Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260929T150709Z

7 pages moved out of 256 read.

Pages moved 7 significant first
Pages read 256 in this capture
Captured 15:07 UTC
Corpus hash 9b3c0cf75523 corpus-hash

What this read moved

1-7 of 7

claude-science/admin-controls Changed · +38 / -10 lines

### Capabilities in custom roles

from line 6
66 
77## Organization settings
88 
9The [**Organization settings** > **Claude Science**](https://claude.ai/admin-settings/claude-science) page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see [Enable Claude Science](/docs/claude-science/enable-claude-science)), and the other controls unlock once Claude Science is on. Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.
9The [**Organization settings** > **Claude Science**](https://claude.ai/admin-settings/claude-science) page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see [Enable Claude Science](/docs/claude-science/enable-claude-science)), and the other controls unlock once Claude Science is on. On Enterprise plans, you can also limit some of the controls to certain custom roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.
1010 
1111### Defaults by plan
1212 
from line 37
3737 
3838Turning a control off doesn't delete anything on the members' computers. What members set up under that control (custom connectors, SSH hosts, their Modal connection, saved memories, and their own choices) stays on their computer, and that feature cannot be used inside the Claude Science app while the control is off. The setting shows grayed out in the app with a note that an admin turned it off, and everything works again as before if you turn the control back on. A control that is off by your plan's default instead shows a note that an admin can turn it on. When the **Allow custom skills** switch is off, skills a member added earlier keep working (see [Custom skills](#custom-skills)).
3939 
40### Capabilities in custom roles
41 
42On Enterprise plans, seven of the controls on this page also have a capability in custom roles, so you can leave a control on for the organization and, among members with custom roles, limit it to certain roles. Go to [**Organization settings > Roles**](https://claude.ai/admin-settings/roles), open a custom role, and go to its **Capabilities** tab. In the **Claude Science** section, the seven are listed under the **Claude Science** capability.
43 
44The table shows each capability and the control on the **Claude Science** page that it goes with.
45 
46| Capability in a custom role | Control on the **Claude Science** page |
47| - | - |
48| **Access previously saved work** | [**Allow members to access Claude Science work previously saved on their computer**](#previously-saved-claude-science-work) |
49| **Connect to SSH hosts** | [**Allow members to connect SSH hosts**](#ssh-hosts) |
50| **Custom connectors** | [**Allow custom connectors**](#custom-connectors) |
51| **Custom skills** | [**Allow custom skills**](#custom-skills) |
52| **Memory** | [**Turn on memory for your team**](#memory) |
53| **Modal** | [**Allow members to connect to Modal**](#modal) |
54| **Scientific model endpoint providers** | [**Show scientific model endpoint providers on the Compute tab**](#scientific-model-endpoints) |
55 
56The control on the **Claude Science** page is the upper limit, and roles narrow it:
57 
58* **Control off**: the feature is off for every member, whatever their roles include. In the role, the capability's row says that it's turned off at the organization level.
59* **Control on, built-in role**: members whose role is User, Admin, Owner, or Primary Owner can use the feature, because custom roles affect only members whose role is set to **Custom**. On Team plans, which don't have custom roles, that's every member.
60* **Control on, custom roles**: a member whose role is set to **Custom** can use the feature only if at least one of their custom roles has the capability turned on.
61 
62Turning on the **Claude Science** capability in a role also turns on the seven under it, and you can then turn off the ones that role shouldn't have. Any capability whose control your organization can't turn on stays off. Turning the **Claude Science** capability off turns them all off. A role whose **Capability access** setting is **All capabilities** already includes all seven. A role set to **All generally available** gets them when you turn on its **Claude Science** capability (see [Who gets access after you enable](/docs/claude-science/enable-claude-science#who-gets-access-after-you-enable)).
63 
64For a member whose custom roles don't include a capability, the feature behaves as it does when you turn its control off (see [How changes reach members](#how-changes-reach-members)). The setting is grayed out in the Claude Science app, and what the member set up earlier is kept. To give that member the feature, turn on the capability in one of their roles. A change to a role's capabilities can take up to 15 minutes to reach members, and then applies on the member's next turn or request.
65 
66The network allowlist, the package mirror, Modal workspaces, and the switches for Featured connectors and skills aren't set by role and apply to the whole organization. To create custom roles and assign them to groups, see [Manage custom roles on Enterprise plans](https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans).
67 
4068### Featured connectors and skills
4169 
