04 · Identity and domain blocker
Target identity topology for chargebee.com
Anthropic documents
that domain verification lives at the parent-organization level. Another parent cannot claim
chargebee.com, but multiple Team/Enterprise organizations can share one parent’s domain and SSO.
01
Enterprise parent
Existing parent retains verified chargebee.com and current IdP.
02
Merge Team org
Enterprise owner invites each Team organization into the parent.
03
Map groups
Unique IdP group per Team org; Team uses JIT rather than SCIM.
04
Real identities
@chargebee.com users switch between authorized orgs.
Error observed: “You are not under any organizations of your domain”
Anthropic does not publish a definition for this exact error string. The documented rules make the likely
cause clear: the destination
chargebeeinc Team org does not currently have
chargebee.com as an allowed domain under the same identity parent. Direct invitations and invite
links still check the invitee’s domain against the destination organization’s allowed domains
(
invite-link rules).
Meanwhile,
chargebee.com is already verified by the Enterprise parent, and another parent cannot
claim it. If Enterprise domain capture is active, new
chargebee.com accounts are also routed
directly through Enterprise SSO
(
domain-capture rules).
What official docs confirm
Current POC prerequisites
- The invited org’s members must all match a verified parent domain.
- The POC currently contains separate
chargebeeinc identities.
- The invited org cannot already belong to another parent.
- Anthropic Support may need to detach the POC parent and migrate ownership/members.
- Future Team orgs should be created directly within the supported parent topology.
Why each attempted path behaves differently
| Attempt | Expected result | Technical reason | Correct action |
Add @chargebee.com directly to the unrelated chargebeeinc Team org |
Needs parent linking |
The destination org’s parent does not own that domain; another parent already verified it. |
Merge/link the Team org into the existing Enterprise identity parent first. |
| Use “Continue with Google” |
No topology change |
Authentication proves identity; it does not change Anthropic domain ownership, allowed-domain checks or parent membership. |
Use the corporate IdP configured on the shared parent. Google Workspace could be that SAML IdP, but changing IdPs is unrelated to this fix. |
| Invite using an org link |
Requires allowed domain |
Invite links only work when the invitee matches the organization’s allowed domains. They are unavailable entirely when SSO is enabled. |
After parent linking, provision through SSO/JIT and mapped IdP groups. |
| Link Team org under Enterprise parent |
Supported path |
Linked organizations share domain verification and SSO while retaining separate billing and usage. |
Satisfy merge prerequisites or ask Anthropic Support to detach/migrate the POC org. |
Current POC merge complication
The invited organization’s existing members must all have email addresses matching a domain verified by the
destination parent, and the invited organization cannot already have another parent. Because the POC owner and
members use chargebeeinc identities, a self-service merge may not be available. The clean options
are Support-assisted detachment/owner migration or creation of a fresh Team child under the Enterprise parent.
Google sign-in and domain ownership
“Continue with Google” authenticates a user; it does not move domain ownership between Anthropic parents.
Google Workspace can be the SAML IdP, but replacing Okta changes the shared SSO connection for every child org
and adds migration risk without changing token economics. Keep the existing corporate IdP unless IT has a
separate reason to migrate.
Support request to send
Copy/adapt this; it asks for topology support, not special permission to own multiple teams.
We have an existing Claude Enterprise parent with chargebee.com verified and a Team POC created under
chargebeeinc because the domain was already claimed. When inviting a chargebee.com account to the Team org,
we receive “You are not under any organizations of your domain.” Please help link this Team org—and future Team orgs—
under the existing Enterprise parent so they share chargebee.com SSO/domain verification while retaining
separate Team billing and usage. We intend to use unique IdP group mappings per Team org. Please advise the
required detachment, owner transfer, and member migration steps for the current POC org, whose current
owner/members use chargebeeinc identities.