Skip to main content
Feature available with the Enterprise Plan Workspace security controls protect Orq.ai workspaces with verified domains and approved network ranges. Only workspace admins can manage these settings. Navigate to Settings > Organization > Security.

Domains

Verify domain ownership with a DNS TXT record. Each domain remains pending until Orq.ai finds the required record.
1

Add a domain

Select Domain. Enter the root domain. Do not include a protocol or path. Select Add domain.
2

Add the TXT record

Copy the displayed TXT host and TXT value to the DNS provider.
3

Verify the domain

Open the menu. Select View TXT details. After the DNS record is available, select Verify domain.
The verification challenge expires after seven days. Add the domain again to create a new challenge after expiration. To remove a domain, open the menu. Select Delete.

IP allowlist

Restrict workspace requests to approved IPv4 or IPv6 network ranges. Every listed range applies while the global allowlist is enabled. The IP allowlist applies only to requests to Orq.ai backend APIs. It does not restrict access to the AI Studio frontend.
Add the current network range before enabling the allowlist, or you may lose access to the workspace.
1

Add an IP range

Select IP range. Enter the range in CIDR notation, or select Use my current IP. Add an optional description.
2

Choose the CIDR prefix

Use /32 for one IPv4 address. Use /128 for one IPv6 address.
3

Enable the allowlist

Turn on Enable allowlist after all required ranges are present.
Open the menu to delete a range. To stop enforcing all ranges without deleting them, turn off Enable allowlist. Domain actions, allowlist changes, and IP range actions are recorded under Settings > Organization > Audit Logs.