4270Featured connectors and Featured skills come with Claude Science, and admins can control whether they are enabled or disabled for your members (see [Connectors and skills](/docs/claude-science/connectors-and-skills)). The **Featured connectors** and **Featured skills** sections list them with one switch per item, so you can choose which ones members can use. Every item is on by default for Team and Enterprise organizations. In an organization with HIPAA compliance enabled, every Featured connector and skill starts disabled; turn on the ones you have reviewed.
from line 87
5987 
6088If a connector needs a sign-in, each member signs in with their own account; the app opens claude.ai for them to do it. Connector permissions in Enterprise custom roles apply the same way; see [Connectors](#connectors) under How other admin settings apply to Claude Science.
6189 
62Two kinds of connectors are controlled on **Organization settings > Claude Science** instead: the Featured connectors that run on members' computers (see [Featured connectors and skills](#featured-connectors-and-skills)), and connectors members add in the app themselves (see [Custom connectors](#custom-connectors)).
90Two kinds of connectors are controlled on **Organization settings > Claude Science** instead: the Featured connectors that run on members' computers (see [Featured connectors and skills](#featured-connectors-and-skills)), and connectors members add in the app themselves (see [Custom connectors](#custom-connectors)). On Enterprise plans, a custom role's **Custom connectors** capability can also limit the second kind to certain roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)).
6391 
6492### Custom connectors
6593 
from line 99
7199 
72100Connectors are built on an open standard called the Model Context Protocol (MCP). When your organization needs a connector it doesn't have yet, what to do depends on where the data lives:
73101 
74* **Your own systems and data**, such as an internal database or lab system: have your developers build a connector for it, then add its web address for everyone under **Organization settings > Connectors > Add > Custom** (see [Third party connectors with remote MCP](/docs/connectors/custom/remote-mcp)). Claude connects to it from Anthropic's servers, so it must be reachable from the internet. For a system that isn't, Enterprise organizations can request an MCP tunnel, a secure link from their own network to Anthropic (in research preview; see [MCP tunnels](/docs/connectors/mcp-tunnels/overview)).
75* **Another company's product**: the company that makes the product usually builds and runs its connector, not Anthropic. Check the [Connectors Directory](/docs/connectors/directory) first. If the company offers a connector that isn't listed there, add its web address under **Organization settings > Connectors > Add > Custom**; a connector doesn't need to be in the directory to work (see [Connector verification](/docs/connectors/verification)). If the company doesn't offer one, ask them to build one. They can [submit it to the Connectors Directory](/docs/connectors/building/submission#submit-your-connector) for review; if Anthropic accepts it, any Claude user can find it there.
102* **Your own systems and data**, such as an internal database or lab system: have your developers build a connector for it, then add its web address for everyone under **Organization settings > Connectors > Add > Custom** (see [Add a connector by URL](/docs/connectors/custom/add-unlisted#add-a-connector-by-url)). Claude connects to it from Anthropic's servers, so it must be reachable from the internet. For a system that isn't, Enterprise organizations can request an MCP tunnel, a secure link from their own network to Anthropic (in research preview; see [MCP tunnels](/docs/connectors/mcp-tunnels/overview)).
103* **Another company's product**: the company that makes the product usually builds and runs its connector, not Anthropic. Check the [Connectors Directory](/docs/connectors/directory) first. If the company offers a connector that isn't listed there, add its web address under **Organization settings > Connectors > Add > Custom**; a connector doesn't need to be in the directory to work (see [Connector verification](/docs/connectors/verification)). If the company doesn't offer one, ask them to build one. They can [submit it to the Connectors Directory](/docs/connectors/building/submission) for review; if Anthropic accepts it, any Claude user can find it there.
76104* **Public scientific databases and tools**: Claude may not need a connector at all. Code that Claude runs on members' computers can reach any site on Claude Science's list of allowed sites, so adding the site to that list is often enough. By default, members allow a new site themselves when Claude asks. If you turn on **Manage network allowlist** on **Organization settings > Claude Science**, you add sites for them under **Custom domains** instead (see [Network allowlist](#network-allowlist)). If a connector would still help, look for one in the [Connectors Directory](/docs/connectors/directory) and add it on **Organization settings > Connectors**.
77105 
78106### Custom skills
from line 163
135163 
136164### SSH hosts
137165 
138Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see [Remote compute clusters](/docs/claude-science/remote-compute-clusters)). The **Allow members to connect SSH hosts** switch decides whether they can. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
166Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see [Remote compute clusters](/docs/claude-science/remote-compute-clusters)). The **Allow members to connect SSH hosts** switch decides whether they can. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on. On Enterprise plans, you can also limit SSH hosts to certain custom roles with the **Connect to SSH hosts** capability (see [Capabilities in custom roles](#capabilities-in-custom-roles)).
