App
Identity & tenantsDomain Governance
Identity & tenants

Domain Governance

Domain Governance lets you claim your company's email domain and apply organisation-wide rules to every Uslimato account whose address ends in that domain — including accounts created outside your tenant.

#What the feature does

  • Claim a domain — prove ownership of a domain via a DNS record
  • Account policies — control whether managed accounts may join other tenants, register on their own, or change profile fields
  • Session control — sign managed accounts out remotely
  • Transition period — 30 days after verification, so existing users can adjust

Domain Governance is a paid add-on, enabled per tenant. Without an active licence the settings page shows a note instead of the controls.

#Claiming a domain

  1. Open Settings › Domain Governance
  2. Enter the email domain, e.g. example.com, and click Add
  3. Place the generated DNS TXT record in your DNS management
  4. Click Verify — Uslimato performs a live lookup
  5. On success the status turns *Verified* and the 30-day transition period starts

If the check fails, DNS propagation is usually not through yet — that can take up to 48 hours. A daily reconciliation keeps re-checking verified domains afterwards.

Note
The DNS proof is the core of the feature. Without it, someone could claim domains they do not own and impose policies on accounts that are not theirs. There is therefore no way around verification.

#Transition period

After verification, 30 days run during which managed accounts see a notice but are not yet restricted. What happens afterwards is up to you:

PolicyBehaviour once it ends
Leave as isExisting memberships stay untouched
FreezeExisting memberships are set to read-only
RevokeMemberships in other tenants are withdrawn

#Policies

#Block joining other tenants

Managed accounts cannot accept invitations from other tenants. Invitations into the managing tenant itself are always allowed. The rule applies to both invitation paths — see Cross-tenant invitations.

#Block self-registration

People with an address on the managed domain cannot create a tenant of their own. Access then runs exclusively through an invitation.

#Restrict profile editing

Selected profile fields are locked for managed accounts. You choose which — typically first and last name plus the display name, so names stay reliable in tickets and the audit log.

#Prevent account deletion

With the option off, managed accounts cannot delete themselves from their profile page.

#Forced sign-out

From the list of managed accounts you sign a person out of every running session. The practical case: a departure where access should end immediately.

#Keeping track of managed accounts

After verification, every account whose address matches the domain lands automatically in the list under Settings › Domain Governance › Managed users. It shows email address and display name, the governance status — active, in transition or frozen — and the available actions.

Those affected see the badge **"Managed by *tenant*"** in their own profile, so it is transparent to them who enforces rules over their account.

Was this helpful?
Suggest an edit