// FOR ORGANIZATIONS

Report at volume. Manage a team. Plug it into your own tools.

An individual account is enough for reporting spam you personally receive. If you're a security or abuse team that sees spam at volume, or a business that wants shared visibility across a team, an organization account gives you that without changing how reporting itself works — every bulk submission still goes through the exact same evidence checks as a single report. Volume is never a shortcut around them.

Create an organization from your portal and you become its owner. Owners and admins can invite teammates by email — if someone doesn't have an OpenShield account yet, they get an email invite and join automatically the first time they sign in. You can change a teammate's role or remove them at any time; an organization always keeps at least one owner, so it can never be left unmanageable.

Bulk reporting

Organizations on the paid Enterprise plan can submit up to 100 reports in a single call — the natural fit for a security team's own detection pipeline. Each item is verified, checked for duplicates, and gated exactly like an individual report; a bad or duplicate item in a batch doesn't fail the rest.

Connect it to your own systems

Two ways to wire OpenShield into tooling your team already uses, both managed from your organization's portal:

  • API keys let your own detection pipeline submit bulk reports without a person logging in each time. An owner or admin creates a key, copies it once (it's never shown again), and can revoke it instantly if it's no longer needed.
  • Webhooks notify your own systems — Slack, a ticketing queue, a SIEM — the moment a case your organization reported reaches a meaningful stage (formally noticed, enforced against, or resolved). Each notification is signed, so your system can verify it really came from OpenShield.

Usage & audit log

A usage page shows your organization's bulk-reporting volume against its quota, so a large team never gets surprised by a limit. A separate, permanent audit log records who on your team added or removed a member, created or revoked an API key, or changed a webhook — a self-service record you can export for your own compliance needs, without waiting on us.

DMARC monitoring

Point your domain's DMARC aggregate-report address (the rua= tag) at OpenShield and see exactly who is sending — and spoofing — as your domain. Enroll a domain from the DMARC Monitoring page, prove ownership with a single DNS TXT record, and the spoofing-source dashboard lists every sending IP with its volume and whether it passed authentication, so an unauthorized high-volume sender stands out immediately. It never changes anything about how your domain is listed or scored — it's visibility, not enforcement.

Single sign-on (early access)

Organizations can configure sign-in through their own identity provider (OIDC) so teammates log in with the credentials they already use for work, and can set up automatic account provisioning so someone who leaves the company loses access without anyone having to remember to remove them by hand. This is genuinely new and still going through a security review before we turn it on for real logins — reach out if you'd like to be an early tester.