# Home Page

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>Command</strong></td><td>Securely access and manage your Verkada devices through our web-based platform</td><td><a href="https://help.verkada.com/command/">https://help.verkada.com/command/</a></td><td><a href="/files/8bXdWJw3QzpKq0kNI73n">/files/8bXdWJw3QzpKq0kNI73n</a></td></tr><tr><td><strong>Government Solutions</strong></td><td>Proactive, streamlined, and scalable approach to physical security, with key enhancements for high-security government use</td><td><a href="https://help.verkada.com/government-solutions/">https://help.verkada.com/government-solutions/</a></td><td><a href="/files/a85iinar9TlIg0NLGqD2">/files/a85iinar9TlIg0NLGqD2</a></td></tr><tr><td><strong>Video Security</strong></td><td>Manage your enterprise security with our infinitely scalable hybrid cloud video surveillance solution</td><td><a href="https://help.verkada.com/verkada-cameras/">https://help.verkada.com/verkada-cameras/</a></td><td><a href="/files/ldQIHN3N6ce3r12UUtSG">/files/ldQIHN3N6ce3r12UUtSG</a></td></tr><tr><td><strong>Access Control</strong></td><td>Manage building access with our plug-and-play hybrid cloud system</td><td><a href="https://help.verkada.com/access-control/">https://help.verkada.com/access-control/</a></td><td><a href="/files/DaMZWzetqjosej2vwMnw">/files/DaMZWzetqjosej2vwMnw</a></td></tr><tr><td><strong>Intercom</strong></td><td>Effortlessly manage, speak to, and view visitors before they enter your building</td><td><a href="https://help.verkada.com/intercom/">https://help.verkada.com/intercom/</a></td><td><a href="/files/3WxEozQi0BrrCbfaaaGB">/files/3WxEozQi0BrrCbfaaaGB</a></td></tr><tr><td><strong>Air Quality Sensors</strong></td><td>Get a detailed real-time view of what is happening in your facility</td><td><a href="https://help.verkada.com/air-quality/">https://help.verkada.com/air-quality/</a></td><td><a href="/files/paIeNaU4Xq1qirNMedFS">/files/paIeNaU4Xq1qirNMedFS</a></td></tr><tr><td><strong>New Alarms</strong></td><td>Detect and respond to intruders using our software, devices, and services</td><td><a href="https://help.verkada.com/new-alarms/">https://help.verkada.com/new-alarms/</a></td><td><a href="/files/t60yajTIFEMzKJtukDff">/files/t60yajTIFEMzKJtukDff</a></td></tr><tr><td><strong>Classic Alarms</strong></td><td>Detect and respond to intruders using our software, devices, and services</td><td><a href="https://help.verkada.com/classic-alarms/">https://help.verkada.com/classic-alarms/</a></td><td><a href="/files/RALFOQn5bhStXsJ5tinZ">/files/RALFOQn5bhStXsJ5tinZ</a></td></tr><tr><td><strong>Guest</strong></td><td>Our visitor management system that integrates seamlessly with video security and access control</td><td><a href="https://help.verkada.com/guest/">https://help.verkada.com/guest/</a></td><td><a href="/files/dRJrHc6gRFF2JU7H2W2G">/files/dRJrHc6gRFF2JU7H2W2G</a></td></tr><tr><td><strong>Connectivity</strong></td><td>Deploy Verkada products anywhere with cell signal or Wi-Fi</td><td><a href="https://help.verkada.com/connectivity/">https://help.verkada.com/connectivity/</a></td><td><a href="/files/ynmjltnEpmEnVN27FGo9">/files/ynmjltnEpmEnVN27FGo9</a></td></tr><tr><td><strong>Command Connector</strong></td><td>Add non-Verkada cameras to your Command organization quickly, easily, and reliably</td><td><a href="https://help.verkada.com/command-connector/">https://help.verkada.com/command-connector/</a></td><td><a href="/files/Cjy6lrVRe385pPqb0eiH">/files/Cjy6lrVRe385pPqb0eiH</a></td></tr><tr><td><strong>Viewing Station</strong></td><td>Stream 30 camera feeds simultaneously to any display with user-customizable layouts</td><td><a href="https://help.verkada.com/viewing-station/">https://help.verkada.com/viewing-station/</a></td><td><a href="/files/1EJQiIBqxTmBhzlg2aUD">/files/1EJQiIBqxTmBhzlg2aUD</a></td></tr><tr><td><strong>Mailroom</strong></td><td>Streamline deliveries with an app to scan packages, notify recipients, and manage deliveries</td><td><a href="https://help.verkada.com/mailroom/">https://help.verkada.com/mailroom/</a></td><td><a href="/files/TVq1siQrrWDUBwuoneoh">/files/TVq1siQrrWDUBwuoneoh</a></td></tr><tr><td><strong>Incident Response</strong></td><td>Locate and check in on people's well-being during an emergency</td><td><a href="https://help.verkada.com/incident-response/">https://help.verkada.com/incident-response/</a></td><td><a href="/files/XiWn4CN7Qh0ljjgkmhf7">/files/XiWn4CN7Qh0ljjgkmhf7</a></td></tr><tr><td><strong>Security Trailer</strong></td><td>Our solar-powered, cloud-managed trailer gives you instant security anywhere</td><td><a href="https://help.verkada.com/security-trailer/">https://help.verkada.com/security-trailer/</a></td><td><a href="/files/TWBSL4jKdNsjaKUAyBYG">/files/TWBSL4jKdNsjaKUAyBYG</a></td></tr></tbody></table>


# Command

Securely access and manage your Verkada devices through our web-based platform

**Overview**\
Verkada Command is a cloud-based platform that lets you manage all Verkada products from a single, secure interface. You can monitor devices and system health, adjust settings, review events, and manage users across all sites in your organization. Command supports SSO and third-party provisioning to centralize authentication and automate user management through your identity provider. The platform unifies cameras, access control, alarms, sensors, intercom, and other products in one place to keep your security operations efficient and organized.

This collection guides you through using Command to manage your organization and sites, configure user roles and permissions, monitor device health, track activity across all products, and leverage tools that simplify day-to-day security operations.

Check out these links to get started:

<table data-view="cards"><thead><tr><th data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/3xGCS3mgZorlDIGcjowr">/pages/3xGCS3mgZorlDIGcjowr</a></td></tr><tr><td><a href="/pages/aGdcffaKhJDNs4z3tJvo">/pages/aGdcffaKhJDNs4z3tJvo</a></td></tr><tr><td><a href="/pages/KrF8B4CQb4ukbsd9Ee2C">/pages/KrF8B4CQb4ukbsd9Ee2C</a></td></tr></tbody></table>

***

You can also check out this video and others on our [video training center.](https://www.youtube.com/@Verkada)

{% embed url="<https://www.youtube.com/watch?list=PL3USUWfBbtdL8jOcyAnCPozw-PkzWXtfN&v=QwSngXrWUoc>" %}


# Create a Command Organization

Create a Command account to manage your Verkada devices

Verkada’s web software is Command. You need Command to interact with and monitor all of your Verkada devices.

## Create a Command Account

{% stepper %}
{% step %}
**Navigate to the** [**Command**](https://command.verkada.com) **home page.**
{% endstep %}

{% step %}
**Click Create a New Organization.**
{% endstep %}

{% step %}
**Enter your email and click Continue.**
{% endstep %}

{% step %}
**Enter your organization name and select a region to create your organization in.**
{% endstep %}

{% step %}
**Click Next to continue.**
{% endstep %}

{% step %}
**An organization short name will be automatically generated.**

**Note:** You can edit the short name to anything not already used by another Command account.
{% endstep %}

{% step %}
**Click Next to continue.**
{% endstep %}

{% step %}
**Select a data residency region for your organization.**
{% endstep %}

{% step %}
**Click Next to continue.**
{% endstep %}

{% step %}
**Enter the following user information:**

1. First Name
2. Last Name
3. Phone (optional)
4. Create Password
5. Confirm Password
   {% endstep %}

{% step %}
**Click Submit to create your organization.**
{% endstep %}
{% endstepper %}

***

### Verify your email address

You will need to verify your email address before you can access your Command account

{% stepper %}
{% step %}
**You will be brought to an overview page after you create your organization.**
{% endstep %}

{% step %}
**Click Next, and you will be prompted to check your inbox for a verification email.**
{% endstep %}

{% step %}
**From the email, click Verify Email.**
{% endstep %}

{% step %}
**A new web page will open confirming the email verification.**
{% endstep %}

{% step %}
**Click Continue to log in to your Command account.**
{% endstep %}
{% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=vme3YdOdhsE).
{% endhint %}


# Get Started with Verkada Command

Learn how to manage your devices with Verkada Command

## Create a Command account

Verkada’s web software is called Command. Command is the platform used to interact with and monitor all of your Verkada devices. See [Create a Command Account](/command/getting-started/create-a-command-organization) for more information.

## Organization settings

Org Admins will have access to the **Admin** page, where they can manage org-wide settings and configurations. These include managing users, accessing the audit log, licensing, and support access. See [Manage Your Admin Page Settings](/command/organization-settings/manage-your-admin-page-settings) for more information.

## Add devices

Org Admins need to add devices to Command before you can access and manage them. Add devices from the **Devices** page or directly from the site for some product lines. See [Add a Device to Your Command Account](/command/organization-settings/add-a-device-to-your-command-organization) for more information.

## Licensing

Most Verkada devices managed in Command will need a license. Licenses are managed from the [Manage Licenses](https://command.verkada.com/admin/org-settings/license-manager?tab=productLicenses) page. Verkada licensing is applied for each Command organization, and the licenses co-term to a single expiration date. Your licenses may have been automatically added if you claimed your devices via order number. Otherwise, manually add the licenses from the Admin page. See [Manage Your Licenses](/command/licensing/manage-your-licenses) for more information on adding and managing licenses.

## Add users

Your Verkada Command software license includes unlimited users. See [Manage Users in Your Organization](/command/users-and-permissions/manage-users-in-your-organization) for more information.

#### Permissions

Assign different permission levels to users in your organization based on your organization’s security needs. Permissions can be assigned at the org level and the site level for each product line to give each user the exact amount of access they need. See [Roles and Permissions for Command](/command/users-and-permissions/roles-and-permissions-for-command) for more information.

#### Single Sign-On (SSO)

SSO allows you to log in using a third-party authentication service, such as Okta, Microsoft Entra ID, G Suite, etc. This method provides a single point of management for authentication across multiple applications, including Verkada Command. See [Single Sign-On (SSO)](/command/security/identity-providers) for more information.

{% hint style="info" %}
Verkada recommends enabling OIDC instead of SAML when available.
{% endhint %}

#### SCIM

SCIM allows you to sync users and groups from your IdP management software Verkada Command. This enables you to manage users and permission groups easily. See our [SCIM/SSO](/command/security/identity-providers) section of the knowledge base for more information.

## Check network settings

Verkada devices are designed to be plug-and-play. However, if your environment includes a firewall with custom rules and policies, you may need to make some configuration changes to get your devices connected to the cloud. See [Required Network Settings](/command/need-help/required-network-settings) for more information.

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=QwSngXrWUoc).
{% endhint %}


# Quick Reference Guide for Verkada Command

Reference links to help you navigate Verkada Command

## Account Setup

* [Get Started with Verkada Command](/command/getting-started/get-started-with-verkada-command)
* [Required Network Settings](/command/need-help/required-network-settings)
* [Verkada Command System Requirements](/command/need-help/required-network-settings/verkada-command-system-requirements)
* [Verify Your Verkada Command Account](/command/security/authentication-overview/verify-your-verkada-command-account)
* [Switch Organizations in Command](/command/security/authentication-overview/switch-organizations-in-command)

## Users and Permissions

* [Roles and Permissions for Command](/command/users-and-permissions/roles-and-permissions-for-command)
* [Customize Roles and Permissions](/command/users-and-permissions/roles-and-permissions-for-command/customize-roles-and-permissions)
* [Manage Users in Your Organization](/command/users-and-permissions/manage-users-in-your-organization)
* [Manage Temporary Users](/command/users-and-permissions/manage-users-in-your-organization/manage-temporary-users)
* [Login Links](/command/security/authentication-overview/login-links)

## Organization Settings

* [Manage Your Admin Page Settings](/command/organization-settings/manage-your-admin-page-settings)
* [Manage and View Audit Logs](/command/organization-settings/manage-your-admin-page-settings/manage-and-view-audit-logs)
* [Feature Manager](/command/organization-settings/manage-your-admin-page-settings/feature-manager)
* [Partner Installation Guide](/command/need-help/site-planner-homepage-overview/verkada-best-practice-partner-installation-guide)

## Authentication

* [Authentication Overview](/command/security/authentication-overview)
* [Two-Factor Authentication](/command/security/authentication-overview/two-factor-authentication)
* [Identity Providers Overview](/command/security/identity-providers)
* [Microsoft Entra ID](/command/security/identity-providers/microsoft-entra-id)
* [Okta](/command/security/identity-providers/okta)
* [SCIM Token Management](/command/security/identity-providers/scim-token-management)

## **Data Protection and Security**

* [Set a Default or Camera-Specific Location for Image and Video Data](/command/security/privacy-and-security-disclosure/set-a-default-or-camera-specific-location-for-image-and-video-data-storage-and-processing)
* [Privacy and Security Checklist](/command/security/privacy-and-security-disclosure/privacy-and-security-checklist)
* [Enable Data Sharing with Verkada](/command/security/privacy-and-security-disclosure/enable-data-sharing-with-verkada)

## Troubleshooting

* [Contact Verkada Support](/command/need-help/contact-verkada-support)
* [Enable Support Access](/command/need-help/contact-verkada-support/enable-support-access)
* [Clear Your Browser Cache](/command/need-help/required-network-settings/clear-your-browser-cache)

{% hint style="info" %}
Follow [our blog](https://www.verkada.com/blog/) for all our latest features and announcements!
{% endhint %}


# Manage Users

Learn how to add, deactivate, reactivate, or delete a user from your organization

Your Verkada Command software license includes unlimited users. Use this article to learn more about how to manage users in your Command organizational account. Learn more about [Roles and Permissions for Command](/command/users-and-permissions/roles-and-permissions-for-command).

***

## Invite a user to your organization

With an Org Admin account, you can invite users to your organization’s Command account and control their access. Once invited, your users receive an automatic email inviting them to create their account and set a password.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**At the top right, select Add User.**
{% endstep %}

{% step %}
**(Optional) Enter the user’s first name, last name, email address**, **phone number, and upload a profile photo.**
{% endstep %}

{% step %}
**(Optional) Select Command Roles to grant user permissions in Command.** See [Roles and Permissions](/command/users-and-permissions/roles-and-permissions-for-command#set-permissions) for more information.
{% endstep %}

{% step %}
**(Optional) Add the user to Command groups.**
{% endstep %}

{% step %}
**(Optional) Set the user as a Temporary User and set an end date for their access to Command.**

See [Manage Temporary Users](/command/users-and-permissions/manage-users-in-your-organization/manage-temporary-users) to learn more about deactivation, restrictions, and other management capabilities on Temporary Users.

<div align="left" data-with-frame="true"><figure><img src="/files/mVrm99TL0IYYUXLBcFCp" alt=""><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

Your users should receive an email inviting them to your organization’s Command account with the role permissions you define.

{% hint style="warning" %}
If you or your users don’t receive the invite email as expected, check your spam folder. Some email filters may prevent it from reaching your inbox.
{% endhint %}

### Invited users

Users who have been invited to your organization but have not accepted the invitation will show up under the **Invited** filter. This state gives Org Admins visibility and control over who is active in the organization.

<div align="left" data-with-frame="true"><figure><img src="/files/R3B8c1M0COjjw2jwjidg" alt=""><figcaption></figcaption></figure></div>

{% hint style="warning" %}
Invited users can still be assigned to groups, permissions, and alerts.
{% endhint %}

***

## Deactivate a user

You can deactivate these types of users: [Command](#h_7ae35d2759) or System for Cross-Domain Identity Management ([SCIM](#h_6d57c015cb)).

### Deactivate Command users

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Select the user you want to deactivate.**
{% endstep %}

{% step %}
**Select the User Actions dropdown and select Deactivate User.**
{% endstep %}

{% step %}
**Click Deactivate to confirm. The status should appear as Deactivated on the Users page.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Once a user is deactivated, their permissions, group assignments, and so on cannot be changed. If you need to edit a user’s data, they **must** be reactivated.
{% endhint %}

### Deactivate SCIM users

If your users are SCIM-managed, you can deactivate them by performing the appropriate actions in your Identity Provider (IdP). Once synced, the user’s status is switched to **Deactivated**.

{% hint style="danger" %}
You cannot reactivate SCIM-deactivated users via Command. You **must** reactivate them by performing the appropriate actions in your IdP.
{% endhint %}

***

## Reactivate a user

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Select the users email.**
{% endstep %}

{% step %}
**Select the User Actions dropdown and select Reactivate User.**
{% endstep %}

{% step %}
**Click Reactivate to confirm.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You can reactivate *deactivated* and *deleted* users.
{% endhint %}

***

## Delete a user

Deleting a user in Command removes all access, roles, and group memberships, but the user remains visible in the Deleted tab. Admins can choose to [restore](#h_4b768acc8c) the user later, which recovers their basic profile (name, email, photo) but not their previous roles, site access, or credentials.

If a new user is added with the same email or external ID as a deleted user, Command prompts the Admin to either [restore the existing user](#h_4b768acc8c) or [permanently delete](#h_886dbe6a06) them.

### Delete

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Select the user to delete.**
{% endstep %}

{% step %}
**Click the User Actions dropdown menu and select Delete User.**
{% endstep %}

{% step %}
**Select Delete to confirm.**
{% endstep %}

{% step %}
**(Optional) Bulk remove users: Next to each user’s name you want to remove, check the box and click Remove.**
{% endstep %}
{% endstepper %}

### Permanently Remove

Admins can hard delete users, which permanently removes them from the Deleted tab. This fully erases the user’s profile and identifiers from Command. Once hard deleted, the user’s email and external ID become available for reuse.

