Your organization workspace
Use an organization to keep a team’s investigations, client access and spending together. Each client space or asset scope contains its own cases, evidence and reports. Open Organizations to create or join one. Before creating one, read What changes for your account: purchased personal credits move after your confirmation, and an active personal subscription must end first.
Resume work from Teams or Search
When signed in with an organization membership, Teams shows your workspace dashboard: accessible scopes, investigation cases, changes to review, reports and organization credits. Select an organization and a space before starting a search. Opening the dashboard does not start a collection or spend credits.
While your account belongs to an organization, research pages open in that organization's context and use its credits; personal research is not available. Staff start in General research, the organization's shared internal context, and can switch to a client or asset scope with Research context. External clients choose one of the clients they can access. The context bar identifies the payer.
Research navigation preserves the selected organization and space. Use Active case in the research bar to keep a case selected as you follow research links within that space. You can also start from Research in this case inside a case. Selecting a case does not run a search or save anything: the evidence dialog still requires confirmation. Changing spaces clears the case selection; unavailable or archived cases must be replaced before saving. After searching, use Save evidence on an individual result to attach it to a case. Unified results and the individual host, DNS, certificate and WHOIS record views offer this action. The field action menu also offers Save evidence: it prefills a note with the selected field and value while retaining the full source record.
Choose an existing case in the save dialog, add a note and review visibility. If none exists, follow the link to that client’s cases and create it there. The save dialog never creates a case. Evidence defaults to Internal only for staff; external client users save client-visible evidence. This action uses the completed search, without another paid search. Filtering or changing the displayed order does not change which source record is saved.
General research cannot own new cases. To save one of its observations, select a real client and explicitly rerun the search in that client’s context; the client’s budget pays for that run. Existing historical cases in General research remain accessible for review.
The workspace toolbar still supports selecting up to 20 records from a completed search, with a filter to find records in the selection list. A search does not automatically add evidence to a case or report.
Choose your workflow
Choose Internal security team for your own brands, subsidiaries or technical perimeters, or Manage client work for a consultancy. Both use Teams and Business. The owner can change the wording later in Settings without moving data or changing access.
Create an organization
- Sign in with a verified account and enter an organization name.
- For the 14-day trial with 1,000 shared credits, enter and verify a business domain. Follow the displayed proof instructions; when requested, publish the exact DNS TXT record before choosing Verify domain.
- Read What changes for your account and tick I understand and accept these changes to my account. Both creation buttons stay disabled until you do.
- Choose Start organization trial. Trials are subject to eligibility and anti-abuse checks. Some accounts require administrator approval before the organization opens.
- Alternatively, Subscribe without a trial creates an empty billing workspace. It grants no free credits and takes no payment until checkout is completed.
A personal email address such as Gmail is not proof of a business domain. Renaming or transferring an organization does not create another trial. A domain declared later in a client scope is not the business-domain verification used for admission.
If an organization is pending approval, wait for its status to change. If it is inactive or awaiting payment, complete the action shown in Billing. An owner role alone does not bypass these restrictions.
What changes for your account
Creating an organization changes how your account works, so the form asks for your consent first:
- After creation, your account works in the organization context. Personal research is no longer available to it while it belongs to the organization.
- The purchased credits in your personal wallet move to the organization, where they do not expire. The form shows the exact amount, or that no credits will move.
- Your personal plan does not change, and its monthly allowance is not transferred.
The form checks your account before it offers creation. It is unavailable while your personal plan, trial or subscription is active: cancel its renewal in personal billing, then create the organization once it has ended. It also waits while a personal payment is still processing, and an account that already owns an organization or belongs to one as staff cannot create another one.
The form reads GET /api/v2/organizations/creation-preview, which returns allowed, a reason when creation is unavailable, and transfer_credits. POST /api/v2/organizations must include "accept_account_transition": true and "expected_transfer" set to that amount; without them, the request is refused with invalid_input (422). If the amount changed in the meantime, creation is refused with transfer_changed (409): review the new amount and confirm again.
WHOIS during the trial
During the 14-day trial, WHOIS results never include natural-person contacts: the registrant name and email, and the technical and administrative contact names and emails. The registrant organization, the registrar and the name servers stay visible. A search, watch or export that filters or sorts on one of those contacts is refused before any credit is reserved, and Pivot does not connect domains through a shared registrant email. Teams and Business show every field.
First client space or asset scope
- Open Client spaces or Asset scopes and choose Create. A read-only or inactive organization cannot create new scopes.
- Assign colleagues and set a credit envelope. If external users can search, set their portion too. Both are limits within the shared organization balance.
- Record domains and contacts under Declared scope & contacts. These entries do not grant access or send messages, and do not restrict public searches to that scope.
- Choose Search in this space. Keep the space selected so jobs use its permissions and budget. Activity retains job status when you leave the page.
- Save useful observations as evidence in a case. Review visibility before producing a report.
- Open Monitoring in the space to prepare a scheduled watch. Collection only starts after explicit activation.
The workspace credit bar shows the shared balance to managers and the permitted envelope to other members. Reserved amounts cover pending work. A failed budget check never falls back to personal credits. The bar's Credit usage link opens the organization-wide usage report for owners and administrators, also available in My account → Organization → Credit usage. Other members get their current client's usage.
People and permissions
| Role | Access |
|---|---|
| Owner | Organization settings, billing, SSO, staff and all spaces |
| Administrator | Organization operations and all spaces; owner-only billing changes and ownership transfer remain restricted |
| Analyst | Assigned spaces and their internal work |
| External client | Assigned spaces, explicitly shared content and searches within their permitted envelope |
See Members and invitations. Removal of a member or assignment revokes the corresponding access. Report guest links are separate shares and must also be revoked when no longer needed.
SSO and integrations
Configure staff authentication in Single sign-on using Entra ID, Google Workspace or another supported OpenID Connect provider. Test and save the recovery code before enforcing it. External clients retain named access. See Staff SSO.
For automation, create a scoped service key in API integrations. A personal API key or personal MCP OAuth connection does not grant organization access. See MCP and workflow automation.
Read the overview
Without a selected space, the overview summarizes accessible scopes, cases, jobs, reports and monitoring work. Counts respect member permissions; client users do not see private staff work. Choose Refresh overview to reload it.
An internal team's declared-domain count is not a discovered inventory. The first successful watch run establishes a baseline; missing data or partial collection never proves that a service disappeared.
Archive, restore or leave
Archiving a space pauses its work and schedules and revokes relevant shares. Restoring preserves history but does not restart schedules or recreate revoked links. Review budgets and access before continuing.
Ownership transfer needs explicit acceptance by the recipient; see SSO and ownership recovery. For retention, exports and deletion, follow Export and delete organization data.
Some capabilities depend on deployment configuration. An unavailable action is shown explicitly; it must not switch to a personal payer.
Continue the review across spaces
From the connected Teams dashboard or organization navigation, open Review queue to review observations across all spaces you can access. Assign a colleague, set a due date and retain the source in a case. Then prepare a report comparison from the selected evidence. The queue is for internal members; external clients keep their explicitly published space view.