139167 
140168When the switch is off, members can't add SSH hosts, and hosts they added earlier are kept but refuse new commands and file transfers; the app shows that SSH host setup is disabled by your admin. A job that is already running can still be stopped and its results collected.
141169 
from line 195
167195 
168196When the switch is off, memory is off for every member, whatever they chose in their own settings; Claude neither recalls nor saves facts, first-time setup skips its memory step, and the **Memory** setting shows that memory is disabled by your admin. Facts a member saved earlier stay on their computer, the member can still review and delete them, and Claude uses them again if you turn the switch back on.
169197 
170When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session's conversation and handled like the rest of the conversation (see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data)). The **Capabilities** > **Memory** setting in claude.ai **Organization settings** doesn't control memory in Claude Science.
198When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session's conversation and handled like the rest of the conversation (see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data)). The **Capabilities** > **Memory** setting in claude.ai **Organization settings** doesn't control memory in Claude Science. In a custom role, the **Memory** row under **Claude Science** is the capability for the app's memory, and the **Memory** row under **Chat** is for claude.ai chat (see [Capabilities in custom roles](#capabilities-in-custom-roles)).
171199 
172200## How other admin settings apply to Claude Science
173201 
from line 217
189217| Organization and access > Domains | Supported in Claude Science | Domain verification, and the **Migrate accounts using your domains** and **Restrict organization creation** settings that build on it, act on claude.ai accounts before anyone reaches the app, so they apply unchanged. |
190218| Members | Supported in Claude Science | Adding or removing members controls who can sign in to Claude Science. |
191219| Roles (built-in) | Supported in Claude Science | Every built-in role (User, Admin, Owner, and Primary Owner) can use Claude Science once it's turned on for the organization. |
192| Roles > Claude Science permission in custom roles (Enterprise) | Supported in Claude Science | Add the Claude Science permission to a custom role to give the app to that role's members. Members whose custom roles don't include it can't use the app. Team plans don't have custom roles, so everyone gets access when Claude Science is on. |
220| Roles > Claude Science permission in custom roles (Enterprise) | Supported in Claude Science | Add the Claude Science permission to a custom role to give the app to that role's members. Members whose custom roles don't include it can't use the app. On the role's **Capabilities** tab, seven capabilities under **Claude Science** decide which of the app's features that role's members can use (see [Capabilities in custom roles](#capabilities-in-custom-roles)). Team plans don't have custom roles, so everyone gets access when Claude Science is on. |
193221| Groups (Enterprise) | Supported in Claude Science | Members get the Claude Science access of the roles their groups assign. |
194222| IP allowlist (Enterprise) | Partially supported in Claude Science | The app's sign-in, its requests to Claude, and its Directory connector calls are checked against your allowlist (see [Restrict access to Claude with IP allowlisting](https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting)). Traffic that doesn't go to Anthropic isn't checked, which covers code on the member's computer, SSH hosts, or Modal account, and custom connectors members add in the app. You can turn SSH hosts, Modal, and custom connectors off under [Organization settings](#organization-settings). |
195223| Organization and access > Shortened session length (Enterprise) | Partially supported in Claude Science | Applies to the browser sign-in a member completes to connect the app. It doesn't shorten the app's own sign-in after that, so members aren't asked to sign in again on your schedule. Turning Claude Science off for the organization or removing a member still stops their app within a few minutes. |
from line 234
206234| Capabilities > Code execution and file creation | Not applicable in Claude Science | This setting governs the code sandbox Anthropic hosts for claude.ai chat. Running code on the member's computer, or on compute the member connects, is the core of Claude Science and can't be turned off; you govern what that code can reach with the [network allowlist](#network-allowlist), [SSH hosts](#ssh-hosts), and [Modal](#modal) controls. |
207235| Capabilities > Allow network egress and Domain allowlist | Supported in Claude Science | These settings govern the hosted sandbox for claude.ai chat. Claude Science's sandbox has its own allowlist: manage it for the whole organization with the **Manage network allowlist** switch on the **Claude Science** page (see [Network allowlist](#network-allowlist)), or leave it off and let members manage their own. Administrators can also extend a member's list per device with the sandbox network keys in the [configuration file reference](/docs/claude-science/configuration-file-reference). |
208236| Data and privacy > Location metadata | Not applicable in Claude Science | Claude Science doesn't send location data with requests to Claude, so there is nothing for this setting to govern. |