{% hint style="danger" %}
This action cannot be undone.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**At the top, select Deleted > your user.**
{% endstep %}

{% step %}
**Click next to the user’s name and select Permanently Remove User.**

a. Type "**REMOVE"** in the text box.\
b. Click **Permanently Remove.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}

* SCIM-managed users are permanently deleted when removed in the identity provider. Admins cannot manually re-add these users unless the original profile is fully purged. This prevents identifier conflicts and orphaned records.
* Deleting a user through the public users API performs a soft delete. The user’s data is moved to the Deleted users section.
  {% endhint %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=7ldbcKo8u0Q).
{% endhint %}


# Directories for User & Group Management

Learn how to segment management of users and user groups with Directories

Directories allow organizations to segment user and group management into scoped containers. Each directory can include a subset of an organization’s users or user groups (both Command user groups and access control user groups).

This structure allows organizations to delegate user management to regional or functional admins without granting organization-wide permissions. For example, an admin managing badge access for the San Francisco office can be limited to the "SF Directory."

***

## Directories in Command

Directories allow organizations to segment user and group management, providing control over permissions, visibility, and administrative scope. With Directories, you can:

* Restrict permissions to view, edit, or create users and groups to a specific directory.
* Allow Access Control admins to manage users, access groups, and credentials for a location without affecting other sites.
* Limit visibility and edit rights so directory-scoped admins can only act on users and groups within their assigned directory.
* Optionally hide all users and groups outside an admin’s assigned directory.

### Organize Directories

Organizations can move existing users and groups into a Directory or create new ones directly within a Directory. Users and groups are organized from Global, the organization-wide container, into individual Directories.

### Global

Global contains all users and groups by default. Only roles granted at the org-wide level provide administrative control over Global and all Directories. SCIM-synced users sync to Global, and Global-level groups can serve as sources for assignment across Directories.

### Directory

A Directory is a logical container for users and groups within an organization. It is typically used to represent locations, regions, campuses, business units, or tenants, enabling scoped administration.

Directories can:

* Contain a subset of users and groups (Command and access control groups).
* Exist only under Global (nesting is not supported).
* Be managed independently via directory-scoped roles.
* Automatically populate with users and groups via SCIM sync or existing Command/Access Control groups.
* Automatically update when users are added or removed from synced or source groups.
* Optionally restrict visibility so admins scoped to a Directory only see users and groups within their directory.

***

## Manage Directories

### Users

* Users can be members of one or more directories.
* Users created in or added to a directory will still be contained within Global.
* SCIM-synced users are always placed in Global by default.

### Groups

Like users, groups (both Command groups and Access control groups) can be placed in Directories.

* Each group can exist in only one Directory.
* A group can contain only users who belong to the same Directory.
* Groups are scoped to their Directory and cannot be referenced in other Directories.
* Groups can be automatically populated using SCIM-synced groups or existing Command/Access Control groups as sources of assignment, ensuring membership stays updated without manual changes.

***

## Roles and permissions

User management permissions in Verkada are granted through Command roles and Access User Management roles.

By default, these roles provide permissions over all users, Command groups, and access groups across the organization. With Directories, these roles can optionally be scoped to a specific Directory.

The organization-wide version of these roles remains available. Assigning a user an organization-wide role grants permissions over all users and groups in Global and across all Directories.

Users assigned one of these roles before Directories were enabled will automatically retain the organization-wide version of the role.

### Directory-specific roles & permissions

<table><thead><tr><th width="162.81640625">Role</th><th width="168">Scope</th><th width="420.90234375">Key User Management Permissions</th></tr></thead><tbody><tr><td><strong>Org Admin</strong></td><td>Organization-wide</td><td>Create and delete Directories. Manage all users and Command groups, including deactivating users, deleting users, and permanently removing users.</td></tr><tr><td><strong>Command User Admin</strong></td><td>Organization-wide</td><td>Create and edit users and Command groups across Global and all Directories. Deactivate users, delete users, and remove users from Directories. Cannot permanently remove users.</td></tr><tr><td><strong>Command User Viewer</strong></td><td>Organization-wide</td><td>View users and groups.</td></tr><tr><td><strong>Access User Admin</strong></td><td>Organization-wide</td><td>Create, edit, and delete users and Command groups in Global and across all Directories.</td></tr><tr><td><strong>Access User Manager</strong></td><td>Organization-wide</td><td>Edit users and access group memberships in Global and across all Directories.</td></tr><tr><td><strong>Access Credential Manager</strong></td><td>Organization-wide</td><td>Edit and delete user credentials (cards, PINs, mobile unlocks) in Global and across all Directories.</td></tr><tr><td><strong>Command User Admin</strong></td><td>Directory</td><td><p>Create and edit users and Command groups within the Directory. Remove users from the Directory (users revert to Global) or deactivate users.</p><p>Cannot delete or permanently remove users.</p></td></tr><tr><td><strong>Command User Viewer*</strong></td><td>Directory</td><td>View users and groups within the relevant Directory.</td></tr><tr><td><strong>Access User Admin</strong></td><td>Directory</td><td>Create and edit users and access groups within the Directory. Remove users from the Directory (users revert to Global).<br><br>Cannot de-activate, delete or permanently remove users.</td></tr><tr><td><strong>Access User Manager</strong></td><td>Directory</td><td>Create users and credentials. Manage group membership within the Directory.</td></tr><tr><td><strong>Access Credential Manager</strong></td><td>Directory</td><td>Create and edit user credentials within the Directory.</td></tr></tbody></table>

With directory-scoped roles, admins can only view and manage users, groups, and credentials within their assigned directory. Access and visibility outside the directory are fully restricted.

{% hint style="warning" %}
**\*** The Command User Viewer role for directories is only available to assign to users if Limit User Visibility is enabled.
{% endhint %}

***

## Configuration

### Enable Directories

All directory functionality is disabled by default. Directories can be enabled from Feature Manager. Once enabled, Directories can be created and managed from the **Admin >** **User Management** page in Command.

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Feature Manager.**
{% endstep %}

{% step %}
**Under Command, select Enable next to Directories.**
{% endstep %}
{% endstepper %}

After enabling Directories:

* All existing users, groups, and role assignments remain visible in the Global view.
* You can create directories to manage users and groups within scoped areas.
* To fully hide out-of-scope users and groups for directory-scoped admins, enable **Limited User Visibility for Site Roles** in Feature Manager.

{% hint style="danger" %}
You will not be able to enable Directories if your organization has users assigned any legacy Access Control roles. See [Legacy Access Control Roles](/access-control/users-and-credentials/add-and-modify-access-groups/legacy-access-control-roles) for more information.
{% endhint %}

### Create a Directory

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Users Management.**
{% endstep %}

{% step %}
**In the top left, click Global.**

a. Next to **Directories,** click on <i class="fa-plus">:plus:</i>.\
b. Select **New Directory**.\
c. Enter a globally unique name.\
d. Hit enter on your keyboard to save.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Auto-creating a Directory from a site will only copy the site’s name during Directory creation. Directory and site names will not be kept in sync after creation.
{% endhint %}

After creating directories:

* Move existing users and groups from Global into the desired directories.
* Create new users or groups directly within a directory.
* Automatically populate directories using SCIM-synced groups or existing Command/Access Control groups as sources of assignment.
* When **Limited User Visibility for Site Roles** is enabled in Feature Manager, directory-scoped admins can only see users and groups within their assigned directory.

### Add users to a Directory

### Existing user

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Select one or more users and click Add to Directory.**

a. Select the needed Directories.\
b. Click **Done.**
{% endstep %}
{% endstepper %}

### New user

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**In the top right, click Add User.**

a. Follow the on-screen instructions to create a new user.\
b. On **Directories**:

1. Select the needed Directories.
2. Click **Done.**

e. Continue with the step-up steps.\
f. Click **Create New User.**
{% endstep %}
{% endstepper %}

### Add groups to a Directory

### Existing groups

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Groups** or select Users & Permissions and click on Groups.
{% endstep %}

{% step %}
**Select one or more groups and click Add To Directory > Move to Directory.**
{% endstep %}

{% step %}
**Select a single Directory and click Done.**
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
When you move a group into a directory, all its users are added to that directory if they aren’t already members. Removing the group later does not remove its users from the directory.
{% endhint %}

### New groups

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Groups** or select Users & Permissions and click on Groups.
{% endstep %}

{% step %}
**In the top right, click Create.**
{% endstep %}

{% step %}
**Select Command Group or Access Group.**

a. Follow the on-screen instructions to create a new group.\
b. On **Directory Location**, select a specific Directory.\
c. Continue with the step-up steps.\
d. Click **Create Group.**
{% endstep %}
{% endstepper %}

### Grant Directory-scoped roles to a user or group

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Groups** or select Users & Permissions and click on Groups.
{% endstep %}

{% step %}
**Select the user or group to grant directory-scoped roles to.**
{% endstep %}

{% step %}
**Under User Management Role, click Manage.**
{% endstep %}

{% step %}
**Locate the desired directory and select the relevant access user role.**
{% endstep %}
{% endstepper %}

***

## Sync users to a Directory

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Users & Permissions > Directories.**
{% endstep %}

{% step %}
**In the top left, select Groups.**
{% endstep %}

{% step %}
**Select the checkbox next to the group(s) from the list to use as a source of assignment for a Directory.**
{% endstep %}

{% step %}
**In the top right, click Add To Directory > Sync to Directory.**

a. Select the Directory where you want to sync users from this group.\
b. Click **Confirm.**\
c. Alternatively, you can go to an individual group’s page and choose to sync its members to a Directory.
{% endstep %}
{% endstepper %}

{% hint style="danger" %}

* SCIM groups cannot be added to a directory like locally managed Command or Access groups. They can only sync their members to a directory.
* A group can either be added to a directory or set to sync its members. It cannot do both.
  {% endhint %}

***

## Limit User Visibility

When Directories are enabled, Org Admins can activate the **Limit User Visibility** setting in Feature Manager. This setting restricts which users and groups are visible in both Command and access control based on the user’s assigned role.

With Limit User Visibility enabled, users with the following roles see only users and groups associated with their assigned sites:

* Site Admin
* Site Viewer
* Access System Manager
* Access Site Admin
* Access Site Manager
* Access Site Viewer
* Workplace Site Admin

This ensures that site-level and system managers cannot view users outside their assigned locations, improving privacy and maintaining proper access boundaries.


# Manage Temporary Users

Learn how to limit user access to a Command organization

The **Temporary Users** feature is a category of users that can be granted all regular [Verkada Command roles](/command/users-and-permissions/roles-and-permissions-for-command) (although they cannot perform a [few restricted actions](#h_47f7046263)), for a predetermined period. At the end of this period, the user’s Command access is automatically revoked (via deactivation).

This feature is intended to enable third parties, such as installers, contractors, and so on to perform necessary tasks without the need for unlimited access to a customer’s Command organization.

{% hint style="danger" %}
Only users with the ability to add new users can add temporary users. This can be Org Admins and Site Admins, depending on how custom roles are configured in your organization. Learn more about [Roles and Permissions for Command](/command/users-and-permissions/roles-and-permissions-for-command).
{% endhint %}

***

## Add a temporary user

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**At the top right, select Add User.**
{% endstep %}

{% step %}
**On Add User:**

1. Enter the user’s first name, last name, email address, and phone number
2. (Optional) [Assign Command Roles and Command Groups to the user](/command/users-and-permissions/manage-users-in-your-organization)
3. Toggle on **Temporary User**.
4. Click the **Allow access until** dropdown and set the date for when the temporary user’s access to your organization should be revoked.
5. Review and click **Create New User** to invite the temporary user to your organization.

<div align="left" data-with-frame="true"><figure><img src="/files/Ib5vSV1BeynpGoqqPvRN" alt="" width="433"><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

***

## Modify a temporary user

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Next to the user’s name, click and select Temporary User Settings.**
{% endstep %}

{% step %}
**Adjust the time period for the temporary user who has access to your organization.**
{% endstep %}

{% step %}
**(Optional) You can promote the temporary user to having full access to the organization.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
When you upgrade a temporary user to full user, the user becomes a permanent user and is granted permission to perform any previously restricted actions.
{% endhint %}

***

## Reactivate a temporary user

In addition to the automatic deactivation that takes place upon reaching the end of a temporary user’s access period, you can also manually deactivate temporary users. The steps to do so are similar to how you [deactivate full access for users](/command/users-and-permissions/manage-users-in-your-organization).

To reactivate a deactivated temporary user:

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Next to the user’s name, click and select Reactivate User.**
{% endstep %}

{% step %}
**Specify the time period for which you’d like the user to be able to access your organization.**
{% endstep %}

{% step %}
**(Optional) Click Upgrade to Full User to reactivate the user as a full user.**
{% endstep %}

{% step %}
**Click Save to apply your changes.**
{% endstep %}
{% endstepper %}

***

## Convert a full user to a temporary user

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Go to User Management > Users** or select Users & Permissions and click on Users.
{% endstep %}

{% step %}
**Go to the user profile of the user you want and next to the user’s name, click and select Make Temporary User.**
{% endstep %}

{% step %}
**Specify the time period for which you’d like the user to be able to access your org.**
{% endstep %}

{% step %}
**Click Save to apply your changes and convert the user to a temporary user.**
{% endstep %}
{% endstepper %}

***

## Restrictions on temporary users

You can assign any of the roles within Command to temporary users, regardless of the role assigned to them. However, there are a set of actions that they **cannot** perform:

* Export/download any information from Command, including but not limited to camera footage, audit logs, user info, device info, and so on.
* Accept any terms and conditions for the organization on behalf of the organization; for example, analytics terms and conditions.
* Delete users (although they can deactivate users as permitted by their role).
* Convert temporary users to full users, including themselves.


# Manage Command Groups

Use groups to control user’s access to sites and subsites

Organization Admins can create groups to easily manage large numbers of users who should receive the same permissions on Command. You can create a group and grant it permissions that will apply to all group members. When you delete a group, the users no longer have access to the sites and subsites from that group.

***

## Create a group and assign roles

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select** **Users & Permissions** > **Groups.**
{% endstep %}

{% step %}
**At the top right, click Create > Command Group.**

1. Enter a unique name.
2. (Optional) Set a **Directory Location** (default Global) or **Sync Members to Directory**, then click **Done.**
3. (Optional) On **Members,** select the members to add, then click **Done.**
4. Click **Create Group.**
   {% endstep %}

{% step %}
**Back on the group page, at the top, click Roles.**
{% endstep %}

{% step %}
**Click Manage to the right of Organization Roles, User Management Roles, or Site Roles.**

1. For site roles, select the relevant product.
2. Select the role to grant to the group.
3. Click **Save**.

See [Roles and Permissions](/command/users-and-permissions/roles-and-permissions-for-command) for more information.
{% endstep %}
{% endstepper %}

***

## Set permissions for existing groups

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select** **Users & Permissions** > **Groups.**
{% endstep %}

{% step %}
**Select a Command group to grant permissions.**
{% endstep %}

{% step %}
**At the top, click Roles.**
{% endstep %}

{% step %}
**Click Manage to the right of Organization Roles, User Management Roles, or Site Roles.**

1. For site roles, select the relevant product.
2. De-select the role to remove from the group.
3. Click **Save**.

See [Roles and Permissions](/command/users-and-permissions/roles-and-permissions-for-command) for more information.
{% endstep %}
{% endstepper %}

***

## Add users to a group

You can add users to a group from the [Users page](#h_44e5401b70) or the [Groups page](#h_2cc1a3d362).

### Users page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select** **Users & Permissions** > **Users.**
{% endstep %}

{% step %}
**Select the user profile you want to edit.**
{% endstep %}

{% step %}
**At the top, select Groups.**
{% endstep %}

{% step %}
**On the right, click Manage Groups.**

a. Select the group(s) to add/remove the user to.

b. Click **Done**.
{% endstep %}
{% endstepper %}

### Groups page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select** **Users & Permissions** > **Groups.**
{% endstep %}

{% step %}
**Click on the group you want to edit.**
{% endstep %}

{% step %}
**To remove current group members, select members from the table and click the Delete button.**
{% endstep %}

{% step %}
**To add users to the group, click the Add Members button near the top right.**

a. Select the users(s) to add to the group.

b. Click **Done**.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Users can be members of multiple groups and will default to the **highest** level of permission set for them.
{% endhint %}

***

## Delete a group

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select** **Users & Permissions** > **Groups.**

1. Click on the group you would like to delete.
2. In the top left, click <i class="fa-ellipsis">:ellipsis:</i> **> Delete Group.**
3. Click **Delete** to confirm.
   {% endstep %}

{% step %}
**(Optional) To bulk delete groups:**

1. Click the checkbox next to each group you need to delete.
2. At the top right, click **Delete**.
3. Click **Delete** to confirm.
   {% endstep %}
   {% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=7ldbcKo8u0Q).
{% endhint %}


# Roles and Permissions

Set roles and permissions for Command users

This article describes the set of roles and associated permissions for Verkada Command.

{% hint style="info" %}
As of April 16, 2026, Command organizes roles by scope first (organization, user management, site) and then by product area within each scope. This replaces the previous model that grouped roles primarily by product. See roles and permissions in each product area for more information.
{% endhint %}

### Roles and permissions by Verkada product

All users added to the organization can log in to Command, but need additional permissions to view all the products. Select a product from the list below for more information on its roles and permissions.

* [Roles and Permissions for Access Control](/access-control/getting-started/roles-and-permissions-for-access-control)
* [Roles and Permissions for Air Quality Sensors](/air-quality/getting-started/roles-and-permissions-for-air-quality-sensors)
* [Roles and Permissions for Alarms](/new-alarms/getting-started/roles-and-permissions-for-new-alarms)
* [Roles and Permissions for Classic Alarms](/classic-alarms/getting-started/roles-and-permissions-for-classic-alarms)
* [Roles and Permissions for Cameras](/verkada-cameras/getting-started/roles-and-permissions-for-cameras)
* [Roles and Permissions for Intercom](/intercom/getting-started/roles-and-permissions-for-intercom)
* [Roles and Permissions for Gateway](/connectivity/getting-started/roles-and-permissions-for-gateway)
* [Roles and Permissions for Guest](/guest/getting-started/roles-and-permissions-for-guest)
* [Roles and Permissions for Mailroom](/mailroom/getting-started/roles-and-permissions-for-mailroom)

***

## Organization-level roles

Organization roles apply across the entire Command organization and are not tied to a specific site. They control broad platform access, such as organization-wide settings, Access Control at the organization level, alerts, operations, and similar areas.

