# Overview

# Team management & SSO

## Roles

- **Admins** use the Admin Console: policy, inventory, activity, billing.
- **Developers** use the Sentilai Endpoint on their machines; they don't need console access.

Both take a **seat**. Your plan's seat limit and current usage are on the Billing page.

## Invites & passkeys

Invite by email: the invitee gets a **passkey setup link** — they register a passkey and are in. No passwords anywhere in Sentilai. A backup passkey can be added from Account settings; admins can issue a new setup link if a device is lost.

## Enterprise SSO

Connect your identity provider (Okta, Entra ID, Google Workspace, or any OIDC/SAML IdP) with the guided **SSO wizard**: pick the provider, follow the tailored steps, validate the connection with a live test login, and switch enrollment to SSO. New team members then sign in with your IdP — accounts are provisioned on first login (JIT).

## Session security

Sign-ins use phishing-resistant credentials (passkeys or your IdP's own MFA). Device credentials are separate, rotated, and revocable per device from the console.