agents, Workflows, Knowledge Base content, meetings, sharing, etc.View organization audit logs
Search, filter, and export audit events for investigations.
Secret management
API keys, passwords, and other sensitive credentials used in Workflows are stored as encrypted secret keys rather than plain text values. Secrets can be scoped to specific users or groups so only authorized team members can use them in Workflow actions. Once saved, secret values are never exposed in the Workflow editor or run history.Use secret keys
Store and manage encrypted credentials for Workflows.
Custom integrations and extensibility
Cassidy integrates natively with most enterprise tools. For everything else, Workflows can send API requests to any external system, accept webhook and email triggers from any source, run custom code for advanced logic, and Agents can reach internal systems through Custom Connectors. Most integrations are point-and-click. The edge cases are covered by code.Browse integrations
Native integrations catalog.
Send API Request
Connect to any external API.
Custom Connectors
Connect Agents to custom systems.
Connect non-native apps
Webhooks, API requests, and custom code.
Custom Connectors and built-in Connectors
Custom Connectors connect Cassidy to internal systems through MCP. People with the Manage Connectors privilege add them, choose who can use them, and can disable one for the whole organization without deleting it. Cassidy also provides built-in Connectors for HubSpot, Salesforce, Airtable, Snowflake, BigQuery, ServiceNow, and other business apps. Roles decide which built-in Connectors people may use. Organization settings can turn off individual actions, decide what happens to new actions, and require approval for changes or for every action. People connect their own accounts, so each person keeps their own permissions in the external app. Agents and Workflows can instead use a shared connection limited to selected people, groups, or the organization.Agent connectors
Native connectors for CRMs, data warehouses, and more.
Custom Connectors
Connect Agents to any system via MCP.
Native OAuth integrations
All native integrations connect through standard OAuth or API key authentication. Cassidy only requests the scopes needed for each integration, and credentials are encrypted and stored separately from content data. Users connect their own accounts through the standard OAuth flow. For shared service accounts, anyone with the privilege to connect that integration can set up a shared connection and choose who may use it.Browse integrations
See all available integrations.
Multi-organization support
Cassidy supports multiple separate organizations under the same login, useful for companies managing multiple divisions, brands, or client environments that require strict data separation.Manage multiple accounts
Set up and switch between organizations.
Deploy Cassidy wherever your team works
Agents can be deployed wherever your team already works: Slack, Microsoft Teams, Outlook, Word, Excel, Chrome, Edge, email, embedded in any website, or accessed via API. All deployment surfaces operate under the same security model as the main platform.Deploy to Slack
Deploy an Agent into Slack.
Deploy to Teams
Deploy an Agent into Microsoft Teams.
Deploy via email
Deploy an Agent to a dedicated email address.
Embed an Agent
Embed an Agent in any website or portal.
Agent API
Access Agents via API.
For questions about enterprise deployment, contact support@cassidyai.com or visit trust.cassidyai.com.