209| Capabilities > Memory (Enable memory for your team) | Supported in Claude Science | This setting governs memory in claude.ai chat. Claude Science keeps a separate memory on each member's computer, which you turn on or off for everyone with the **Turn on memory for your team** switch on the **Claude Science** page (see [Memory](#memory)). |
237| Capabilities > Memory (Enable memory for your team) | Supported in Claude Science | This setting governs memory in claude.ai chat. Claude Science keeps a separate memory on each member's computer, which you turn on or off with the **Turn on memory for your team** switch on the **Claude Science** page (see [Memory](#memory)). On Enterprise plans, a custom role's **Memory** capability under **Claude Science** can limit it to certain roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). |
210238| Settings for claude.ai projects (Public projects, Retention period for projects) | Not applicable in Claude Science | Claude Science doesn't use claude.ai projects. Its projects are folders on the member's computer. |
211239 
212240### Connectors
from line 242
214242| Setting in claude.ai | Status for Claude Science | Note |
215243| - | - | - |
216244| Connectors > connectors you add for your organization | Supported in Claude Science | Connectors you add on the **Connectors** page, from the directory or by web address (custom connectors), are available to members in the app, as in claude.ai. Claude connects to them from Anthropic's servers, and members sign in with their own accounts where needed. |
217| Roles > connector permissions in custom roles (Enterprise) | Partially supported in Claude Science | Apply to the connectors on your **Connectors** page, which the app reaches through Anthropic. They don't apply to Featured connectors or custom connectors added via the Claude Science app; the **Claude Science** page controls those for every member rather than per role (see [Organization settings](#organization-settings)). |
245| Roles > connector permissions in custom roles (Enterprise) | Partially supported in Claude Science | Apply to the connectors on your **Connectors** page, which the app reaches through Anthropic. They don't apply to the Featured connectors that run on members' computers or to custom connectors members add in the Claude Science app. The **Claude Science** page controls those Featured connectors for every member. The **Allow custom connectors** switch there decides whether members can add and use custom connectors, and a separate capability in custom roles, **Custom connectors**, can limit that to certain roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). |
218246| Plugins > plugins you add for the organization | Partially supported in Claude Science | Plugins you set to **Installed by default** or **Required** are synced to members' Claude Science app, which loads their skills and connectors. Plugins left as **Available to install** aren't offered in the app, and plugin commands don't apply there. Which Featured connectors and skills members can use, and whether they can add their own, are separate controls on the **Claude Science** page (see [Featured connectors and skills](#featured-connectors-and-skills), [Custom connectors](#custom-connectors), and [Custom skills](#custom-skills)). |
219247| Connectors > Tunnels API (Enterprise) | Partially supported in Claude Science | A connector your organization serves through a tunnel works in the app the same way it does in claude.ai, because the app reaches the connectors on your **Connectors** page through Anthropic's hosted connector service. Custom connectors a member adds in the Claude Science app connect directly from the member's computer and never use a tunnel (admins can restrict this in [Custom connectors](#custom-connectors)). |
220| Connectors > connectors members add themselves | Supported in Claude Science | In claude.ai, members use only the connectors on your **Connectors** page. In Claude Science, members can also add custom connectors (a server URL or a local command) while the **Allow custom connectors** switch is on, which it is by default for Team and not for Enterprise, and the **Connectors** page and its restrictions don't apply to those. Turn off the **Allow custom connectors** switch under **Organization settings** > **Claude Science** to limit members to Featured connectors and the connectors you add on your **Connectors** page (see [Custom connectors](#custom-connectors)). |
248| Connectors > connectors members add themselves | Supported in Claude Science | In claude.ai, members use only the connectors on your **Connectors** page. In Claude Science, members can also add custom connectors (a server URL or a local command) while the **Allow custom connectors** switch is on, which it is by default for Team and not for Enterprise, and the **Connectors** page and its restrictions don't apply to those. Turn off the **Allow custom connectors** switch under **Organization settings** > **Claude Science** to limit members to Featured connectors and the connectors you add on your **Connectors** page (see [Custom connectors](#custom-connectors)). On Enterprise plans, you can also leave the switch on and limit custom connectors to certain custom roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). |
221249| Connectors > Desktop extension allowlist | Not applicable in Claude Science | Claude Science doesn't install desktop extensions, so there is nothing for this setting to govern. |
222250 
223251### Data and privacy

