> For the complete documentation index, see [llms.txt](https://academy.shade.inc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://academy.shade.inc/guides/setup-and-migration/roll-out-shade-company-wide.md).

# Roll out Shade company-wide

An admin's checklist for rolling Shade out to a large organization, with SSO, SCIM, managed installs, and shared cache.

**Outcome:** Shade rolled out to a large team. People sign in through your identity provider, membership follows your directory, the desktop app installs itself on managed Macs, and offices share a local cache.

**Who it's for:** IT and workspace admins at organizations with dozens to hundreds of Shade users. Some of these steps need an Enterprise plan.

**Time:** a few days, mostly spent waiting on identity provider and device-management changes.

## Before you start

* Decide whether you need one workspace or several. Large organizations with separate departments often want several workspaces under one organization with shared billing. Contact Shade to set that up. See [Setting Up Workspaces and Drives](https://academy.shade.inc/workspaces-and-drives/setting-up-workspaces-and-drives).
* Have admin access to your identity provider and your Mac device-management tool.

## Checklist

{% stepper %}
{% step %}

### Verify your domain and turn on SSO

Go to **Settings > Enterprise**, click **Add domain** under **Domain Verification**, and follow the steps. Then choose **Set up SSO** and pick your SAML provider. Once SSO is on, anyone with your domain signs in through your identity provider.

See [Enterprise Security and SSO](https://academy.shade.inc/enterprise/enterprise-security-and-sso).
{% endstep %}

{% step %}

### Sync membership with SCIM

Choose **Set up SCIM** in the same section. Members of the groups you provision are added to Shade automatically, and those groups appear in **Groups** with the type **Directory**. Make membership changes in your identity provider. Directory groups are read-only in Shade.

Every SCIM-provisioned user is a workspace member and takes a paid seat, so provision only the groups that need Shade.
{% endstep %}

{% step %}

### Map groups to drives

Give each department its own drives, and grant access to the synced groups rather than to individual people. Set each drive's default inheritance deliberately. See [Designing Your Permission Hierarchy](https://academy.shade.inc/sharing-and-collaboration/designing-your-permission-hierarchy).
{% endstep %}

{% step %}

### Push the desktop app to managed Macs

Download the right Shade PKG for each Mac architecture (Apple Silicon or Intel), upload it to Jamf Pro, and deploy it with a policy. See [Deploying the Shade PKG to Jamf Pro](https://academy.shade.inc/enterprise/deploying-the-shade-pkg-to-jamf-pro).
{% endstep %}

{% step %}

### Open the right network paths

If your network filters outbound traffic, allow Shade's domains before rollout day. See [Shade Network Configuration Guide](https://academy.shade.inc/help-center/security/shade-network-configuration-guide).
{% endstep %}

{% step %}

### Add a shared cache in each office

In offices where several editors work from the same footage, run a shared cache server on the local network. The first person to open a file pulls it from the cloud, and everyone after that gets it at LAN speed. See [Using Shared Cache](https://academy.shade.inc/shared-cache/using-shared-cache).
{% endstep %}

{% step %}

### Turn on audit logging

Send Shade's audit events to your security tools. See [Audit Logging](https://academy.shade.inc/help-center/security/audit-logging) and [Shade SIEM Documentation](https://academy.shade.inc/help-center/security/shade-siem-documentation).
{% endstep %}
{% endstepper %}

## Related guides

* [Your first week in Shade](/guides/setup-and-migration/your-first-week-in-shade.md)
* [Work with freelancers](/guides/review-and-client-delivery/work-with-freelancers.md)
* [Edit remotely over ShadeFS](/guides/editing-integrations/edit-remotely-over-shadefs.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://academy.shade.inc/guides/setup-and-migration/roll-out-shade-company-wide.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
