Manage access and feature controls for your organisation
As an org admin, you can set default permissions that apply across all teams in your organisation. You can also control whether team admins can customise these settings for their teams. Team admins can manage access rights and turn features on or off based on your organisation's policies.
- To configure your SCIM integration, see SCIM user provisioning and de-provisioning.
- To set up SSO, see Setting up SSO login and signup controls.
Set organisation default permissions
Set organization default permissions
You can set default permissions that apply across all teams in your organisation. This gives you centralised control over what team members can do.
- From the homepage, go to your account profile, then select Settings.
- Go to the Controls and permissions section.
- Select Permissions.
- Use the search function to find specific settings you want to edit.
- Select the dropdowns under Organisation default to configure each permission. Choose from:
- Everyon
- Team admins and team brand designers
- Team admins only
- No one
Permissions you set here apply to all teams unless a team has overrides enabled.
Control team admin overrides
You can choose whether team admins can customise permissions for their individual teams.
- From the homepage, go to your account profile, then select Settings.
- Go to the Controls and permissions section.
- Select Permissions.
- Choose the Team management tab.
- Enable or disable the toggles under Team Overrides for each permission setting.
When you enable team overrides, team admins can change permissions for their teams. When you disable team overrides, your organisation defaults apply to all teams automatically.
View teams with different permissions
You can see which teams have permissions that differ from your organisation defaults.
- From the homepage, go to your account profile, then select Settings.
- Go to the Controls and permissions section.
- Select Permissions. Teams with different permissions appear next to Organisation.
- Select a team to view their specific permission settings.
- You can also change the permission settings for individual teams from this view.
Granting team and role access
Note: If your org admin has disabled team overrides, some settings below may not be editable. Contact your org admin to request changes.
Provision team and role access for team members of the organisation and set the rules on:
- Who can join, leave, and invite new team members
- Manage role-based access and email visibility
Canva Enterprise lets you set a joining policy, restrict new team member invites, and control email visibility. Learn more about Canva Enterprise.
Here’s how to set it up:
- From the homepage, go to your account profile, then select Settings.
- Select Controls.
- To set up the joining policy, go to Team access tab, click the dropdown beside ‘Who can join this team?’ If you need to limit team members or assure security, choose among these options:
- Only invited people can join
- Anyone with an [emaildomain] email can join
- Anyone with an [emaildomain] email can request to join
- To keep access to content and secure it from departing team members, click the dropdown beside Who can leave this team? and set it to Admins only.
- Note: If you set permission to Everyone, you won’t be able to control content transfer. Learn more about transferring content and design ownership.
- To set limits on new team members-invite, click the dropdown beside Who can invite new members? and choose to set it to:
- Everyone
- Members with admin approval
- Admins and brand designers
- Admins only
Note: If you set permission to Everyone, new team members will incur a subscription charge.
Role-based access and email visibility
- Only team admins can change a team member’s role
- Team admins and brand designers can publish Brand Templates
- To set rules for group creation, select the Who can create a group? dropdown, if Group Permissions are enabled, choose Everyone, No one, or Select Groups & Roles. If Group Permissions aren't enabled, choose Everyone, Admins and Brand Designers, or No one.
- To restrict visibility on member emails, select Who can see member emails? dropdown, if Group Permissions are enabled, choose Everyone, No one, or Select Groups & Roles. If Group Permissions aren't enabled, choose Everyone, Admins and Brand Designers, or No one. Learn more about group permissions.
Managing feature controls
As a team admin, you can turn features and functionalities on or off based on your organisation's policies and needs.
To oversee the configuration of Canva Enterprise feature controls:
- From the homepage, go to your account profile, then select Settings.
- Select Permissions.
- From here, you can start setting up, applying rules, and restricting who can have access to features under these categories:
- Magic and AI
- Enable or disable Canva Assistant
- Set permissions for team members to access Dream Lab
- Control who can use Magic features
- Canva content
- Team content
- Share and Publish
- Integrations
- Magic and AI
Review permission audit logs
Org admins can review a history of permission changes across your organisation to maintain compliance visibility.
- From the homepage, select your profile photo.
- Select Settings, then select Security.
- Select Audit Log.
Managing design sharing with Canva Support
As an Organisation Admin, you can choose whether to let team members consent to temporarily share affected designs with Canva Support when requesting help. This setting will be applied across all teams in the Organisation.
To manage design sharing with Canva Support:
- From the homepage, go to your account profile.
- Select Settings.
- Select Data and privacy.
- Turn the toggle On or Off for Allow team members to temporarily share affected designs with Canva Support.
Was this helpful?
Helpful
Unhelpful