5 min read
Mar 08, 2026

Controlling Verified Domain Accounts

Learn how to enforce full account control over members with verified organization email addresses using the Control Verified Domain Accounts policy.

Control Verified Domain Accounts

The Control Verified Domain Accounts policy allows enterprise organizations to enforce strict separation between organizational and personal email addresses on Pivot accounts. When enabled, your organization gains full control over accounts that use your verified domain emails.

This is an opt-in enterprise feature. It defaults to off and must be explicitly enabled by an organization admin. Your organization must have at least one verified domain before this policy has any effect.

What This Policy Does

When this policy is enabled:

  • Members with a verified organization email (e.g. alice@acme.com) cannot add personal email addresses (e.g. alice@gmail.com) to their Pivot account.
  • Members with a personal email cannot add an organization email from a verified domain to their account.
  • Invitations sent to a verified domain email can only be accepted by users whose Pivot account contains only organization email addresses. Users with existing personal emails on their account will be unable to accept the invite.
  • Members cannot verify a pending personal email if they already have a verified organization email on their account, and vice versa.

Members with email addresses at domains not verified by your organization are completely unaffected by this policy.

This policy also enables organization admins to update profile details and organization email addresses for eligible managed members.

Enabling the Policy

1

Navigate to Domains and Security

From the sidebar, click your profile picture, then select Organization admin and choose your organization. Navigate to the Domains and Security tab.

2

Verify a domain

If you haven’t already, add and verify your organization’s domain. The policy only applies to verified domains. See Adding a Domain for instructions.

3

Enable the toggle

Under the security settings, enable Control Pivot accounts for all members that have verified organization email addresses. The policy takes effect immediately for new actions.

Managing Verified Domain Members

After this policy is enabled, organization admins can update basic profile details for eligible managed members from the Members tab in Organization admin.

Admins can update:

  • A member’s first name.
  • A member’s last name.
  • A member’s primary organization email address.

When an email address is changed, the new email must belong to one of the organization’s verified domains. The new organization email becomes the member’s primary email address.

Who Can Be Managed

A member can be edited by an organization admin when:

  • The admin has permission to manage the organization.
  • The organization has at least one verified email domain.
  • Control Verified Domain Accounts is enabled.
  • The member has a verified email address at one of the organization’s verified domains.
  • The new email address, if changed, also uses a verified organization domain.

Pivot does not let organization admins use this flow to take over personal accounts, change unrelated external emails, or manage users whose account cannot be clearly associated with the organization.

Update a Member

1

Open Organization admin

Click your profile picture, choose Organization admin, then select the organization.

2

Open the Members tab

Select Members from the Organization admin tabs.

3

Choose a managed member

Find the member you want to update. If the member is eligible for organization management, open the member actions and choose Edit user.

4

Update the details

Edit the member’s first name, last name, or organization email address. Email changes must use a verified domain for the organization.

5

Save

Click Save. Pivot validates the change before applying it.

If you do not see the edit option for a member, check that you are an admin for the organization, the organization’s domain is verified, this policy is enabled, and the member’s account uses a verified email address for your organization.

Important Considerations

This policy is not retroactive

Enabling the policy does not affect existing users who already have mixed personal and organizational email addresses on their account. It only prevents new violations going forward. Before enabling this policy, you may want to:

  • Audit which members currently have mixed email addresses.
  • Communicate with affected members and ask them to remove personal emails from their accounts.
  • Enable the policy once existing accounts are in compliance.

Disabling the policy

When the policy is disabled, all email restrictions are lifted. Members can freely add personal or organizational email addresses to their accounts, and invitations can be accepted regardless of existing email addresses.

Relationship with SCIM

This policy is a prerequisite for using the SCIM integration. SCIM-based member management requires that your organization has full control over member accounts, which this policy enforces.

Was this guide helpful?