Skip to main content

Accounts & SSO

Your Fleet account is what links the Kenaz Harness you run locally to your organization's shared configuration, team, and billing. This page covers how to create one, how sign-in works, and how your organization can set up single sign-on.

:::tip New to Fleet? If you haven't set up an org yet, Getting Started walks through account creation, inviting your team, and publishing your first shared configuration from start to finish. :::

Creating an account

Accounts are created through the Fleet sign-up wizard at fleet.kameas.ai. You choose a plan during sign-up:

  • Pro — single seat, just your email.
  • Team — multi-seat org; you also provide an organization name.

The wizard walks you through three steps: account details, accepting the terms, and payment. After payment clears, your account is active and you can sign in from the Harness or the Fleet dashboard.

There is a 14-day free trial — no charge until day 15, and you can cancel through the billing portal at any time before that.

Signing in

Fleet uses standard OIDC single sign-on, which means you authenticate once and every signed-in Harness picks up your identity automatically.

From the Fleet dashboard

  1. Go to fleet.kameas.ai and enter your work email.
  2. If your organization has configured a corporate identity provider (see below), you're redirected to your company's login page automatically.
  3. Otherwise you complete email + password login.

From the Kenaz Harness

Sign-in from the Harness follows the same flow. Once authenticated, the Harness registers itself with Fleet and begins syncing any shared configuration your admin has published.

Sign-in options

Fleet supports three sign-in methods:

MethodHow it works
Email + passwordAvailable to all plans.
Google SSOYour Google Workspace account, if your organization has configured Google as the identity provider.
Microsoft SSOYour Microsoft / Entra account, if your organization has configured Microsoft as the identity provider.
Custom SAML / OIDCConnect your own IdP (Okta, Azure AD, generic SAML/OIDC). Enterprise plan only — see Corporate SSO below.

The login page uses email domain discovery. When you enter your work email and press Continue, Fleet checks whether your organization has a corporate SSO configuration bound to your email domain. If it does, you're redirected to your IdP automatically — you never see a password field.

Corporate SSO (Enterprise)

Enterprise orgs can connect their own identity provider — Okta (OIDC or SAML), Microsoft Entra (OIDC or SAML), Google (OIDC), Auth0, or any generic OIDC/SAML provider.

Only org owners and admins can configure SSO. To set it up:

  1. Open Settings → SSO in the Fleet dashboard.
  2. Select your provider type and enter your IdP's details.
  3. Claim and verify your email domains.
  4. Test the connection before activating it.

Once SSO is active, anyone signing in with an email on your claimed domains is routed to your IdP. Members who were previously using email + password continue to work during a transition period.

SCIM provisioning (automatic user creation and de-provisioning from your IdP directory) is also available on Enterprise. Only the org owner can mint SCIM tokens; admins can view and revoke existing tokens.

Staff vs. customer accounts

Kameas staff accounts are a distinct identity category. Staff accounts are federated to the Kameas Google Workspace and are excluded from customer sign-up flows — they cannot be created through the self-serve wizard, and they cannot hold customer org roles. If you're a customer and you see an "account already exists" error, contact support; do not attempt to sign up with a Kameas staff email.

Signing out

To sign out:

  • Dashboard: click your avatar in the top right and select Sign out.
  • Harness: open the Fleet panel and disconnect your account.

Signing out from the Harness stops configuration sync. Your Harness continues working with whatever configuration it last received.


Next: Organizations & Teams — invite members, create teams, and understand what each role can do.