<details>

<summary>Organization Admin</summary>

Any organization member can be upgraded to an Organization Admin.

Access allows you to:

* View the organization when logged in.
* Configure personal notifications (which alerts the user wants to receive).
* Set personal and org-wide 2FA settings.
* Create floor plans.
* Add, delete, and modify access users.
* Set user and group permissions for the organization and all sites/subsites.
* Configure org-wide settings, including maximum archive duration, enable/disable cloud backup globally, and default camera playback quality.
* Rename or delete the org.
* Create new sites and subsites.
* Add and remove devices.
* Adjust camera stream encoding settings.

{% hint style="warning" %}
If the [Global Site Admin](/command/users-and-permissions/roles-and-permissions-for-command/customize-roles-and-permissions) policy is enabled, all Org Admins will automatically be granted Site Admin access to all sites.
{% endhint %}

</details>

<details>

<summary>Organization member</summary>

All users added to an organization are organization members. A user added to the organization who does not have admin permissions has the minimum level of access needed to sign in to the organization.

Access allows you to:

* View the organization when logged in.
* Configure personal notifications (which alerts the user wants to receive).
* Set personal 2-Factor Authentication (2FA) settings.

</details>

## User management roles

User management roles control who can manage people and identity in Command, such as creating or editing users and groups and assigning admin-level roles, often scoped to directories or the full organization. They are separate from organization roles to distinguish who can manage devices (for example, cameras) from who can manage users.

<details>

<summary>Command User Admin</summary>

{% hint style="warning" %}
Command User Admins cannot modify the Organization Admin role. They can assign or remove Command User Admins but cannot elevate or lower Organization Admin permissions.
{% endhint %}

Any organization member can be upgraded to a Command User Admin.

Command User Admin allows you to:

* Add and remove users, designate their roles, and assign them to groups.
* Add and remove groups and assign users to groups.
* Add and remove contacts for individuals outside of your organization.
* Create and assign alerts to groups and users in the organization.
* Manage and restrict access to Shared Links for users in the organization.
* Enable Support Access.

</details>

<details>

<summary>Command User Viewer</summary>

Command User Viewer allows you to:

* View users, their roles, and their groups.
* View groups, their roles, and their users.

</details>

## Site roles

Site-level roles can be assigned to individual users or groups and apply only to a specific site. Subsites inherit permissions from parent sites above them in the hierarchy.

#### Command site roles overview

Command site roles include permissions across product suites, such as Cameras, Alarms, Sensors, Intercoms, and Gateways.

<details>

<summary>Site Admin</summary>

**Cameras**

Site Admins can access live and recorded footage for cameras within the sites for which they have permissions. They can also configure site permissions and camera settings.

Site Admins can:

* Add, remove, and manage user permissions on a site for existing users
* Add cameras to the organization and to any site where they are a Site Admin
* Delete cameras from the organization only from sites where they are a Site Admin
* Create, rename, and delete sites and subsites
* View live streams
* Share live links (SMS and link)
* View historical video
* Archive video and download as an MP4
* View non-private archives.

{% hint style="danger" %}
You need Org Admin permissions to view private archives.
{% endhint %}

* Perform motion searches
* Take live feed snapshots
* Configure camera settings
* Utilize auto and manual focus
* Utilize optical and digital zoom
* Create camera embeds
* View camera stats
* Has full access to controls and features, including Sentry Mode for PTZ cameras

**Alarms**

* Can create or edit an alarm site
* Can create and edit keycodes along with all other alarm configurations
* Can arm or disarm alarm sites or resolve an alarm via Command
* Can add or remove Verkada devices and wired inputs/outputs on the site
* Can view all alarm activity and event history with historical video
* If added as a **response contact** for the alarm site, they can resolve an alarm and disarm the site through the incident link and agent call

**Air Quality Sensors**

* Add or remove sensors, move them between sites you administer, and reboot hardware
* Turn triggers on or off, edit trigger settings and sensitivity, receive offline alerts for sensors on accessible sites, and link a context camera (requires Site Admin permissions for the camera's site)
* Download sensor readings as a CSV and, for supported SV25 units with the feature enabled, use live and recorded audio
* Pair dashboards with displays, share or delete dashboards, create tiles using sensor readings and time ranges, and remove tiles as needed
* View sensor readings across accessible sites, filter and sort readings by type and time range, and switch between sites

**Gateway**

* Open gateway details, run a speed test, and see connected devices
* Review power history, activity logs, and data graphs
* Set up alerts
* Claim, set up, manage, identify, reboot, and delete devices on the site
* Manage data licenses
* Open the gateway home page
* Run packet capture, power cycle ports, and switch a gateway to WAN mode
* Claim connected devices, change network settings, and toggle smart data usage

**Intercom**

* Receive calls with video
* See 24/7 live intercom video, even if not on an active call
* View historical video and events
* Unlock the door both during and outside of a call
* Unlock the door 24/7
* Talk down to the intercom
* Change Receivers and device settings

</details>

<details>

<summary>Site Viewer</summary>

**Cameras**

A Site Viewer can access live and recorded footage for cameras in the site.

Site Viewers can:

* View live streams
* Utilize digital zoom
* View historical video
* Perform motion searches
* View camera settings
* View camera stats
* Take live feed snapshots
* Archive and download video (non-private archives only)
* For PTZ cameras, a Site Viewer has full access to controls but limited access to features and settings
  * Can view existing settings
  * Cannot enable, disable, or edit Sentry Mode settings

**Alarms**

* If added as a **response contact** for the alarm site, they can resolve an alarm and disarm the site through the incident link and agent call

**Air Quality Sensors**

* View the sensors in the site
* View analytics values for the sensors in the site
* Toggle between different durations (live, today, this week, etc.)
* View dashboards

**Gateway**

* Open gateway details, run a speed test, and see connected devices
* Review power history, activity logs, and data graphs
* Set up alerts

**Intercom**

* Receive calls with video
* See 24/7 live intercom video, even if not on an active call
* View historical video and events

</details>

<details>

<summary>Live-Only Viewer</summary>

**Cameras**

Live-Only Viewers can **only** view live streams (no access to historical video) of the cameras in the site.

Live-Only Viewers can:

* View individual camera live streams
* Utilize digital zoom
* Create and view grids
* View floor plans
* Has no access to controls or Sentry Mode for PTZ cameras

**Alarms**

* If added as a **response contact** for the alarm site, they can resolve an alarm and disarm the site through the incident link and agent call

**Intercom**

* Receive calls with video
* See 24/7 live intercom video, even if not on an active call

</details>

{% hint style="warning" %}
See [Roles and permissions by Verkada product](#roles-and-permissions-by-verkada-product) for detailed site role and permissions information for specific products accessible from Command.
{% endhint %}

***

## Set permissions

<details>

<summary>Users</summary>

#### Grant permissions

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Users.**
3. Select a user to grant permissions.
4. Click **Manage** to the right of Organization Roles, User Management Roles, Site Roles, or Custom Roles.
   1. For site roles, select the relevant type (product-specific role or custom role).
   2. Select the role to grant to the user.
   3. Click **Save**.

#### Revoke permissions

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Users.**
3. Select a user to revoke permissions.
4. Click **Manage** to the right of Organization Roles, User Management Roles, Site Roles, or Custom Roles.
   1. For site roles, select the relevant product.
   2. De-select the role to remove from the user.
   3. Click **Save**.

</details>

<details>

<summary>Groups</summary>

#### **Granting permissions**

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Groups.**
3. Select a Command group to grant permissions.
4. At the top, click **Roles.**
5. Click **Manage** to the right of Organization Roles, User Management Roles, Site Roles, or Custom Roles.
   1. For site roles, select the relevant product.
   2. Select the role to grant to the group.
   3. Click **Save**.

#### **Revoking permissions**

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Groups.**
3. Select a Command group to revoke permissions.
4. At the top, click **Roles.**
5. Click **Manage** to the right of Organization Roles, User Management Roles, Site Roles, or Custom Roles.
   1. For site roles, select the relevant type (product-specific role or custom role).
   2. De-select the role to remove from the group.
   3. Click **Save**.

</details>

***

## FAQ

<details>

<summary>Why has my organization disappeared?</summary>

A user must be a member at the organization level to see the organization in the dropdown when they log in. If a user is a member of an organization, they appear on the user list that Organization Admins and Site Admins can access in Command.

If your organization disappeared, it can be due to one of these reasons:

* Your user account was removed from the organization.
* The organization was deleted.

**Troubleshoot**

* If you are the affected user, contact the Organization Admin and request to re-add you to the organization.
* If a user has reported this to you, verify they are a member of the organization.

</details>

<details>

<summary>Why are cameras missing from my organization?</summary>

Sites do not inherit users from the organization or other sites. Users who are members of the organization cannot see cameras unless they have explicitly been granted permissions to the site or sub-site where the cameras reside.

* If you are the affected user, contact the Organization Admin or Site Admin and request access to the desired sites and subsites.
* If a user has reported this to you, grant them access to the desired sites and subsites.

</details>

<details>

<summary>Why can’t I access certain features or settings, such as other users?</summary>

If you are unable to access certain features or settings, you don’t have sufficient permissions. Only Admins can access all features and settings.

Organization Admins are not automatically escalated to Site Admin for any site. This is a separate feature set. Therefore, Organization Admins do not inherently have permission to view any one particular site, but they can assign themselves the required roles to see their desired sites.

**Troubleshoot tips:**

* If you are the affected user, contact the Organization Admin or Site Admin and request that they elevate your permissions to Organization Admin or the desired site or subsite.
* If a user has reported this to you, elevate their permissions on the organization or desired site or subsite.

</details>

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=7ldbcKo8u0Q).
{% endhint %}


# Custom Roles

Learn how to create, configure, and assign custom roles in Verkada Command

{% hint style="success" %}
Custom Roles replaces the legacy Customize Roles feature under **Admin > Users & Permissions**, now renamed to [Modify Default Roles](/command/users-and-permissions/roles-and-permissions-for-command/customize-roles-and-permissions). If your organization previously used Customize Roles to toggle permissions on standard roles, those settings remain unchanged. New role customization should use the Roles page described in this article.
{% endhint %}

Custom Roles lets Organization Admins build roles from the ground up, selecting exactly the permissions a user or group needs and nothing more. This is designed to help organizations apply the principle of least privilege across teams, locations, and job functions.

{% hint style="danger" %}
Custom Roles currently only support Cameras and Workplace permissions.
{% endhint %}

***

## Create a Custom Role

{% hint style="success" %}
As of May 14, 2026, Custom Roles can only be site-scoped.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Admin > Users & Permissions, click Roles.**
{% endstep %}

{% step %}
**In the right, click Create.**
{% endstep %}

{% step %}
**Enter a unique name for the role.**
{% endstep %}

{% step %}
**(Optional) Select a common template to copy permissions from.**
{% endstep %}

{% step %}
**Review the list of available permissions and toggle each one on or off based on what this role requires.**
{% endstep %}

{% step %}
**In the top right, click Save.**
{% endstep %}
{% endstepper %}

***

## Edit a Custom Role

You can edit an existing custom role at any time from Admin > Users & Permissions > Roles. Changes apply immediately to all users and groups assigned that role.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Admin > Users & Permissions, click Roles.**
{% endstep %}

{% step %}
**Select the role to edit.**
{% endstep %}

{% step %}
**Next to the role name, click** <i class="fa-ellipsis">:ellipsis:</i> **> Edit Permissions.**

Review the list of available permissions and toggle each one on or off based on what this role requires.
{% endstep %}

{% step %}
**In the top right, click Save.**
{% endstep %}
{% endstepper %}

***

## Assign a Custom Role

When picking a role type, find custom roles under the **Custom** section.

<details>

<summary>Users</summary>

#### Grant permissions

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Users.**
3. Select a user to grant permissions.
4. Click **Manage** to the right of **Site Roles**
   1. From a list of role types, select **Custom.**
   2. Click **Save**.

#### Revoke permissions

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Users.**
3. Select a user to revoke permissions.
4. Click **Manage** to the right of **Site Roles**
   1. From a list of role types, select **Custom.**
   2. De-select the role to remove from the user.
   3. Click **Save**.

</details>

<details>

<summary>Groups</summary>

#### **Granting permissions**

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Groups.**
3. Select a Command group to grant permissions.
4. At the top, click **Roles.**
5. Click **Manage** to the right of **Site Roles**
   1. From a list of role types, select **Custom.**
   2. Click **Save**.

#### **Revoking permissions**

1. In Verkada Command, go to **All Products > Admin.**
2. Select **Users & Permissions** > **Groups.**
3. Select a Command group to revoke permissions.
4. At the top, click **Roles.**
5. Click **Manage** to the right of **Site Roles**
   1. From a list of role types, select **Custom.**
   2. De-select the role to remove from the group.
   3. Click **Save**.

</details>

***

## Supported permissions

Admins can toggle each permission below when creating a custom role to control what users can view and manage within a site.

{% tabs %}
{% tab title="Cameras" %}
**Site Configuration**

* View Site
* Manage Site
  * Add, remove, and manage user permissions on a site for existing users
  * Create, rename, and delete sites and subsites

**Camera Settings**

* View Camera Details
* Manage Camera Settings
  * Accept face search & biometric compliance setting
  * Manage cloud backup
  * Set privacy mode
  * Set camera read-only mode
  * Apply site device defaults Manage org camera presets
  * Manage device network and access
  * Configure encoding and bandwidth
* Add and Modify Cameras in Site.
  * Add cameras to the organization and the site(s) where they have this permission
  * Delete cameras only from the site(s) where they have this permission
* Set Onboard Video Retention

**Video & Sharing**

* View Live Camera Streams
* View Historical Footage
* Share Camera Live Links

**Analytics & Search**

* Use AI-powered Search
* View People Analytics
* Manage Occupancy Trends
* View Person of Interest Lists
* Manage Person of Interest Lists
* View License Plates of Interest
* View License Plate Analytics
* View Vehicle Analytics

**Archives**

* View Public Archives
* Create Public Archives
* Create Private Archives
* View All Private Archives
* Download Archives
* Delete Archives
* Share Archive Live Links
  {% endtab %}

{% tab title="Workplace" %}
**Site Configuration**

* View Guest Site
* Manage Guest Site

**Visitor Management**

* View Approved Lists
* Modify Approved Lists
* View Deny Lists
* Modify Deny Lists
* Override Denials
* View Guest Phone Numbers
* Manage Visitor Security Screening Results
* Manage Applicant Security Screening Results

**Incidents Response**

* View Responses
* Launch Responses
* End Responses
  {% endtab %}
  {% endtabs %}


# Modify Default Roles

Learn how to fine-tune the permissions on Verkada's standard roles

Verkada's standard site roles (Site Admin and Site Viewer) include a set of default permissions. Organization Admins can extend or restrict those defaults to match their organization's needs without creating a new role from scratch.

***

## Configuration

{% hint style="danger" %}
You need [Org Admin](/command/users-and-permissions/roles-and-permissions-for-command) permissions to customize roles and permissions.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Admin > Users & Permissions, toggle on Customize Roles.**

This may take a few minutes to update.

{% hint style="info" %}
Enabling this feature unlocks Custom Roles, which let you create new roles with fully customized permission sets. See [Custom Roles](/command/users-and-permissions/roles-and-permissions-for-command/custom-roles) for more information.
{% endhint %}
{% endstep %}

{% step %}
**After the feature has been enabled. You can navigate to** **Admin > Users & Permissions > Modify Default Roles.**
{% endstep %}

{% step %}
**Under Modify Default Roles:**

a. Click **Edit** next to a role and configure permissions as needed.\
b. Click **Save.**
{% endstep %}

{% step %}
**(Optional) Toggle on Global Site Admin to automatically grant Org Admins Site Admin permissions for all sites.**
{% endstep %}
{% endstepper %}


# Authentication Overview

View options for user authentication and provisioning

Secure your Verkada Command organization with multiple authentication options. Choose the method that best fits your security requirements.

***

## Choose your authentication method

| Method                                                                                           | Best for                                          | Security level |
| ------------------------------------------------------------------------------------------------ | ------------------------------------------------- | -------------- |
| [Two-Factor Authentication](/command/security/authentication-overview/two-factor-authentication) | Quick security boost for password-based login     | Medium         |
| [Passkeys](/command/security/authentication-overview/passkeys-for-login)                         | Passwordless login using device biometrics        | High           |
| [Single Sign-On (SSO)](/command/security/identity-providers)                                     | Enterprise organizations using identity providers | High           |
| [Enterprise Controlled Encryption](/command/security/enterprise-controlled-encryption)           | Maximum security with customer-managed keys       | Maximum        |

{% hint style="info" %}
Verkada recommends enabling SSO with OIDC for the best balance of security and user experience.
{% endhint %}

***

## Authentication methods

By default, users use their email and password to log in. To enhance security, several additional login options are available.

### OpenID Connect (OIDC)

OIDC is an authentication protocol built on OAuth 2.0 that enables secure user identity verification. It allows applications to authenticate users through a trusted identity provider (IdP) without storing credentials. OIDC enhances security by providing standardized identity tokens, enabling single sign-on (SSO) and seamless platform integration.

{% hint style="info" %}
Verkada recommends enabling OIDC instead of SAML when available.
{% endhint %}

### SAML/OAuth

SAML allows you to log in using a third-party authenticating service, such as Okta, Microsoft Entra ID, Google Workspace, or OneLogin. This method provides a single point of management for authentication across multiple applications.

Verkada Command is compatible with any SAML 2.0 provider. Learn more about setting up [identity providers](/command/security/identity-providers).

### 2-Factor Authentication

2-Factor Authentication (2FA) requires you to retrieve a code via SMS or through an authenticator app to log in. See [Two-Factor Authentication](/command/security/authentication-overview/two-factor-authentication) for detailed setup instructions.