claude-science/enable-claude-science Changed · +4 / -2 lines

from line 48
4848Turning on the **Enable for your organization** toggle controls whether Claude Science is accessible to your organization at all. Adding members or assigning seats doesn't turn it on. Once it's on, roles control which members can use it:
4949 
5050Built-in roles include the Claude Science entitlement, so those members can download and sign in immediately.\
51Custom roles (Enterprise plans only) need the **Claude Science** capability added. Members on a custom role without the capability see the app as unavailable even after you enable it for the organization.\
52A custom role whose **Capability access** setting is **All capabilities** already includes Claude Science. The **All generally available** setting excludes beta capabilities such as Claude Science, so for those roles also select the **Claude Science** capability.
51Custom roles (Enterprise plans only) need the **Claude Science** capability turned on. Members on a custom role without the capability see the app as unavailable even after you enable it for the organization.\
52A custom role whose **Capability access** setting is **All capabilities** already includes Claude Science. The **All generally available** setting excludes beta capabilities such as Claude Science, so for those roles also turn on the **Claude Science** capability.
5353 
5454This is the same pattern as other Claude apps you enable per organization.
55 
56In a custom role, the **Claude Science** capability has seven capabilities under it, one for each feature you can limit by role, such as SSH hosts, Modal, and memory. Turning on the **Claude Science** capability turns these on too, and you can then turn off the ones that role shouldn't have (see [Capabilities in custom roles](/docs/claude-science/admin-controls#capabilities-in-custom-roles)). Any that goes with an organization setting you can't turn on stays off.
5557 
5658## What members see
5759 

claude-science/connectors-and-skills Changed · +1 / -1 lines

from line 48
4848* **Ask Claude first.** Many public databases and tools work without a connector, because the code Claude runs can reach websites directly. The first time Claude needs a new site, a permission card asks you to allow it. If your organization manages the list of allowed sites, ask an admin to add it. See [Sandbox](/docs/claude-science/core-concepts#sandbox).
4949* **Add one from the Connectors Directory.** Go to **Settings > Connectors > Add connector > Browse Connectors Directory**, which opens the directory in claude.ai. On Pro and Max plans, add the connector there and it appears in Claude Science. On Team and Enterprise plans, you may be able to add it yourself; if not, an admin can add it for your organization. On a Team plan, select **Request** on the connector's listing to ask your admins.
5050* **Add one yourself.** If the tool's maker gives you a web address for its connector (sometimes called an MCP server URL), go to **Settings > Connectors > Add connector > Remote URL** and paste it in. If the maker gives you a command to run instead, choose **Local command** and enter it there. On Team and Enterprise plans, this works only if your organization allows custom connectors. See [Custom connectors](/docs/claude-science/custom-connectors).
51* **Ask the tool's maker.** If no connector exists yet, ask them to build one and [submit it to the Connectors Directory](/docs/connectors/building/submission#submit-your-connector).
51* **Ask the tool's maker.** If no connector exists yet, ask them to build one and [submit it to the Connectors Directory](/docs/connectors/building/submission).
5252 
5353Admins can find the full set of options in [Add a connector your organization needs](/docs/claude-science/admin-controls#add-a-connector-your-organization-needs).
5454 

government/config/overview Changed · +1 / -1 lines

from line 92
9292 
9393When a higher-priority group gains configuration for someone, it takes the place of the lower-priority group that applied to them before, and the lower-priority group's settings, including locked ones, stop applying to them. Removing a group's last setting, changing the priority order, or changing someone's group memberships in your identity provider can change which group applies to a person in the same way.
9494 
95The priority order is set by a tenant administrator on the [Identity and access](/docs/government/tenant-admin/identity-and-access) page by dragging the groups into the order they want. The same priority order is used wherever configuration is resolved for a person; seat-tier group mappings on the [Provisioning](/docs/government/org-admin/provisioning) page use a separate fixed order. At the organization level the priority order is shown for reference and cannot be reordered there.
95A tenant administrator sets the priority order on the [Identity and access](/docs/government/tenant-admin/identity-and-access#directory-groups) page. The same priority order is used wherever configuration is resolved for a person; seat-tier group mappings on the [Provisioning](/docs/government/org-admin/provisioning) page use a separate fixed order. At the organization level the priority order is shown for reference and cannot be reordered there.
9696 
9797If no groups appear in the scope bar dropdown, none have been synced from the identity provider yet. Connect SCIM on the Identity and access page and push groups from your directory, and they will appear automatically.
9898 

