security
Glossary ↗Domain Capture
Domain capture — also called domain claiming or domain verification — is the administrative feature that lets an organisation prove ownership of an email domain and take control of every account in a SaaS product created with an address on it. Once claimed, existing personal or team workspaces created by employees are absorbed into the corporate tenant, new signups on that domain join it automatically instead of creating their own island, and the admin gains visibility, policy enforcement and the ability to deprovision. It exists because bottom-up SaaS adoption creates exactly the mess it cleans up: a designer starts a free workspace, a team of five grows inside it, three years of work accumulates in an account the company does not administer and cannot recover if that person leaves. That situation is shadow IT with data in it. Domain capture is how a company converts those pockets into managed tenants without asking each team to migrate manually. The mechanics are worth understanding before you run it. Claiming usually requires a DNS record or a verification file, the same proof a domain-ownership check uses elsewhere. Vendors differ on what happens to the content in absorbed workspaces — some transfer ownership of data to the organisation, some only place the user under management — and on whether affected users are notified. It also has a personal-data dimension: absorbing an account can give administrators access to material an employee reasonably considered private, so the rollout should be announced, not sprung, and paired with a clear acceptable-use position. Run it in sequence: claim the domain, then enforce SSO, then turn on SCIM, so that entry, identity and exit are all governed rather than only the first.
Related terms