***

## Provisioning

### SCIM

If you have a large number of users, you may opt to use System for Cross-Domain Identity Management (SCIM) to automatically provision and manage users. This is particularly advantageous if your company uses [Microsoft Entra ID](/command/security/identity-providers/microsoft-entra-id) or [Okta](/command/security/identity-providers/okta) as your Identity Provider.

SCIM allows you to sync users and groups between Verkada Command and your IdP, where you can easily add, remove, or modify multiple users and groups simultaneously.

See the [Identity Providers](/command/security/identity-providers) section for detailed SCIM setup instructions.

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=VXlMhHfLwoI).
{% endhint %}


# Two-Factor Authentication

Learn more about Verkada's built-in option for 2-Factor Authentication (2FA)

Enabling two-factor authentication (2FA) adds an extra layer of security to your account, significantly reducing the risk of unauthorized access by requiring a secondary verification method beyond just a password.

{% hint style="danger" %}
Org Admins are required to enable 2FA when setting up their accounts. However, if you log in with SSO, 2FA will be handled by your identity provider.
{% endhint %}

***

## Enable 2FA on your Command account

{% hint style="info" %}
We recommend enabling 2FA with a passkey for the strongest protection.
{% endhint %}

{% stepper %}
{% step %}
**In the bottom left of Verkada Command, click the org icon.**
{% endstep %}

{% step %}
**Click My Account.**
{% endstep %}

{% step %}
**Next to Two-Factor Authentication, click Add.**
{% endstep %}

{% step %}
**Select the type of authentication you want to set up:**

a. [Passkey or biometric authenticator](#passkey-or-biometric-authenticator)\
b. [Authenticator App](#authenticator-app)\
c. [SMS](#sms)
{% endstep %}

{% step %}
**Enter your password and click Continue.**
{% endstep %}

{% step %}
**Follow the prompts to complete the setup.**
{% endstep %}
{% endstepper %}

### Passkey or biometric authenticator

With 2FA via security key or biometric authenticator, you can set up device-specific verification methods like TouchID and FaceID, as well as external security keys like YubiKey or phone as a passkey.

{% hint style="warning" %}

* You can set up multiple passkeys/biometric authenticators for the same account using different devices.
* Passkeys and biometric authenticators are not supported by the Verkada Command mobile app.
  {% endhint %}

### Authenticator app

With 2FA by an authenticator app, you will see a 6-digit code automatically generated. This code expires every 30 seconds, so check the app for a new code each time you log in.

{% hint style="warning" %}
For help adding a QR code, contact the app's vendor for troubleshooting steps.
{% endhint %}

### SMS

With 2FA via SMS, you will receive a 6-digit code in a text message. This phone number can be different from the number verified on your profile.

***

## Enforce organization-wide 2FA

{% hint style="danger" %}
2FA is required for all Org Admins in Command. Org Admins will be prompted to set it up at their next login if not already configured. This requirement cannot be bypassed. However, if you log in with SSO, 2FA is handled by your identity provider.
{% endhint %}

Org Admins can enforce 2FA for all users in the organization. When enforced, users will be required to have a minimum of 1 authentication method set up.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access.**
{% endstep %}

{% step %}
**Select Two-factor Authentication > Enforce Two-Factor Authentication.**
{% endstep %}

{% step %}
**Click Confirm to save the changes.**
{% endstep %}
{% endstepper %}

Once 2FA is enforced at the organization level:

* **Existing users** will be required to set up 2FA at the next login.
* **New users** will be required to set up 2FA while setting up their account.

***

## Reset a user's 2FA

If you lose or misplace your authentication device and are locked out, contact your Org Admin to have 2FA reset.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Admin > Users & Permissions, click Users.**
{% endstep %}

{% step %}
**Select the email of the locked-out user.**
{% endstep %}

{% step %}
**At the top left, click** <i class="fa-ellipsis">:ellipsis:</i>**> Control Login.**
{% endstep %}

{% step %}
**Under** **Reset Two-Factor Authentication Configuration:**

1. Click **Reset 2FA.**
2. Click **Confirm** to delete all 2FA methods.
   {% endstep %}

{% step %}
**Click Done to confirm.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
If 2FA is enforced for the organization, the user will be required to set up a new 2FA configuration at the next login. If not, 2FA will be disabled on the user account.
{% endhint %}

***

## Disable 2FA

{% hint style="warning" %}
If 2FA is enforced for the org, Org Admins cannot disable 2FA for themselves or other Org Admins.
{% endhint %}

{% stepper %}
{% step %}
**In the bottom left of Verkada Command, click the org icon.**
{% endstep %}

{% step %}
**Click My Account.**
{% endstep %}

{% step %}
**Click next to the authentication method you want to disable.**
{% endstep %}

{% step %}
**Enter your password and click Continue.**
{% endstep %}
{% endstepper %}

If you no longer have access to the 2FA app and are not signed in, contact your Org Admin to reset 2FA for your account.

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=vme3YdOdhsE).
{% endhint %}


# Passkeys for Login

Learn how to ensure a secure and seamless login experience

Log in to your Verkada Command organizations with passkeys for the most secure and seamless login experience. Learn more about the [industry's move towards passkeys](https://fidoalliance.org/passkeys/).

{% hint style="danger" %}
This feature is not available in organizations where SSO is required to log in.
{% endhint %}

***

## Set up your passkey

{% stepper %}
{% step %}
**Navigate to your account's security settings: At the bottom left, click Profile and find My Account.**
{% endstep %}

{% step %}
**Under Passkeys, click Add a Passkey.**
{% endstep %}

{% step %}
**For security purposes, you may be prompted to re-enter your password or verify through an email link.**
{% endstep %}

{% step %}
**When prompted to Set up Passkey, follow the prompts to set up any passkey supported by your device and/or external security key.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
For an external security key to be configured as a passkey, it must be FIDO2-compliant.
{% endhint %}

***

## Log in with your passkey

Once your passkey is configured, you can use it to log in to your Command organization.

{% hint style="warning" %}
If you have passkeys registered for multiple Command organizations, first select the passkey to log in with. Each passkey is stored with the email address and organization name it correlates to.
{% endhint %}

{% stepper %}
{% step %}
**From the main login page, under Log in with passkey, click Login.**
{% endstep %}

{% step %}
**You should see a browser or OS prompt to use your passkey.**
{% endstep %}

{% step %}
**Use the selected passkey to log in. Alternatively, enter your email and select your organization as usual, then use your passkey in place of your password.**
{% endstep %}
{% endstepper %}

***

## Delete your passkey

{% stepper %}
{% step %}
**Navigate to your account's security settings: At the bottom left, click Profile and find My Account.**
{% endstep %}

{% step %}
**Under Passkeys, go to the specific passkey to remove.**
{% endstep %}

{% step %}
**Next to the passkey, click Delete.**
{% endstep %}

{% step %}
**For security purposes, you may be prompted to re-enter your password or verify through an email link.**
{% endstep %}
{% endstepper %}

***

## Important notes

When you set up your passkey, it does not disable or affect any other login methods. Passkeys simply present another login option.

However, when you use a passkey to log in, it bypasses 2FA (if enabled), because passkeys already provide built-in multi-factor authentication.


# Passwordless Authentication

Overview of passwordless authentication methods for Verkada Command

In today's digital landscape, security is paramount. Passwordless authentication methods enhance security while maintaining user convenience.

***

## Benefits of passwordless authentication

* **Enhanced Security:** Reduces the risk of password-related attacks such as phishing, brute force, and credential stuffing.
* **Improved User Experience:** Eliminates the need to remember and manage multiple passwords.
* **Reduced IT Burden:** Lowers the number of password reset requests, freeing up IT resources.

***

## Recommended methods

### Single Sign-On (SSO) via SAML

SAML (Security Assertion Markup Language) is an open standard for exchanging authentication and authorization data between parties, particularly between an identity provider and a service provider.

**Benefits:**

* Centralized authentication process
* Streamlined user experience with one set of credentials

{% hint style="info" %}
See [Generic SAML Setup](https://github.com/verkada/Verkada-Support-Docs/blob/main/en/command/identity-providers/generic-saml-setup.md) for more information.
{% endhint %}

### Single Sign-On (SSO) via OIDC

OIDC (OpenID Connect) is an identity layer built on top of the OAuth 2.0 protocol. It allows clients to verify the identity of the end-user based on the authentication performed by an authorization server.

**Benefits:**

* Interoperability across different platforms
* Enhanced security features like token-based authentication

{% hint style="info" %}
See [Identity Providers](https://github.com/verkada/Verkada-Support-Docs/blob/main/en/command/identity-providers/generic-saml-setup.md) for OIDC setup guides.
{% endhint %}

### MFA

MFA is strongly recommended for all users using password-based authentication. We recommend using a passkey, security key, or a time-based one-time password (TOTP) app as your primary 2FA method. SMS as a 2FA option poses security risks and is not recommended.

{% hint style="info" %}
See [Two-Factor Authentication](/command/security/authentication-overview/two-factor-authentication) for more information.
{% endhint %}

***

## Password resets

For scenarios where passwordless options are not available, users may need to reset their passwords. Admins have the ability to reset passwords for users within their organization.

{% hint style="info" %}
See the [Verkada Command Account FAQ](/command/need-help/verkada-command-account-faq) for more information.
{% endhint %}


# Session Management

Learn how to configure and utilize the available session and security controls

Verkada's enhanced session management feature ensures an efficient and secure user experience.

***

## Maximum session duration

The **Maximum Session Duration** control manages the time period after which a user is logged out, regardless of activity history.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access > Session Management.**
{% endstep %}

{% step %}
**Locate and set the Maximum Session Duration:**

* Default: 60 days
* Min: 1 day
* Max: 180 days
  {% endstep %}
  {% endstepper %}

***

## Idle timeout

This control specifies the maximum period of inactivity after which a user is logged out. If a user has not used Command in over the specified time, they are logged out regardless of whether maximum session duration has been reached.

{% hint style="warning" %}
The **Idle Session Timeout** value can never be greater than the **Maximum Session Duration** value.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access > Session Management.**
{% endstep %}

{% step %}
**Locate and set the Idle Timeout:**

* Default: 7 days
* Min: 15 minutes
* Max: 30 days
* Government Command organizations default to 1 hour
  {% endstep %}
  {% endstepper %}

***

## Customize login lockouts

Control the number of unsuccessful login attempts and lockout behavior.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access > Session Management.**
{% endstep %}

{% step %}
**Set the Allowed Login Attempts** (unsuccessful attempts within 15 minutes before lockout):

* Default: 6 attempts
* Government Command organizations default to 3 attempts
  {% endstep %}

{% step %}
**Set the Lockout Period** (time until automatic unlock):

* Default: 15 minutes
* Government Command organizations default to 30 minutes
  {% endstep %}
  {% endstepper %}

***

## Limit concurrent user sessions

This control specifies the maximum number of active sessions a user can have at any given time.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access > Session Management.**
{% endstep %}

{% step %}
**Set the Maximum Sessions per User:**

* Default: Unlimited sessions
* Government Command organizations default to 2 sessions per user
  {% endstep %}
  {% endstepper %}

{% hint style="warning" %}
**Session** refers to a web/mobile instance of Command and extends to the Verkada Pass app (but not other native product-specific apps).

* Being logged in on 10 different tabs in the same browser = 1 unique session
* Being logged in on 2 different browsers = 2 separate sessions
* Being logged in on desktop, mobile browser, and mobile app = 3 separate sessions
  {% endhint %}

For the Pass app, if the active session maximum is reached, previously logged in users will be logged out and have their BLE credentials revoked until a new active login is established.


# Control User Login

Edit a user's login settings

**Control Login** allows Org Admins to change user login settings, such as resending the Command invite or resetting passwords.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Users & Permissions > Users.**
{% endstep %}

{% step %}
**Select a user profile.**
{% endstep %}

{% step %}
**In the top left, click** <i class="fa-ellipsis">:ellipsis:</i> **> Control Login.**

<div align="left" data-with-frame="true"><img src="/files/z6WW6IiB3LikZYbOH0yP" alt="" width="563"></div>
{% endstep %}

{% step %}
**Edit the user's login settings as needed.**
{% endstep %}

{% step %}
**Click Done when finished.**
{% endstep %}
{% endstepper %}


# Login Links

Easily switch between your Verkada Command organizations

Login links are an alternative to logging in to Verkada Command with the organization's short name and password for each organization you're a member of. With login links, you can log in to all of your password-only organizations at one time.

While logged in, you can switch between organizations without having to authenticate them each time.

{% hint style="danger" %}
For orgs that require Two-Factor Authentication (2FA) or Single Sign-On (SSO), you need to authenticate them before switching between them.
{% endhint %}

***

## Authenticate your organization

{% stepper %}
{% step %}
**Navigate to the** [**Verkada Command login page**](https://command.verkada.com/login)**.**

1. Enter your email.
2. Click **email my login link**.

<div align="left" data-with-frame="true"><img src="/files/TYgUDLOFs7PZhdjBSiis" alt=""></div>
{% endstep %}

{% step %}
**Check your inbox for an email that was automatically sent.**
{% endstep %}

{% step %}
**Select the link in the email, and you should be redirected to a list of your organizations.**
{% endstep %}

{% step %}
**Select the first organization you want to log in to.**

You are automatically logged in to all of your password-only organizations.
{% endstep %}
{% endstepper %}


# Switch Organizations

Learn how to switch between more than one organization in Verkada Command

When you are a part of multiple organizations, your user account is separate for each organization. This allows for more granular control of user accounts by Organization Admins, such as requiring 2-factor authentication.

***

## Specify an org's short name

An org's **short name** is a unique identifier used to specify which org you log in to.

{% hint style="warning" %}
If you are part of 2 or more orgs, when you log in to Verkada Command, you must specify the org's short name. Once logged in, if you have verified your email, you can switch between all organizations.
{% endhint %}

You can also use a [Login Link](/command/security/authentication-overview/login-links) to log in to all password-only orgs at once.

***

## Find your short name

### Via email

When you log in to Verkada Command, if you don't know the short name, click **Email me a list** to receive an email list with verification links for each org.

### While logged in

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under General > Organization, the short name is listed next to the Subdomain field.**
{% endstep %}
{% endstepper %}

***

## Switch between orgs

{% hint style="warning" %}
If you have created organizations in different regions, you will see separate lists for **United States**, **Europe**, and **Australia**.
{% endhint %}

{% stepper %}
{% step %}
**At the bottom left, select the organization icon to view all organizations where you have login access.**
{% endstep %}

{% step %}
**Select any organization listed to switch.**

<div align="left" data-with-frame="true"><img src="/files/RSZWrazykfPeUR7LjFtj" alt=""></div>
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
You are **required** to log in to other orgs when switching, unless you have authenticated recently within the org's session time limit.
{% endhint %}

***

## Unable to see all of your orgs

If not all orgs appear in the list, this can happen when your email is not verified in each org.

{% stepper %}
{% step %}
**At the bottom left, select the org name.**
{% endstep %}

{% step %}
**Check for a green checkmark next to your email. If you don't see it,** [**verify your email**](/command/security/authentication-overview/verify-your-verkada-command-account)**.**
{% endstep %}
{% endstepper %}


# Verify Your Account

Learn how to verify your Verkada Command account and the email for your account

To enhance the security of your Command account, Verkada requires that all Command users have verified email addresses. Verifying your email ensures you receive all notifications and emails related to your Verkada Command account, including configured alerts.

***

## Verify your email

{% hint style="danger" %}
You must verify your email to receive any configured alerts in your org.
{% endhint %}

{% stepper %}
{% step %}
**Log in to your Verkada Command account.**
{% endstep %}

{% step %}
**At the bottom left, select your organization name.**

* If you see a **green checkmark** by your email, your email is verified.
* If not verified, click **Verify Email**.

<div align="left" data-with-frame="true"><img src="/files/6Cry4q59ayo2nXtZBfbH" alt=""></div>

This sends a verification email from <no-reply@command.verkada.com>. Check your spam folder if you don't see it.

<div align="left" data-with-frame="true"><img src="/files/OpH6I8ehBeqHqJ9xtUmw" alt="" width="1247"></div>
{% endstep %}

{% step %}
**Select Account Settings and your email should show as verified.**
{% endstep %}

{% step %}
**Click Continue to complete the verification process.**
{% endstep %}
{% endstepper %}

***

## Verify your phone number

{% hint style="danger" %}
Verifying your phone number is required to receive SMS notifications related to your Command account.
{% endhint %}

{% hint style="warning" %}
You can only edit and verify your own phone number. If you are a SCIM-managed user, your phone number is automatically verified.
{% endhint %}

{% stepper %}
{% step %}
**Log in to your Command account.**
{% endstep %}

{% step %}
**At the bottom left, select your organization name.**
{% endstep %}

{% step %}
**On the left slide out, click My Account.**
{% endstep %}

{% step %}
**Next to Profile, click** <i class="fa-pen-line">:pen-line:</i>.

1. On **Profile**, enter your first and last name, email address, and phone number.
2. Click **Save.**
3. A verification code should be sent to you. Enter it in the verification pop-up and click **Verify.**

{% hint style="warning" %}
You cannot edit your name or email address if your account is externally managed. See [Identity Providers](/command/security/identity-providers) for more information.
{% endhint %}
{% endstep %}

{% step %}
**When verification is successful,&#x20;*****Verified*****&#x20;will appear next to your phone number.**
{% endstep %}
{% endstepper %}


# Enterprise Controlled Encryption

Enable customer-managed encryption keys for maximum data security

Enterprise Controlled Encryption (ECE) provides the highest level of data security by allowing your organization to manage its own encryption keys. With ECE enabled, only your organization can decrypt your data—Verkada cannot access it.