government/tenant-admin/configuration Changed · +1 / -1 lines

from line 14
1414 
1515**Two settings that only tenant administrators can change.** [Let organizations manage their own seat tiers](/docs/government/config/settings#let-organizations-manage-their-own-seat-tiers) and [Compliance API](/docs/government/config/settings#compliance-api) are always read-only for organization owners, regardless of whether they are locked.
1616 
17**Group priority order.** You set the priority order between directory groups on the [Identity and access](/docs/government/tenant-admin/identity-and-access) page by dragging the groups into the order you want. Organization owners see this order for reference but cannot change it. See [When someone belongs to more than one group](/docs/government/config/overview#when-someone-belongs-to-more-than-one-group).
17**Group priority order.** You set the priority order between directory groups on the [Identity and access](/docs/government/tenant-admin/identity-and-access#directory-groups) page. Organization owners see this order for reference but cannot change it. See [When someone belongs to more than one group](/docs/government/config/overview#when-someone-belongs-to-more-than-one-group).
1818 
1919**Managing any organization's config.** As a tenant administrator you can open any organization's Config page and act on that organization's behalf, using the scope bar above the settings list. Organization owners see only their own organization.
2020 

government/tenant-admin/identity-and-access Changed · +2 / -2 lines

from line 99
9999 
100100## Directory groups
101101 
102Once your identity provider has pushed groups over SCIM, they appear here with their member counts. Drag the groups into the order you want; this priority is used for group-level configuration on the [Config](/docs/government/config/overview#group-specific-settings) page.
102Once your identity provider has pushed groups over SCIM, they appear here with their member counts. To change the order, drag a group by the handle at the start of its row or use the **…** menu at the end. The order you set here is the priority used for group-level configuration on the [Config](/docs/government/config/overview#group-specific-settings) page.
103103 
104104## Routing rules
105105 
from line 135
135135* An **email domain** rule matches the domain of the user's email address exactly. You choose from your tenant's verified domains; you cannot type an arbitrary domain. Subdomains are not matched automatically, so `sub.example.gov` needs its own rule if you want it routed.
136136* An **identity provider (IdP) group** rule matches a value in the group membership list that your identity provider includes in the sign-in token. You type the exact value your provider sends, and matching is exact and case-sensitive.
137137 
138Rules are evaluated from top to bottom, and the first match wins. When you have more than one rule, drag the handle next to a rule (or focus the handle and press the up or down arrow key) to reorder the list. Only one rule can exist for any given condition. If you pick a domain or group that already has a rule, a message below the form shows which organization it currently routes to and asks you to remove that rule first.
138Rules are evaluated from top to bottom, and the first match wins. To change the order, drag a rule by the handle at the start of its row or use the **…** menu at the end. Only one rule can exist for any given condition. If you pick a domain or group that already has a rule, a message below the form shows which organization it currently routes to and asks you to remove that rule first.
139139 
140140Each rule shows a status line with diagnostics:
141141 

government/tenant-admin/setup-wizard Changed · +1 / -1 lines

from line 81
8181* In the **Then place in** field, pick the organization.
8282* Click **Add rule**.
8383 
84Rules run from top to bottom and the first match wins, so drag more specific rules above broader ones. Rules that match directory groups pushed over SCIM are managed on the full [Identity and access](/docs/government/tenant-admin/identity-and-access#routing-rules) page, which also has a preview tool for testing where a specific email address would land.
84Rules run from top to bottom and the first match wins, so move more specific rules above broader ones. Rules that match directory groups pushed over SCIM are managed on the full [Identity and access](/docs/government/tenant-admin/identity-and-access#routing-rules) page, which also has a preview tool for testing where a specific email address would land.
8585 
8686## Steps 8 and 9: Seat tiers and Products (single-organization tenants only)
8787 
Feedback