{% hint style="warning" %}
ECE requires OIDC-based SSO with Google Workspace, Microsoft Entra ID, or Okta. SAML-only providers are not supported.
{% endhint %}

***

## How ECE works

ECE uses your identity provider to generate and manage encryption keys. When enabled:

* All data at rest is encrypted with keys derived from your IdP
* Verkada cannot decrypt your data without your IdP's authorization
* Losing access to your IdP means losing access to your encrypted data

***

## Setup and recovery

{% content-ref url="/pages/sqdqy4fJFDe0NUIV1iiG" %}
[Enable Enterprise Controlled Encryption](/command/security/enterprise-controlled-encryption/enable-enterprise-controlled-encryption)
{% endcontent-ref %}

{% content-ref url="/pages/umUW5ykuZAchQIipp6m7" %}
[Enterprise Controlled Encryption Account Recovery](/command/security/enterprise-controlled-encryption/ece-account-recovery)
{% endcontent-ref %}


# Enable Enterprise Controlled Encryption

Enable customer-managed encryption keys for maximum data security

{% hint style="info" %}
See [Enterprise Controlled Encryption (ECE) Overview](https://docs.verkada.com/docs/enterprise-controlled-encryption-overview.pdf) for more information.
{% endhint %}

***

## Prerequisites

### Configure Single Sign-On OIDC

Verkada currently only supports Okta, Microsoft Entra ID (Azure AD), and Google Workspace as identity providers for Single Sign-On with OIDC. For setup guides, see:

* [Okta](/command/security/identity-providers/okta)
* [Microsoft Entra ID](/command/security/identity-providers/microsoft-entra-id)
* [Google Workspace](/command/security/identity-providers/google-workspace)

{% hint style="danger" %}
OIDC SSO must be enabled in your organization to enable ECE.
{% endhint %}

### Update the Command mobile app

Ask all users in your organization to update their Verkada Command mobile app. The app updates automatically unless auto-update is disabled.

* iOS: [Verkada Command](https://apps.apple.com/us/app/verkada-command/id1157022527)
* Android: [Verkada Command](https://play.google.com/store/apps/details?id=com.verkada.android\&hl=en\&gl=US)

There is **no need** to update the Verkada Pass app.

***

## Enable ECE

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access > Enterprise Controlled Encryption.**
{% endstep %}

{% step %}
**Click Get Started.**
{% endstep %}

{% step %}
**Under Generate Key:**

a. Click **Generate Key**\
b. Download the encryption key\
c. [Add the encryption key to your identity provider](#add-encryption-key-to-identity-provider)\
d. Click **Continue**
{% endstep %}

{% step %}
**Under Verify:**

a. Click **Logout and Test**\
b. If successful, you will be redirected to this page\
c. Click **Continue**
{% endstep %}

{% step %}
**Under Enroll Devices:**

a. Click **Select Devices** and choose the devices to enroll in ECE\
b. Click **Enroll Devices**

{% hint style="info" %}
We recommend choosing **Select All Devices** to ensure additional security and data protection for your entire fleet.
{% endhint %}
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
The encryption key should only be generated once. Use this key to create the mapping in the OIDC provider. After verification, avoid regenerating the encryption key.
{% endhint %}

{% hint style="success" %}
Example encryption key file format:

```
File name: <command-org-name>_org_secret.txt

Format:
<display-name / variable-name>

<encryption-key>
```

{% endhint %}

***

## Add Encryption Key to Identity Provider

ECE is supported on Okta, Microsoft Entra ID (Azure AD), and Google Workspace.

<details>

<summary>Okta</summary>

1. Log in to your Okta admin account.
2. On the left, click **Directory > Profile Editor**.
3. Open **Verkada SSO OIDC User**.
4. Select **Add Attribute**:
   1. Add the Display name and Variable name (both values are the same) from the org\_secret.txt file. It starts with "vkdae2ee…"
   2. Click **Save**
5. Select **Mappings**:
   1. Click **Okta User to Verkada SSO OIDC**
   2. Copy the encryption key value (the second value in the .txt file, including quotation marks)
   3. At the bottom of the Mappings page, paste into the text box for the new variable
   4. Click the icon in the middle and select **Apply mapping on user create and update**
   5. Click **Save Mappings**, then **Apply updates now**

{% hint style="danger" %}
Completing the mapping steps correctly is crucial for a seamless ECE camera enrollment process.
{% endhint %}

{% hint style="info" %}
Refer to [Add Custom Profile Attributes](https://support.okta.com/help/s/article/How-To-Add-Custom-Profile-Attributes-As-Claims-In-a-ID-Token-or-userinfo?language=en_US) if you encounter issues.
{% endhint %}

</details>

<details>

<summary>Microsoft Entra ID (Azure AD)</summary>

1. Log in to your Azure portal.
2. Search for and select **App registrations**.
3. Select **Verkada SSO OIDC** (check All applications if not visible).
4. On the left, click **Manage > App roles**:
   1. Click **Create app role**
   2. Add the **Display Name** and **Description** using the same first value from the `org_secret.txt` file
   3. Under **Allowed member types**, select **Users/Groups**
   4. **Under Value, enter the encryption key in the format** `first_value:second_value` (without quotes)
   5. Click **Apply**
5. On the left, click **Manage > Token Configuration**:
   1. Click **Add groups claim**
   2. Select **Security groups** as the group type
   3. Select **Emit groups as role claims** as the ID
   4. Click **Add**
6. On the left, click **Manage > Authentication > Settings**:
   1. Under **Implicit grant and hybrid flows**, select both **ID tokens** and **Access tokens**
   2. Click **Save**
7. On the left, click **Manage > Manifest**:
   1. Verify `idToken.additionalProperties.emit_as_roles` is present
8. Assign users to the new role:
   1. Search for and select **Microsoft Entra ID**
   2. On the left, click **Manage > Enterprise applications**
   3. Click **Verkada SSO OIDC**
   4. On the left, click **Manage > Users and groups**
   5. Click **Add user/group**
   6. Assign users the newly created role
   7. Click **Assign**

</details>

<details>

<summary>Google Workspace</summary>

1. Open your Google Admin console.
2. Navigate to **Directory > Users**.
3. Select **More Options > Manage custom attributes**.
4. Click **Add Custom Attribute** with:
   1. Category: **ECEInfo**
   2. Custom field: Name: **keys**, Info Type: **Text**, Visibility: **Visible to User and Admin**, No. of Values: **Multi-Value**
   3. Click **Add**
5. For each user needing access to your Verkada organization:
   1. Go to **Directory > Users** and select a user
   2. Expand **User Information > ECEInfo**
   3. Click **Edit**
   4. Add the display name and encryption key separated by a colon: `<display name>:<encryption key>`
   5. Click **Save**
   6. Repeat for all users

**For automation**, create a Google Group and use the Apps Script provided in the [Verkada ECE documentation](https://docs.verkada.com/docs/enterprise-controlled-encryption-overview.pdf).

</details>


# Enterprise Controlled Encryption Account Recovery

Recover access to your ECE-protected account

Enterprise Controlled Encryption (ECE) allows your organization to create and manage its own encryption keys. Verkada cannot access or decrypt your video data.

If you lose access to your customer secret (the cryptographic key that secures your data), you cannot decrypt your data. This can happen if:

* You forgot your password
* You logged in using a passwordless method like a magic link
* You need to recover access without your original credentials

Recovery codes provide a secure fallback method to regain access.

***

## Recovery codes

A recovery code is a unique, secure string tied to your user account. It lets you decrypt a version of your encrypted customer secret when you cannot access it through normal login.

Your recovery code:

* Is created when you join the organization
* Is emailed to you after you set your password
* Stays valid until you rotate it or your account is deleted
* Can be resent by an Organization Admin

### When recovery codes are sent

We send your recovery code only after you accept your invite and set your password. This ensures you are a verified user.

The email will be titled: **Verkada ECE Recovery Code - \<org short name>**

### Why recovery codes matter

Your recovery code provides a backup way to decrypt your customer secret. Without it, you may lose access if:

* You forgot your password
* You lose your login device
* You cannot use passwordless login methods

### Encryption and security

Recovery codes are protected using:

* Argon2id (a modern password hashing algorithm) with high entropy (128-bit minimum)
* AES encryption with keys derived from your recovery code
* RSA key pairs for additional protection
* Secret keys stored securely in our backend, accessible only to you

***

## Use your recovery code

If you are locked out and prompted to enter your recovery code:

{% stepper %}
{% step %}
**Find the email titled "Verkada ECE Recovery Code - \<org short name>" (sent after account setup).**
{% endstep %}

{% step %}
**Copy and paste the code into the recovery form.**
{% endstep %}

{% step %}
**You will regain access to decrypt your customer secret.**
{% endstep %}
{% endstepper %}

***

## Rotate or resend a recovery code

Organization Admins can send a new recovery code at any time. You must have access to your current customer secret before sending a recovery code.

{% hint style="danger" %}
You need to log in with an Org Admin account that has validated its recovery code before you can manage user recovery codes. If you log in with a passwordless method, you will be prompted to enter your recovery code. If you skip this step, you will not be able to manage user recovery codes.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Users & Permissions, then click Users.**
{% endstep %}

{% step %}
**Select a user profile.**
{% endstep %}

{% step %}
**In the top right, click > Control Login.**

1. Click **Send New Recovery Code**
2. Click **Confirm** to save
3. The new code will be emailed to the user, and the old code will be automatically invalidated
   {% endstep %}

{% step %}
**Click Done when finished.**
{% endstep %}
{% endstepper %}

***

## FAQ

<details>

<summary><strong>What happens if I lose my recovery code?</strong></summary>

Your admin can send you a new recovery code from your user account settings.

</details>

<details>

<summary><strong>Is my recovery code the same as my invite link?</strong></summary>

No. The invite link is used to join the organization. The recovery code is generated after you join and create your password.

</details>

<details>

<summary><strong>Can I use my recovery code more than once?</strong></summary>

Yes, you can use your recovery code more than once.

</details>


# Identity Providers

Configure SSO and user provisioning with your identity provider

Integrate Verkada Command with your organization's identity provider (IdP) for Single Sign-On (SSO) and automated user provisioning.

***

## Supported providers

| Provider                                                                      | OIDC | SAML | SCIM | ECE Support |
| ----------------------------------------------------------------------------- | :--: | :--: | :--: | :---------: |
| [Okta](/command/security/identity-providers/okta)                             |  Yes |  Yes |  Yes |     Yes     |
| [Microsoft Entra ID](/command/security/identity-providers/microsoft-entra-id) |  Yes |  Yes |  Yes |     Yes     |
| [Google Workspace](/command/security/identity-providers/google-workspace)     |  Yes |  Yes |  Yes |     Yes     |
| [OneLogin](/command/security/identity-providers/onelogin)                     |   —  |  Yes |   —  |      —      |
| [JumpCloud](/command/security/identity-providers/jumpcloud)                   |   —  |  Yes |   —  |      —      |
| [AD FS](/command/security/identity-providers/ad-fs)                           |   —  |  Yes |   —  |      —      |

{% hint style="info" %}
Verkada recommends OIDC over SAML when available for enhanced security and easier configuration.
{% endhint %}

***

## Which method should I use?

* **Want the most secure option?** Use OIDC + [Enterprise Controlled Encryption](/command/security/enterprise-controlled-encryption)
* **Need automated user management?** Add SCIM provisioning to sync users from your IdP
* **IdP only supports SAML?** Follow the generic SAML setup instructions below

***

{% hint style="danger" %}
You need [Organization Admin](/command/users-and-permissions/roles-and-permissions-for-command) permissions to set up SSO.
{% endhint %}

## Generate client-ID

{% stepper %}
{% step %}
**Go to Verkada Command > All Products > Admin.**
{% endstep %}

{% step %}
**Under Login & Access, select Single Sign-On (SSO).**
{% endstep %}

{% step %}
**Click** <i class="fa-plus">:plus:</i> **Add.**

You should see your client ID and the fields to enter into your IdP:

* **Client ID**:
  * US orgs: `https://vauth.command.verkada.com/saml/sso/<client-ID>`
  * EU orgs: `https://saml.prod2.verkada.com/saml/sso/<client-ID>`
  * AUS orgs: `https://saml.prod-ap-syd.verkada.com/saml/sso/<client-ID>`
* **Reply ID**:
  * US orgs: `https://vauth.command.verkada.com/saml/sso/<client-ID>`
  * EU orgs: `https://saml.prod2.verkada.com/saml/sso/<client-ID>`
  * AUS orgs: `https://saml.prod-ap-syd.verkada.com/saml/sso/<client-ID>`
* **Sign-on URL**:
  * US orgs: `https://vauth.command.verkada.com/saml/login/<client-ID>`
  * EU orgs: `https://saml.prod2.verkada.com/saml/login/<client-ID>`
  * AUS orgs: `https://saml.prod-ap-syd.verkada.com/saml/login/<client-ID>`

{% hint style="info" %}
To confirm which region you're located in, refer to where [your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}
{% endstep %}

{% step %}
**Complete your IdP configutation then come back to complete the** [**Command configuration**](#command-configuration)**.**
{% endstep %}
{% endstepper %}

***

## Command SSO configuration

After configuring your IdP, you'll receive an XML metadata file to upload to Command.

{% stepper %}
{% step %}
**Go to Verkada Command > All Products > Admin.**
{% endstep %}

{% step %}
**Under Login & Access, select Single Sign-On (SSO).**
{% endstep %}

{% step %}
**Click** <i class="fa-pencil-line">:pencil-line:</i> **next to your SAML configuration.**
{% endstep %}

{% step %}
**In the Email Domains section, configure the email domains that users in your organization will use to log in.**
{% endstep %}

{% step %}
**In the Identify Provider XML Metadata section, click Upload New XML.**

Upload the XML file you downloaded during your IdP configuration.
{% endstep %}

{% step %}
**In the Verify Metadata section, click Run Login Test to verify that the setup was completed correctly. If the login tests fail, review your metadata file and associated domains.**

Common error: `app_not_configured_for_user` — This can happen when your browser has cached app access. Use an incognito browser or clear your cache and retry.

{% hint style="danger" %}
Before you can verify the XML, you must add email domains.
{% endhint %}
{% endstep %}

{% step %}
**(Optional) Toggle on Require SSO to force everyone in your organization to login with SSO.**

* Anyone using the configured email domain must go through SAML to sign in
* Provides greater control over user access
* If SAML has issues, users cannot sign in until resolved or enforcement is disabled

{% hint style="warning" %}
You cannot require SSO until the XML has been verified.
{% endhint %}
{% endstep %}
{% endstepper %}

***

#### Need help?

See [SCIM Token Management](/command/security/identity-providers/scim-token-management) for provisioning configuration.


# Okta

Configure SSO and user provisioning with Okta

Verkada Command has the ability to integrate with Okta (amongst other Identity Providers \[IdPs]) in 2 capacities, depending on the use case:

* OpenID Connect (OIDC)
* Security Assertion Markup Language (SAML)
* System for Cross-Domain Identity Management (SCIM)

**OIDC** and **SAML** both handle authentication, allowing Okta to manage access to Command the same way it manages access to other SaaS applications in your environment. Both protocols let you integrate Command into your existing identity framework and authorize users in line with your current policies.

**SCIM** allows you to leverage your existing users and groups in Okta and synchronize them with Command. This allows you to retain the current central IdP and configure permissions in Command using your existing users and groups.

{% hint style="info" %}
Verkada recommends OIDC over SAML for enhanced security and easier configuration. OIDC also enables [Enterprise Controlled Encryption](/command/security/enterprise-controlled-encryption).
{% endhint %}

***

{% tabs %}
{% tab title="OIDC (Recommended)" %}

#### OIDC based SSO for Okta

Verkada Command supports Single Sign-On (SSO) through OpenID Connect (OIDC) with Okta. This integration allows our users to seamlessly and securely authenticate using their existing Okta credentials, streamlining access to Command and enhancing overall security.

{% hint style="info" %}
Enable [Enterprise Controlled Encryption (ECE)](/command/security/enterprise-controlled-encryption) for enhanced security.
{% endhint %}

| Feature                | Supported |
| ---------------------- | :-------: |
| OIDC SSO               |    Yes    |
| SAML SSO               |    Yes    |
| SCIM User Provisioning |    Yes    |
| ECE Support            |    Yes    |

***

**OIDC configuration**

{% stepper %}
{% step %}
**Navigate to your Okta instance to create a new application to manage your OIDC configuration. Click on Applications from the Applications sidebar option and click Create App Integration.**

<div align="left" data-with-frame="true"><img src="/files/1B4rozOFJ84D5YM6ocKS" alt="" width="563"></div>
{% endstep %}

{% step %}
**Under Create a new app integration, select OIDC - OpenID Connect as your Sign-in method and Single-Page Application as your Application type.**

<div align="left" data-with-frame="true"><img src="/files/GHwflkFWQcyp5D7jmk97" alt="" width="563"></div>
{% endstep %}

{% step %}
**Under Sign-in redirect URIs give your application an identifiable name and add the following links to the list of Sign-in redirect URIs:**

a. <https://command.verkada.com/oidc/okta/callback>\
b. [https://\<org-short-name>.command.verkada.com/oidc/okta/callback](http://org-short-name.command.verkada.com/oidc/okta/callback), where in the URL is the short-name of your Command organization.

<div align="left" data-with-frame="true"><img src="/files/ZPahkRRpj6nvTjRKtltq" alt="" width="800"></div>
{% endstep %}

{% step %}
**(Optional) Under Sign-out redirect URIs add** [**https://command.verkada.com/**](https://command.verkada.com/)**.**

<div align="left" data-with-frame="true"><img src="/files/9jMFZ2e4T8L07Ud62k9p" alt="" width="800"></div>
{% endstep %}

{% step %}
**Under Assignments, select Skip Group Assignment for now and click Save.**

<div align="left" data-with-frame="true"><img src="/files/bfuLJfGSWKUflFcPRcq6" alt="" width="800"></div>
{% endstep %}

{% step %}
**Under Assignments, click on the Assign dropdown to assign this application to your (and other relevant) user profiles.**

<div align="left" data-with-frame="true"><img src="/files/MFMX5cXh4OOa9iw2rqI2" alt="" width="800"></div>
{% endstep %}

{% step %}
**Under General, copy the Client ID displayed under Client Credentials.**

<div align="left" data-with-frame="true"><img src="/files/iplAuIY62CvGHQz7e9SS" alt="" width="800"></div>
{% endstep %}
{% endstepper %}

***

**Command configuration**

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access.**
{% endstep %}

{% step %}
**Select Single Sign-On Configuration.**
{% endstep %}

{% step %}
**Under OIDC Configuration, click Add New.**

a. Toggle on **Enable.**\
b. (Optional) Toggle on **Require OIDC SSO.**\
c. Under **Select Provider,** select **Okta.**\
d. Under **Add Client and Tenant,** click :plus:.

1. In the **Client ID** field paste the Client ID you copied from Okta.
2. In the **Tenant ID** field enter the first part of your Okta instance's URL. It should look like this: [https://yourinstancename.okta.com](https://yourinstancename.okta.com/).
3. Click **Done**.

   <div align="left" data-with-frame="true"><img src="/files/QAwIRyKAOfKW2QC6Dodj" alt="" width="800"></div>

h. **Email Domains,** click :plus:**.**

1. Enter your domain name present (e.g. @verkada.com).
2. Click **Done**.

   <div align="left" data-with-frame="true"><img src="/files/ntREdy9QuYSSp2bzdKya" alt="" width="800"></div>

{% endstep %}

{% step %}
**Under Login Test click Run Login Test.**
{% endstep %}

{% step %}
**A successful login test should redirect to the OIDC configuration page. Once you're logged in, add the domain that you need to whitelist.**
{% endstep %}

{% step %}
**Once your domain is added, run the login test again. SSO will not be enabled until this second login test successfully completes.**
{% endstep %}

{% step %}
**Once your domain is verified, you should see it successfully validated.**
{% endstep %}
{% endstepper %}

***

#### Log in via the mobile application

{% hint style="info" %}
The Android and iOS Command apps support OIDC-based login.
{% endhint %}

{% stepper %}
{% step %}
**Open your Command app.**
{% endstep %}

{% step %}
**In the email address field, enter your email and click Next.**
{% endstep %}

{% step %}
**You should be redirected to your IdP (Okta) to complete the login process.**
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="SAML" %}
**Okta SAML Integration**

***

**Before you begin**

For a successful integration, choose the best path for your region:

* [Enable SAML for Your Command Account](/command/security/identity-providers#upload-saml-xml-metadata)
* **For US orgs**, you will use an existing Verkada application following steps directly below.
* **For EU and AUS orgs**, follow the steps for the next section to configure a new app integration in Okta.

<details>

<summary>Create a Verkada Okta app (US regions)</summary>

1. **Log in to Okta.**
2. **Go to the Applications page and click Browse App Catalog.**

   <div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/449896715/390b39e32ff7892e3a4c7123/Screen+Shot+2022-01-17+at+3.17.12+PM.png?expires=1766003400\&#x26;signature=22f123d38bacf85fa5a9f30c9dc7a5242cd3ed61d9a71b44aa24cf937709bb14\&#x26;req=cCQuHsB4moBaFb4f3HP0gK8CSkgsYzn3qhkkLT8eMaCLqqJiY68f8kCdYBCM%0AqY4%3D%0A" alt="" width="800"></div>
3. **In the search bar, type Verkada.**
4. **Click Add Integration.**

   <div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/449897287/e17bbcb0aac5233606a71783/Screen+Shot+2022-01-17+at+3.18.45+PM.png?expires=1766003400\&#x26;signature=e671263a738671cf7f24df811082e25d8d9fa670f5c9024e9085b5f6e1883fe3\&#x26;req=cCQuHsB5n4lYFb4f3HP0gK4OGuNco5idOO0lt8OafCOqMnOFTJEqxdcz3ZfH%0AOH8%3D%0A" alt="" width="800"></div>
5. **Click Done.**

   <div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/449897651/d563f47daacb254236cf0454/Screen+Shot+2022-01-17+at+3.21.27+PM.png?expires=1766003400\&#x26;signature=6871448aecf02075e8f29cf2fd6c1f908b7793f1d57c547e7cf0f4efbd479ea3\&#x26;req=cCQuHsB5m4ReFb4f3HP0gGt1PTq1x%2B0JH9fUDuo6%2F3taZSMJf6DmU%2FgeF4xI%0AEkA%3D%0A" alt="" width="800"></div>
6. **In Okta, select the Sign On tab for the Verkada app, and click Edit.**

   <div align="left" data-with-frame="true"><img src="/files/f9MBlrKmR3XyfrbbvMVY" alt="" width="800"></div>
7. **Scroll down to Advanced Sign-On Settings and enter the Client ID from your Command account.**

   <div align="left" data-with-frame="true"><img src="/files/KfmQsglel8AzpHKRP5Yd" alt="" width="800"></div>
8. **Select Save.**

   <div align="left" data-with-frame="true"><img src="/files/O5WK36bF98lzWdLt2XN4" alt="" width="800"></div>

</details>

<details>

<summary>Configure a new app integration from Okta (EU &#x26; AUS regions)</summary>

1. **Go to Applications, and select Create App Integration.**
2. **Create a new app integration, select SAML 2.0, and click Next.**

   <div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/1102852007/dd17f8b70d0287d06a11ba40/image.png?expires=1766003400\&#x26;signature=f6e24360efec33ff0e3afa6f07c4c112175037ddb034853b56107bf332cba625\&#x26;req=dSEnFMF7n4FfXvMW1HO4zXPltyd%2B2lhHD1n4y9sXweynIKPYzWTArMzGiQk2%0AxFxH%0A" alt="" width="800"></div>
3. **On the "Create a SAML integration" page, under General Settings, enter an application name, optionally add an application logo, and then click Next.**
4. **In the configure SAML page, fill in the Single Sign-On URL and Audience URI (SP Entity ID) with these links:**

   * For EU orgs: [https://saml.prod2.verkada.com/saml/sso/\<client-ID>](https://saml.prod2.verkada.com/saml/sso/%3Cclient-ID%3E)
   * For AUS orgs: [https://saml.prod-ap-syd.verkada.com/saml/sso/\<client-ID>](https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E)

   Check the **Use this for Recipient URL and Destination URL** box.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Client ID</strong> should be pulled from the Command configuration and replaced in the links inserted in the Okta application.</p></div>

   <div align="left" data-with-frame="true"><figure><img src="/files/zULcm5ZUPGgdvbF1FPyx" alt="" width="800"><figcaption></figcaption></figure></div>
5. **The application username is the Okta Username.**
6. **Click Next. On the feedback page, check the box labeled "This is an internal app that we have created". Click Finish.**

<div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/1102855332/9fae260feef25cb11bd7cd27/image.png?expires=1766003400\&#x26;signature=50ce8e5764340d45248e6c299c221ff32cda6ea62da6428016d113d088f43943\&#x26;req=dSEnFMF7mIJcW%2FMW1HO4zWsfcy8mxJmpu5er%2BtIFWBX5DFNhGgak3xp5mWgs%0A0Rgx%0A" alt="" width="800"></div>

1. **In the attributes statements section, set up attributes mapping as follows:**

   * `email` > `user.email`
   * `firstName` > `user.firstName`
   * `lastName` > `user.lastName`

   <div align="left" data-with-frame="true"><figure><img src="/files/ZwSE6mD7gyPMi4JUbNub" alt="" width="800"><figcaption></figcaption></figure></div>

</details>

***

**Configuration**

{% stepper %}
{% step %}
**In Okta, select the Assignments tab for the app. Click Assign and select People or Groups to enable SSO for these users.**
{% endstep %}

{% step %}
**Select the Sign On tab for the app.**
{% endstep %}

{% step %}
**Scroll down to SAML Signing Certificates and click Generate new certificate if a new certificate does not exist.**
{% endstep %}

{% step %}
**To the right of the certificate, select the Actions dropdown and click View IdP metadata.**

<div align="left" data-with-frame="true"><img src="/files/NUal4JIQkhjXf635CGc3" alt="" width="800"></div>
{% endstep %}

{% step %}
**Right-click the metadata, select "Save As," and download as an XML file.**
{% endstep %}

{% step %}
**After downloading the XML file,** [**upload it to Command**](/command/security/identity-providers#upload-saml-xml-metadata)**.**
{% endstep %}

{% step %}
**In the Verify Metadata section, click Run Login Test.**
{% endstep %}
{% endstepper %}

***

#### Log in via the mobile application

{% hint style="info" %}
The Android and iOS Command apps support SAML-based login.
{% endhint %}

{% stepper %}
{% step %}
**Open your Command app.**
{% endstep %}

{% step %}
**In the email address field, enter your email and click Next.**
{% endstep %}

{% step %}
**You should be redirected to your IdP (Okta) to complete the login process.**
{% endstep %}
{% endstepper %}

***

**Troubleshooting**

* **Updating usernames (emails) does not automatically take effect in Command**. If you need to change a username, unassign the user from the SAML app, then re-add the user to the app for the change to take effect.
* **If a new user cannot log in via SSO**, it could be because the email domain is not being added to the SSO configuration in the Verkada backend. If the user's email is outside the email domains configured when SSO was set up, the user cannot use SSO. If this is the cause of the problem, you need to edit the SSO configuration and add this domain to remedy the issue.
* **If you experience any other problems with setting up SSO**, contact [Verkada Support](/command/need-help/contact-verkada-support).
  {% endtab %}

{% tab title="User Provisioning (SCIM)" %}

#### Okta SCIM Integration

***

**Before you begin**

{% stepper %}
{% step %}
**You need an API token to connect to the Verkada SCIM endpoint. This token is unique per the Verkada organization. Learn how to** [**acquire a SCIM API token**](/command/security/identity-providers/scim-token-management)**.**
{% endstep %}

{% step %}
**For a successful integration, choose the best path for your region:**

* **For US orgs**, follow the steps in Create a Verkada Okta app.
* **For EU and AUS orgs**, follow the steps in Enable SCIM provisioning in Okta app.
  {% endstep %}
  {% endstepper %}

{% hint style="warning" %}
To confirm which region you're located, [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}

***

**Create a Verkada Okta app**

<details>

<summary>US region</summary>

1. Log in to Okta.
2. On the left navigation panel, click Applications.
3. At the top, click Browse App Catalog.

<div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/449896715/390b39e32ff7892e3a4c7123/Screen+Shot+2022-01-17+at+3.17.12+PM.png?expires=1766003400&#x26;signature=22f123d38bacf85fa5a9f30c9dc7a5242cd3ed61d9a71b44aa24cf937709bb14&#x26;req=cCQuHsB4moBaFb4f3HP0gK8CSkgsYzn3qhkkLT8eMaCLqqJiY68f8kCdYBCM%0AqY4%3D%0A" alt="" width="800"></div>

4\. In the search bar, type Verkada, click the app, and then click Add Integration.

<div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/862216187/b148b14a43ce418501b12069/8375910_OktaSCIMintegration.png?expires=1766003400&#x26;signature=2ed4243f90ccb2112842367c8966cd540765dba751717a8f5963079ce366b0fc&#x26;req=fCYlFMh4nIlYFb4f3HP0gBUSQgAMwz4tz0EiSwyS8tw2UQZtrTgdZJv0gOHs%0AYM4%3D%0A" alt="" width="800"></div>

5\. For Application label, type Verkada (or any unique name you prefer) and click Done.

<div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/449897651/d563f47daacb254236cf0454/Screen+Shot+2022-01-17+at+3.21.27+PM.png?expires=1766003400\&#x26;signature=6871448aecf02075e8f29cf2fd6c1f908b7793f1d57c547e7cf0f4efbd479ea3\&#x26;req=cCQuHsB5m4ReFb4f3HP0gGt1PTq1x%2B0JH9fUDuo6%2F3taZSMJf6DmU%2FgeF4xI%0AEkA%3D%0A" alt="" width="800"></div>

</details>

<details>

<summary>EU &#x26; AUS region</summary>

1. Log in to Okta.
2. Go to the Applications page and click Create App Integration.

   <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851144/63f1c84c55eb91cd2c8eaa9a/WsSZmmICcArfKIUzbJYN4_T5Sra5e6IO34jeIdFraM2YPNuIIjjJ8Rh1vnOMjVmDq_dGKbLpqX4o_QT0NP6DyPgJhyjHAy2BUydB7V23rMr5xFPmT4icGAsCgohn0m5wTxje0zah2xX4sQ1xtlm25wo?expires=1766003400\&#x26;signature=19aae02631c4e9ad01969e320ce1ad7c0984fcae271d336cd2f177974e686414\&#x26;req=fCghHsx%2FnIVbFb4f3HP0gFX9cCgDlGGbgLvgCfpHtN1iQ4hvq%2F9YOxRafCNG%0ARbA%3D%0A" alt="" width="800"></div>
3. On Create a new app integration, select SAML 2.0 and click Next.
4. In the App name field, enter a name and click Next.
5. On Create SAML Integration:
   1. For Single sign-on URL:

      For EU orgs: [https://saml.prod2.verkada.com/saml/login/\<org short name>](https://saml.prod2.verkada.com/saml/login/) where *\<org short name>* is your organization’s short name.

      For AUS orgs: [https://saml.ap-syd.verkada.com/saml/login/\<org short name> ](https://saml.prod3.verkada.com/saml/login/)where *\<org short name>* is your organization’s short name.
   2. For Audience URI (SP Entity ID):

      For EU orgs:[ https://saml.prod2.verkada.com/saml/sso/\<org short name> ](https://saml.prod2.verkada.com/saml/sso/)where *\<org short name>* is your organization’s short name.

      For AUS orgs: [https://saml.](https://saml.prod3.verkada.com/saml/sso/)[ap-syd](https://saml.prod3.verkada.com/saml/login/)[.verkada.com/saml/sso/\<org short name> ](https://saml.prod3.verkada.com/saml/sso/)where *\<org short name>* is your organization’s short name.
   3. Scroll down and click Next.

      <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851148/6fd39889aad356e828a9f1e2/c95BQJPAkrZwgMRjzr1FQ1hIT28LoFNI5VMyRfx65HTud87oLHkEbrzq8LPe01MHtA6tKF-sRYv8p0cKUCQkVUThaoJnWGxBHj-Him2q5DmIdm-bQy0dzvQpk0cRvWwRvGf1PTZzGTn79b1zfz_gA98?expires=1766003400\&#x26;signature=5fd20b86013bc0f4ba28cbdd3d233f71a2a6961cec82c73c0b477748fb44a9ef\&#x26;req=fCghHsx%2FnIVXFb4f3HP0gIsENFokZPlQ6p7gfi0ihxbn4uDdLx%2FWBqOO7c3X%0APHg%3D%0A" alt="" width="800"></div>
6. Select the I’m an Okta customer adding an internal app radio button and click Finish (optionally, you can skip Okta’s additional questions).
7. On the left navigation, click Applications and click your newly created app (if you are not automatically redirected to your app).
8. At the top, select the General tab:
   1. At the top right, click Edit for your app’s App Settings.
   2. Check the Enable SCIM provisioning box.
   3. Click Save.

      <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851153/bfa634bbbaae62cca595a09f/vwlKHLqNXGQkFOWEkVbAKXZhzP-aSETLv4m9IQ3O2gzBpP9Np7ocOAkzAktGxC8wM53R8WR3etrx2fs3zsjCXL20YbqEy7DwD8i48-hxcB3FXdllet8sYm3zUtzgB55G0EUGEW1ji0uXjMIYZyzepjA?expires=1766003400\&#x26;signature=55027176fa5d6a8129c53a97c6743086c488a3e43abc188cf83104121a54e73f\&#x26;req=fCghHsx%2FnIRcFb4f3HP0gFJXoIOCtJbQzP0a%2FnhB2y7JCSg5lWFQzV%2F2FDTF%0Ai%2BI%3D%0A" alt="" width="800"></div>
9. On SCIM Connection:
   1. At the top of your newly created app, select the Provisioning tab.
   2. Click Edit for the SCIM Connection settings.
   3. For SCIM connector base URL

      For EU orgs, <https://scim.prod2.verkada.com/scim>

      For AUS orgs, [https://scim.ap-syd.verkada.com/scim](https://scim.prod2.verkada.com/scim)
   4. For Unique identifier field for users, enter userName.
   5. Check the Push New Users, Push Profile Updates, and Push Groups boxes.
   6. Click the Authentication Mode dropdown and select HTTP Header.
10. Copy and paste the SCIM token from Command in the Authorization field.

    <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851157/96d872e82636280e8810b5cd/2psAWP661MUUm0bwdb-15pWDM2yInrCLzJ52ju9UQ141G1OuZWQvUCD-MJE3HWMumJyPIyqIxUXUfmJG7JtQ4DaTJ6OkaaThBRqXBDWznAvJ8F-6vRExzhUfbTQVHJ9ySeGsrujuOhPE9kEmMykpFpo?expires=1766003400\&#x26;signature=1a3a6dac2cf88e1fc3668dca25798e5742035c80f146cd21a11274e619978943\&#x26;req=fCghHsx%2FnIRYFb4f3HP0gIT5S38DtHQhhUWTe3Q20l5GdXTLrtOI2YLqFnK0%0ARYY%3D%0A" alt="" width="800"></div>
11. Click Save.

</details>

***

**Configure the Verkada Okta app**

<details>

<summary>US region</summary>

1. Log in to Okta.
2. On the left, click Applications and click the Verkada app.
3. On the left, select the Provisioning tab.
4. Under the Provisioning tab > Integration:
   1. Click Configure API Integration.
   2. Check the Enable API integration box.
   3. In the API Token field, copy and paste your Command-generated API token.
   4. Click Save.

      <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851164/bfaea19da7bc2d70c8718f59/1Uqq8IPPIlQxHHrtgwQX2uoof53IwL43EqOj6sgOKGkL21FpMDgPKvZU4O3UR8axr9tSc0o-EfGs239SNAEqxzIKwfe8j1N5UXZPHSHo4-fH0O9vh470EhNgw2TU77d72HjC0YEJEFEkQ9gjuJM3JxM?expires=1766003400\&#x26;signature=fec9e530aff69237affe8757ddf306027fbc84c81bc5a234c9c4846d0077cf97\&#x26;req=fCghHsx%2FnIdbFb4f3HP0gOEEIFpHRoy4XZ%2Bzea%2BP76fZ9tG4Lw5cmlHZAO6w%0ASvA%3D%0A" alt="" width="800"></div>
5. Under the Provisioning tab > Settings:
   1. Select To App and click Edit.
   2. Check the Enable box for Create Users, Update User Attributes, and Deactivate Users.
   3. Click Save.

      <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851172/d574d2353093abe51f46555f/oEFsUMqaaEmJgSbRL43Q-r3TBLlIl1p0E0z_zu8-iNUsfnUUOM4BY2SodL6eCh99zJ6GERBJX7MCbSGsyBHMgvKnmAEaLE_R8KDIj6x1P6eTXrGJPYyALWqsNQ7q5--t4wu6RsmCY6wPsW8mQAV6ees?expires=1766003400\&#x26;signature=fc77bae6b81720fccb8f86f3570051605226a436ed4b940553c8b4046495089f\&#x26;req=fCghHsx%2FnIZdFb4f3HP0gCKBhfXRZqkUtOVsefJPDM96y22ejfZXznC1xdmM%0AdIc%3D%0A" alt="" width="800"></div>
6. Under the Provisioning tab > To App section > Verkada Attribute Mappings, click Go to Profile Editor.
7. Ensure that the attributes match, as shown in example below. You can add more attributes than shown. See [Add attributes to SCIM-managed users](#add-attributes-to-scim-managed-users).

   <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851176/a0db505658eaae5d0d626de0/PIBYFY8jXzcT7lnRd57pjtfZum9oDzyH5Rx9BiiAKmE6sJflxxQCBQL2HacJRGzZdSH_bIICRVTIt7_BrXbmiJLwyTLxPFAVEtmsQiwPb9qzNrimmTL15XZzwoU2sZivYIIFHNtrvVJDd15Zuff0Oc4?expires=1766003400\&#x26;signature=8b1b23a5e437f5e559e1ae4ed7f555efd35d8fcb36bd832b8a5fcf5c251ed4de\&#x26;req=fCghHsx%2FnIZZFb4f3HP0gGCncM16IH%2BM1u2IZJmbblnERJH2LTdehgXA1xRb%0AF%2Bk%3D%0A" alt="" width="800"></div>

</details>

<details>

<summary>EU and AUS region</summary>

1. Log in to Okta.
2. On the left, click Applications and click the Verkada app.
3. Under the Provisioning tab > Settings:
   1. Select To App and click Edit.
   2. Check the Enable box for Create Users, Update User Attributes, and Deactivate Users.
   3. Click Save. You can add more attributes than shown. See [Add attributes to SCIM-managed users](#add-attributes-to-scim-managed-users).

      <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851180/11af938596e16a8fd1103eb4/oEFsUMqaaEmJgSbRL43Q-r3TBLlIl1p0E0z_zu8-iNUsfnUUOM4BY2SodL6eCh99zJ6GERBJX7MCbSGsyBHMgvKnmAEaLE_R8KDIj6x1P6eTXrGJPYyALWqsNQ7q5--t4wu6RsmCY6wPsW8mQAV6ees?expires=1766003400\&#x26;signature=874ef3a07ff6a32c3366e9c70f41153d76368b171a44aadf9e006292ab41ab34\&#x26;req=fCghHsx%2FnIlfFb4f3HP0gL%2BQvgs5Jd2oAQ0QnMC3vH91dWpOTKMXuDGqcrvr%0AuSs%3D%0A" alt="" width="800"></div>

</details>

***

**Add-on attributes to SCIM-managed users**

<details>

<summary>Add attributes to SCIM-managed users (optional)</summary>

Verkada and Okta support these attributes: `userName` (default), `givenName` (default), `familyName` (default), `title`, `employeeNumber`, `primaryPhone`, `department`, `organization`.

You can also sync a unique identifier to Command by mapping it to the `externalId` field. This enables advanced use cases such as disambiguating users across systems or syncing access credentials to a unique user reference. This value is stored in the database and can be queried via API, but it does not appear in the Command UI.

{% hint style="info" %}
To provision phone numbers outside the US in Command, include the country code in the user's phone number in the Okta profile.

For example:

* US: 123-456-7890 → +1 123-456-7890
* UK: 07123 456789 → +44 7123 456789

Using the international format ensures the number is correctly imported into Command.
{% endhint %}

1. **Log in to Okta.**
2. **Create the Attribute in the SCIM App Profile.**

   1. In Okta, go to **Directory > Profile Editor.**
   2. Select your **Verkada SCIM-managed application User.**
   3. Click **Add Attribute** and add the attribute details as listed in the [table](#attribute-table) below.
   4. Click **Save.**

   <div align="left" data-with-frame="true"><img src="/files/Bqvmd8Mmv9YvSLLILHXx" alt="" width="800"></div>
3. **Map the Attribute**

   1. Still in Profile Editor, click **Mappings.**
   2. Choose **Okta User to \[Your SCIM App].**
   3. Click the dropdown and find the source field you want to map (e.g., `user.nickName`, `employeeNumber`, or another custom field) and map it to the `appuser` attribute.
   4. Click the arrow between fields and select **Apply mapping on user create and update.**
   5. Click **Save Mappings.**

   <div align="left" data-with-frame="true"><img src="/files/ewQ9FClWH36f3WuzfDqs" alt="" width="800"></div>
4. **Confirm Attribute is Populated**

   1. Navigate to **Directory > People.**
   2. Open a user profile and ensure the source field you're mapping from (e.g., Nickname) has a value.
   3. From the **SCIM App > Provisioning tab**, use **Force Sync** to push updates if needed.

   <div align="left" data-with-frame="true"><img src="/files/ZCF5jx6FSIVL6XbrqJLq" alt="" width="800"></div>

{% hint style="warning" %}
Refer to this list of credentials for the list of [acceptable card formats](/access-control/installation/badge-reader-support/supported-card-formats).
{% endhint %}

</details>

<details>

<summary>Add access credentials to SCIM-managed users (optional)</summary>

1. **Log in to Okta.**
2. **On the left navigation, select Directory > Profile Editor.**
   1. Select **User (default)** as the user type.
   2. Click **Add Attribute** and add the custom attributes from the [table](#attribute-table) below.
3. **On the left navigation, select Applications and open your Verkada SCIM-managed application.**
4. **On the Provisioning tab, select To App > Go to Profile Editor.**
5. **Click Add Attribute to create the attributes listed above using the exact same Data Type, Display Name, Variable Name, Description, and ENUM values.**

   1. Set the **External namespace** value for all attributes to:

   ```
   urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User
   ```

   2. Set **Attribute type** to **Personal**.
   3. Click **Save** to add the attribute.
6. **Click Mappings to map the attributes from the Okta User application to your SCIM application.**

   1. Select **Okta User to YourSCIMApp** at the top and map the custom attributes created for the Okta Default User to the ones created on your SCIM application.
   2. Click **Save Mappings** and **Apply updates now** to apply the changes.

   <div align="left" data-with-frame="true"><img src="/files/fTPyYlz9DdF61HtbFxnz" alt="" width="800"></div>
7. **The attributes should now be available to use on all your Okta application's users' profiles.** Once synced, you can view the credentials on Command under Access > Access Users > User Profile > Credentials.

   <div align="left" data-with-frame="true"><img src="/files/xhcQ3YmZPt7rWMA3w1Tf" alt="" width="800"></div>

</details>

<details>

<summary>Attribute table</summary>

Refer to this list of credentials for the list of [acceptable card formats](/access-control/installation/badge-reader-support/supported-card-formats). Data type for all attributes will be string.

<table><thead><tr><th width="128">Display Name</th><th>Variable Name / External Name</th><th>External Namespace</th><th>Description</th><th>ENUM</th></tr></thead><tbody><tr><td>Card Format</td><td><code>cardFormat</code></td><td><code>urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User</code></td><td>Card format for access credential</td><td>Leave unchecked</td></tr><tr><td>Card Number</td><td><code>cardNumber</code></td><td><code>urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User</code></td><td>Card number for access credential</td><td>Leave unchecked</td></tr><tr><td>Card Number Hex</td><td><code>cardNumberHex</code></td><td><code>urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User</code></td><td>Hexadecimal representation of the card number</td><td>Leave unchecked</td></tr><tr><td>Credential Status</td><td><code>credentialStatus</code></td><td><code>urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User</code></td><td>Status of the card credential</td><td>Checkbox: active → active, deactivated → deactivated, deleted → deleted</td></tr><tr><td>Facility Code</td><td><code>facilityCode</code></td><td><code>urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User</code></td><td>Facility code associated with the card</td><td>Leave unchecked</td></tr><tr><td>External ID</td><td><code>externalId</code></td><td><code>urn:ietf:params:scim:schemas:extension:verkada:core:2.0:User</code></td><td>Customer-defined unique ID, not exposed in UI</td><td>Leave unchecked</td></tr><tr><td>Department ID</td><td><code>costCenter</code></td><td><code>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User</code></td><td>Identifier used to map user's department in Command</td><td>Leave unchecked</td></tr><tr><td>Title</td><td><code>title</code></td><td><code>urn:ietf:params:scim:schemas:core:2.0:User</code></td><td>User's title or role</td><td>Leave unchecked</td></tr><tr><td>Employee Number</td><td><code>employeeNumber</code></td><td><code>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User</code></td><td>Employee ID</td><td>Leave unchecked</td></tr><tr><td>Phone Number</td><td><p>Variable Name: <code>phoneNumber</code><br></p><p>External Name: <code>phoneNumbers.^[type==work].value</code></p></td><td><code>urn:ietf:params:scim:schemas:core:2.0:User</code></td><td>Work phone number</td><td>Leave unchecked</td></tr><tr><td>Department</td><td><code>department</code></td><td><code>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User</code></td><td>User's department</td><td>Leave unchecked</td></tr><tr><td>Organization</td><td><code>organization</code></td><td><code>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User</code></td><td>Company or organization</td><td>Leave unchecked</td></tr></tbody></table>

</details>

***

**Provision users and groups**

{% hint style="warning" %}
Users added to the app push automatically; groups need to be pushed manually.
{% endhint %}

<details>

<summary>Users within Okta</summary>

1. Log in to Okta.
2. On the left, click Applications and click the Verkada app.
3. Click the Assignments tab.
4. Click the Assign dropdown and select Assign to People.
5. Click Assign for the people you want to provision to the app.
6. You'll see the information for that user. At the bottom, click Save and Go Back.
7. When you are redirected to the Assign page, click Done.

</details>

<details>

<summary>Groups within Okta</summary>

1. Log in to Okta.
2. On the left, click Applications and click the Verkada app.
3. Click the Assign dropdown and select Assign to Groups.
4. Click Assign for the groups you want to provision to the app.
5. You'll see the information for that group. At the bottom, click Save and Go Back.
6. When you are redirected to the Assign page, click Done.
7. At the top, select the Push Groups tab.
8. Click the Push Groups dropdown to find groups (by name or by rule).

   <div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/908982850/0e072e940214abd86eccae78/8375910_PushGroups2.png?expires=1766003400\&#x26;signature=c683ba9a537f5f61a445595354759205f7d05d3a013958409fa33d10e53b025e\&#x26;req=fSAvH8F8lYRfFb4f3HP0gBjiUrIpNNuxqoUP%2FsMKcUgdsP%2FBiZqRIbif1UoG%0Aack%3D%0A" alt="" width="800"></div>
9. Find the group you want to push and click Save. If successful, the Push Status shows Active.

   <div align="left" data-with-frame="true"><img src="https://verkada.intercom-attachments-7.com/i/o/886851187/ff3bcb4859a185c725971d13/XG0rEyG-XDWORuFFC5OnBuAAl8tUCxUnC-Kld0NoCJokuF5TFUGcUzWV_mvhwu8oB1rlI1RCg_RdNfl8d3vp41h2lbLGUnYWZJYhDPsNIx43BK16y4xlZlyyH-CQzJLAIvzS0nQqIeEWrnpXHLYUkO8?expires=1766003400\&#x26;signature=0246e57d8680e08596d6512b14df2c89c13364b4677a8339da387976b1684953\&#x26;req=fCghHsx%2FnIlYFb4f3HP0gFDQ0cgPnnmdT8g7G1F1L2o4ttgtkFgRDHzNIki%2B%0ABaM%3D%0A" alt="" width="800"></div>
10. Command then tags users and groups as SCIM Managed, if they are imported via SCIM.

<div align="left" data-with-frame="true"><img src="https://downloads.intercomcdn.com/i/o/908983529/77b17d99bdb427518624c0dd/8375910_PushGroups.png?expires=1766003400\&#x26;signature=03b70057ea0ac3881d86f24a8181488733242f8779814dd825870515992d05a8\&#x26;req=fSAvH8F9mINWFb4f3HP0gPMJ%2F1wgTqLZsR1nHZfRlffqmSaMW1oNhJjjRzd5%0ARYc%3D%0A" alt="" width="800"></div>

</details>

***

**Delete SCIM-managed users from Command**

When a SCIM-managed user is deactivated in your identity provider, you can remove the user from Command in two ways:

* **Delete the user** – The account moves to the Deleted Users page but keeps historical records, roles, and permissions.
* **Permanently remove the user** – All roles, credentials, access logs, and associated data are erased. If the user is re-provisioned via SCIM, Command creates a new user record.

{% hint style="warning" %}
You must deactivate the user in your identity provider (IdP) before either deletion option is available in Command.
{% endhint %}

***

**Troubleshooting**

* **If you run into this error while provisioning users,** *"Error while trying to push profile update for user: Bad Request. Errors reported by remote server: Invalid request",* see this [Okta article](https://support.okta.com/help/s/article/verkada-provisioning-error-error-while-trying-to-push-profile-update-for-user-bad-request-errors-reported-by-remote-server-invalid-request?language=en_US) for troubleshooting steps.
* **If you experience any other problems with setting up SCIM**, contact [Verkada Support](/command/need-help/contact-verkada-support).
  {% endtab %}
  {% endtabs %}


# Microsoft Entra ID

Configure SSO and user provisioning with Microsoft Entra ID (Azure AD)

Depending on your use case, [Verkada Command](/command/getting-started/get-started-with-verkada-command) has the ability to integrate with Microsoft Entra ID, amongst other Identity Providers \[IdPs], in the following capacities:

* OpenID Connect (OIDC)
* Security Assertion Markup Language (SAML)
* System for Cross-Domain Identity Management (SCIM)

**OIDC** and **SAML** both handle authentication, allowing Microsoft Entra ID to manage access to Command the same way it manages access to other SaaS applications in your environment. Both protocols let you integrate Command into your existing identity framework and authorize users in line with your current policies.

**SCIM** allows you to leverage your existing users and groups in Microsoft Entra ID and synchronize them with Command. This allows you to retain the current central IdP and configure permissions in Command using your existing users and groups.

{% hint style="info" %}
Verkada recommends OIDC over SAML for enhanced security and easier configuration. OIDC also enables [Enterprise Controlled Encryption](/command/security/enterprise-controlled-encryption).
{% endhint %}

| Feature                | Supported |
| ---------------------- | :-------: |
| OIDC SSO               |    Yes    |
| SAML SSO               |    Yes    |
| SCIM User Provisioning |    Yes    |
| ECE Support            |    Yes    |

***

{% tabs %}
{% tab title="OIDC (Recommended)" %}

#### OIDC Based SSO for Microsoft Entra ID

Verkada Command supports Single Sign-On (SSO) through OpenID Connect (OIDC) with Microsoft Entra ID. This integration allows our users to seamlessly and securely authenticate using their existing Microsoft Entra ID credentials, streamlining access to Command and enhancing overall security.

{% hint style="info" %}
Enable [Enterprise Controlled Encryption (ECE)](/command/security/enterprise-controlled-encryption) for enhanced security.
{% endhint %}

***

**Microsoft Entra ID configuration**

{% stepper %}
{% step %}
**Log in to your** [**Microsoft Entra ID portal**](https://portal.azure.com)**.**
{% endstep %}

{% step %}
**Search for and select App registrations.**
{% endstep %}

{% step %}
**Click New Registration.**

a. Name the application **Verkada SSO OIDC.**\
b. Under **Supported account types,** select **Accounts in this organizational directory only ( only - Single tenant).**\
c. Under **Redirect URI**, select **Single-page application** (SPA) as the platform and add the following callback URLs:

1. <https://command.verkada.com/oidc/aad/callback>
2. [https://org-short-name.command.verkada.com/oidc/aad/callback](http://org-short-name.command.verkada.com/oidc/aad/callback) (replace org-short-name in the URI with your Command organization's short-name.)

{% hint style="warning" %}
Verify there is no trailing slash in the callback URI.
{% endhint %}
{% endstep %}

{% step %}
**Click Register.**
{% endstep %}

{% step %}
**Copy and store your Application (Client) ID and Directory (Tenant) ID in a safe place. You will need them to complete the setup in Verkada Command.**
{% endstep %}

{% step %}
**On the left, click Manage > Expose an API.**

a. Click **Add a scope.**\
b. Click **Save and continue**.\
c. Enter *verkada\_ece* for the following fields:

* Scope name
* Admin consent display name
* Admin consent description
* User consent display name
* User consent description

d. Set **Who can consent?** to **Admins and users.**\
e. Click **Add scope.**

<div align="left" data-with-frame="true"><img src="/files/08IEDuHbg9K0H6n6vNJP" alt="" width="800"></div>
{% endstep %}
{% endstepper %}

***

**Verkada Command configuration**

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access.**
{% endstep %}

{% step %}
**Select Single Sign-On Configuration.**
{% endstep %}

{% step %}
**Under OIDC Configuration, click Add New.**

a. Toggle on **Enable.**\
b. (Optional) Toggle on **Require OIDC SSO.**\
c. Under **Select Provider,** select **Microsoft Entra ID.**\
d. Under **Add Client and Tenant,** click :plus:.

1. In the **Client ID** field, paste the Client ID you copied from Microsoft Entra ID.
2. In the **Tenant ID** field, paste the Tenant ID you copied from Microsoft Entra ID.
3. Click **Done**.

e. Under **Email Domains,** click :plus:**.**

1. Enter your domain name present (e.g., @verkada.com).
2. Click **Done**.

   <div align="left" data-with-frame="true"><img src="/files/ntREdy9QuYSSp2bzdKya" alt="" width="215"></div>

{% endstep %}

{% step %}
**Click Run Login Test.**
{% endstep %}

{% step %}
**A successful login test should redirect to the OIDC configuration page. Once you're logged in, add the domain that you need to whitelist.**
{% endstep %}

{% step %}
**Once your domain is added, run the login test again. SSO will not be enabled until this second login test successfully completes.**
{% endstep %}

{% step %}
**Once your domain is verified, you should see it successfully validated.**
{% endstep %}
{% endstepper %}

***

#### Log in via the mobile application

{% hint style="info" %}
The Android and iOS Command apps support OIDC-based login.
{% endhint %}

{% stepper %}
{% step %}
**Open your Command app.**
{% endstep %}

{% step %}
**In the email address field, enter your email and click Next.**
{% endstep %}

{% step %}
**You should be redirected to your IdP (Microsoft Entra ID) to complete the login process.**
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="SAML" %}

### Microsoft Entra ID SAML Integration

***

#### Set up SAML in Microsoft Entra ID

Verkada Command is registered as a gallery application and can be found within the Microsoft Entra ID marketplace; in other words, you can leverage it with Microsoft Entra ID Free, Microsoft Entra ID P1, and Microsoft Entra ID P2 licenses.

{% hint style="danger" %}
To get started, you need your `client-ID`. Learn how to [generate it and configure your email domains](/command/security/identity-providers#generate-client-id), then return to this article to complete the remainder of this process.
{% endhint %}

{% stepper %}
{% step %}
**Add Verkada Command as an enterprise application in your Microsoft Entra ID directory: Go to your Microsoft Entra ID overview page and select Enterprise applications.**

<div align="left" data-with-frame="true"><img src="/files/5rXicOsbBtY1O7y3gdMB" alt="" width="603"></div>
{% endstep %}

{% step %}
**At the top of the page, select New Application and search for Verkada Command.**
{% endstep %}

{% step %}
**Select Verkada Command and click Create.&#x20;*****Be patient as it can take a few minutes to add the application to your*****&#x20;Microsoft Entra ID&#x20;*****tenant*****.**

<div align="left" data-with-frame="true"><img src="/files/4u2oSeLJVd2qcjlpUVeK" alt="" width="629"></div>

Once the page refreshes, you should see a similar menu (as shown below).
{% endstep %}

{% step %}
**On Set up single sign-on, click Get started.**

<div align="left" data-with-frame="true"><img src="/files/rjRfY7f2kvMeRyZC6ffU" alt="" width="389"></div>
{% endstep %}

{% step %}
**Choose SAML as the single sign-on method.**

<div align="left" data-with-frame="true"><img src="/files/iswrFGEuZp9oak9U3UxB" alt="" width="376"></div>
{% endstep %}

{% step %}
**If necessary, click Edit to further configure your SAML connection.**
{% endstep %}

{% step %}
**Configure the following fields. You need to add your client ID to the end of each URL before adding them to Microsoft Entra ID. See example below the note.**

a. For **Identifier**:\
For US orgs: <https://vauth.command.verkada.com/saml/sso>\
For EU orgs: <https://saml.prod2.verkada.com/saml/sso>For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso>

b. For **Reply URL**:\
For US orgs: <https://vauth.command.verkada.com/saml/sso>\
For EU orgs: <https://saml.prod2.verkada.com/saml/sso>\
For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso>

c. For **Sign on URL**:\
For US orgs: <https://vauth.command.verkada.com/saml/login>\
For EU orgs: [https://saml.prod2.verkada.com/saml/login](https://saml.prod2.verkada.com/saml/login/)\
For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso>

{% hint style="warning" %}
To confirm which region you're located, please refer to where [your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}

<div align="left" data-with-frame="true"><img src="/files/ytfRssGaIPSpH7NqhaLx" alt="" width="561"></div>
{% endstep %}

{% step %}
**Click Save.**
{% endstep %}

{% step %}
**On Attributes & Claims, click Edit to be consistent with these attributes:**

<div align="left" data-with-frame="true"><img src="/files/IfCFPfiF95hrpCfN36kp" alt="" width="806"></div>

{% hint style="warning" %}
If you use a different source attribute for email, configure the attributes according to the source attribute you want to use.
{% endhint %}
{% endstep %}

{% step %}
**On SAML Signing Certificate, import this Federation Metadata XML into Command.**
{% endstep %}

{% step %}
**Click Download to save for later.**

<div align="left" data-with-frame="true"><figure><img src="/files/lOTGZscMZ3S8fwNA2fRC" alt="" width="375"><figcaption></figcaption></figure></div>

{% hint style="info" %}
The next dialogs that appear will contain tools you can use after the integration is finalized.
{% endhint %}
{% endstep %}

{% step %}
**Continue to Verkada Command to** [**complete the configuration**](/command/security/identity-providers#command-sso-configuration)**.**
{% endstep %}
{% endstepper %}

***

#### Test the SAML connection in Microsoft Entra ID

{% stepper %}
{% step %}
**Once the file is uploaded, in your Microsoft Entra ID, click Test to test the integration. A notification will be sent to all users who have a Command account (invitation to org).**

<div align="left" data-with-frame="true"><img src="/files/Y7nlpIxjLEkIqPTkydSk" alt="" width="763"></div>
{% endstep %}

{% step %}
**Log in with Sign in as current user. If everything is set up correctly, you should be redirected to the Command platform.**
{% endstep %}

{% step %}
**Log in with single sign-on to verify access to Command.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Microsoft Entra ID does not support nested groups for app access at this time. All users must be direct members of groups to be assigned.
{% endhint %}

***

#### Log in via the mobile application

{% hint style="info" %}
The Android and iOS Command apps support SAML-based login.
{% endhint %}

{% stepper %}
{% step %}
**Open your Command app.**
{% endstep %}

{% step %}
**In the email address field, enter your email and click Next.**
{% endstep %}

{% step %}
**You should be redirected to your IdP (Microsoft Entra ID) to complete the login process.**
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="User Provisioning (SCIM)" %}

#### Microsoft Entra ID SCIM Integration

Verkada Command integrates with Microsoft Entra ID using System for Cross-Domain Identity Management (SCIM) for automated user and group provisioning.

SCIM synchronizes users and groups from Microsoft Entra ID directly into Command. This lets you:

* Retain Microsoft Entra ID as your central IdP.
* Automatically update users and groups in Command as changes occur in Entra ID.
* Assign and manage permissions in Command using your existing identity structure.

{% hint style="info" %}
If your organization uses SCIM, phone numbers can only be provisioned through SCIM. You will not be able to edit your phone number directly in Command.
{% endhint %}

***

**SCIM in Microsoft Entra ID configuration**

Before you configure SCIM in Microsoft Entra ID, you need to generate your secret token in Command.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Login & Access & Logs > SCIM Users Provisioning.**
{% endstep %}

{% step %}
**Click Add Domain, and enter all relevant email domains you plan to use with SCIM.**

This generates a SCIM token, **which is viewable only once.**

a. Click **Copy** and store the token in a secure place to use later in the configuration.\
b. Click [**Refresh**](/command/security/identity-providers/scim-token-management) to generate a new token if you did not copy your token or it is not visible.
{% endstep %}

{% step %}
**From the Microsoft Entra ID homepage, select Enterprise applications > New application > Create your own application.**
{% endstep %}

{% step %}
**In the Create your own application side panel, type the application's name, select "Integrate any other aplication you don't find in the gallery (Non-gallery)", and click Create.**

{% hint style="warning" %}
Do not select the Verkada Command application. This is a pre-configured SAML only application.
{% endhint %}

<div align="left" data-with-frame="true"><img src="/files/Pmdpo0QktxnvFfXbwo3L" alt="" width="638"></div>
{% endstep %}

{% step %}
**Under Provision User Accounts, click Get started.**

<div align="left" data-with-frame="true"><img src="/files/UVfLCRFi0RKCTejeqWui" alt="" width="380"></div>
{% endstep %}

{% step %}
**Select Manage > Provisioning.**
{% endstep %}

{% step %}
**On the provisioning page:**

a. Set the Provisioning Mode to Automatic.\
b. Set the Tenant URL as:

* For US orgs: <https://api.command.verkada.com/scim>
* For EU orgs: <https://scim.prod2.verkada.com/scim>
* For AUS orgs: <https://scim.prod-ap-syd.verkada.com/scim>

{% hint style="warning" %}
To confirm which region you're located in, [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}

f. Fill in the SCIM *token* generated in Verkada Command (step 2) as the secret token.

<div align="left" data-with-frame="true"><img src="/files/qMVbi6hcrnoES2emerkX" alt="" width="570"></div>
{% endstep %}

{% step %}
**Click Test Connection. You should see a confirmation that the SCIM connection is successful.**

<div align="left" data-with-frame="true"><img src="/files/waff2TfzQKcYgOJkszCE" alt="" width="184"></div>
{% endstep %}

{% step %}
**Click Save.**
{% endstep %}
{% endstepper %}

***

**Configure attributes for Microsoft Entra ID groups**

{% stepper %}
{% step %}
**In the Entra ID portal, click to expand the Mappings dropdown, and select Provision Microsoft Entra ID Groups.**

<div align="left" data-with-frame="true"><img src="/files/0W8NifBdbzcNmUVg5hUz" alt="" width="353"></div>
{% endstep %}

{% step %}
**Configure your mappings to match this screenshot of the data table:**

<div align="left" data-with-frame="true"><img src="/files/2BJzoMksgC7P982jyNlE" alt="" width="741"></div>

{% hint style="warning" %}
The **externalId** attribute is added by default. Remove this attribute to avoid issues with the configuration.
{% endhint %}
{% endstep %}

{% step %}
**(Optional) If you need to add a mapping:**

a. Click **Add New Mapping** > select the **Source attribute** to match the Microsoft Entra ID attribute above.\
b. Set the **Target attribute** to match the **customappsso** attribute above.\
c. Click **OK**.
{% endstep %}

{% step %}
**Click Save and confirm changes, if necessary.**
{% endstep %}

{% step %}
**At the top of the page, select Provisioning to return to the Provisioning page.**
{% endstep %}
{% endstepper %}

***

**Configure attributes for Microsoft Entra ID users**

{% stepper %}
{% step %}
**In the Entra ID portal, click to expand the Mappings dropdown, then select Provision Microsoft Entra ID Users to change the user mappings.**
{% endstep %}

{% step %}
**Update your mappings to match the attribute table below.**

| customappsso Attribute                                                      | Microsoft Entra ID Attribute                                 |
| --------------------------------------------------------------------------- | ------------------------------------------------------------ |
| `userName`                                                                  | mail                                                         |
| `active`                                                                    | Switch(\[IsSoftDeleted], , "False", "True", "True", "False") |
| `title`                                                                     | jobTitle                                                     |
| `name.givenName`                                                            | givenName                                                    |
| `name.familyName`                                                           | surname                                                      |
| `phoneNumbers[type eq "work"].value`                                        | telephoneNumber                                              |
| `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber` | employeeId                                                   |
| `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization`   | companyName                                                  |
| `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department`     | department                                                   |
| `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:costCenter`     | costCenter                                                   |

{% hint style="warning" %}
The **Switch** attribute under Microsoft Entra ID Attribute is added as an **Expression** mapping type.
{% endhint %}

{% hint style="warning" %}
Source Attribute is the Microsoft Entra ID Attribute, and Target Attribute is the customappsso Attribute. If any of the **customappsso** attributes are not available as Target Attributes, you may need to add them to your Microsoft Entra ID platform as options. To do so, check the **Show advanced options** box and click **Edit attribute list for customappsso**.
{% endhint %}
{% endstep %}

{% step %}
**Click Save to confirm the changes.**
{% endstep %}

{% step %}
**At the top, select Provisioning and toggle on Provisioning Status.**

<div align="left" data-with-frame="true"><img src="/files/v480VUJzZYjuVbcEJaUm" alt="" width="528"></div>
{% endstep %}

{% step %}
**Depending on the requirements, adjust the scope to one of the required options:**

* Sync all users and groups.
* Sync only assigned users and groups.

{% hint style="warning" %}
Ensure users and groups are assigned to the enterprise application under Users and Groups. Those assigned are the ones provisioned and present in Command.
{% endhint %}
{% endstep %}

{% step %}
**Verify that users are assigned to the application. Once the initial provisioning cycle has elapsed:**

a. You should see the total number of users and groups that have been provisioned successfully under **Overview**.\
b. In Command, you should see these users and groups populated with the associated **SCIM Managed** tag. These synchronized users and groups can now be used in Command and assigned permissions to control access to the Command platform.

<div align="left" data-with-frame="true"><img src="/files/Zr7scxmJrZXaz4bh46rL" alt="" width="1449"></div>
{% endstep %}
{% endstepper %}

**Delete SCIM-managed users from Command**

When a SCIM-managed user is deactivated in your identity provider, you can remove the user from Command in two ways:

* **Delete the user** – The account moves to the Deleted Users page but keeps historical records, roles, and permissions.
* **Permanently remove the user** – All roles, credentials, access logs, and associated data are erased. If the user is re-provisioned via SCIM, Command creates a new user record.

{% hint style="warning" %}
You must deactivate the user in your identity provider (IdP) before either deletion option is available in Command.
{% endhint %}

***

**(Optional) Add access credentials to SCIM users**

{% stepper %}
{% step %}
**Log in to your** [**Azure portal**](https://portal.azure.com)**.**
{% endstep %}

{% step %}
**In the search bar, type and select Enterprise Applications.**
{% endstep %}

{% step %}
**Select your Verkada SCIM application.**
{% endstep %}

{% step %}
**On the left panel, click Manage > Provisioning.**
{% endstep %}

{% step %}
**Expand the Mappings submenu and select Provision Microsoft Entra ID Users.**
{% endstep %}

{% step %}
**At the bottom, click Show advanced options > Edit attribute list for customappsso.**

a. Add the attributes from the table below.\
b. Click **Save**.
{% endstep %}

{% step %}
**Go back to Provision Microsoft Entra ID Users and select Add New Mapping.**

a. Use extensionAttributes 1-5 as **Source Attributes** and map them to the new attributes created for **Card Format, Card Number, Card Number Hex, Credential Status,** and **Facility Code** as the target attributes.

1. Reference [Acceptable Card Formats](/access-control/installation/badge-reader-support/supported-card-formats) for accepted card formats and their associated facility code, card number, and/or card number hex lengths.
2. **Credential Status** can be "active", "deactivated", or "deleted"
3. Click **Save**.

b. To sync a department identifier, add a new mapping with your desired source attribute (e.g., department or a custom extension attribute) and set the target attribute to costCenter (`urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:costCenter`). This syncs a department ID value to Command.
{% endstep %}
{% endstepper %}

**Attribute table**

| Name                                                                              | Type   |
| --------------------------------------------------------------------------------- | ------ |
| `urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User:cardFormat`       | String |
| `urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User:cardNumber`       | String |
| `urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User:cardNumberHex`    | String |
| `urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User:credentialStatus` | String |
| `urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User:facilityCode`     | String |
| `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:costCenter`           | String |

**Edit the App Registration**

Every SCIM enabled Enterprise Application created on Entra AD typically requires its own App Registration.

{% stepper %}
{% step %}
**In the search bar, type and select App registrations.**
{% endstep %}

{% step %}
**Switch to the All Applications tab and search for the name of your Verkada SCIM application.**
{% endstep %}

{% step %}
**On Overview, note your App Registration's Application (client) ID and Directory (tenant) ID. You will need these later to configure credentials for your Command application from your app registration.**
{% endstep %}

{% step %}
**On the left navigation, click Manage.**

a. Under **Certificates & secrets:**

1. Click **New client secret**.
2. Set the **Description** to "*Verkada SCIM Credentials"* and set your preferred certificate expiration date.
3. Copy and store the value displayed in the **Value** of the new Client Secret created. **This will only be displayed once.**

e. Under **API Permissions**:

1. Click **Add Permissions > Microsoft Graph.**
2. Select **Application Permissions** and search for "*User.ReadWrite.All*".
   1. Check the box to assign the permissions.
   2. Click **Add Permissions**.

      <div align="left" data-with-frame="true"><img src="/files/Honc9HhrvFUaaP9nxRpt" alt="" width="774"></div>
3. To avoid having to manually review and approve all stage changes communicated between Microsoft Entra ID and your Command application, select **Grant admin consent for Default Directory**.

   <div align="left" data-with-frame="true"><img src="/files/JJhJuqJR5iSMN4k6tVsa" alt="" width="512"></div>

{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Refer to this list of credentials for [acceptable card formats](/access-control/installation/badge-reader-support/supported-card-formats).
{% endhint %}

**Access and update your credentials**

To set the extension attributes and the credential information for a particular user, use the Graph API instructions at: <https://learn.microsoft.com/en-us/graph/extensibility-overview>.

{% hint style="warning" %}
Setting the **credentialStatus** attribute to **active** when setting up a credential for a user is necessary to successfully sync credentials with Command. Where credential status (credentialStatus) is extensionAttribute4.
{% endhint %}

Example:

```
curl --location --request PATCH 'https://graph.microsoft.com/v1.0/users/<UserID>' \
--header 'Authorization: Bearer <secure token>' \
--header 'Content-Type: application/json' \
--data '{
    "onPremisesExtensionAttributes": {
        "extensionAttribute1": "Standard 26-bit Wiegand",
        "extensionAttribute2": "7777",
        "extensionAttribute3": "7",
        "extensionAttribute4": "active",
        "extensionAttribute5": "111"
    }
}'
```

***

**Sync External ID to Verkada**

The `externalId` field allows you to assign a persistent, globally unique identifier to your users through Microsoft Entra that Verkada can reference across integrations. This is especially useful for large enterprise environments where users may need to be disambiguated across systems, or where syncing credentials (e.g., access cards) must be tied to a unique identity key. Verkada supports receiving and storing this value as part of its SCIM user schema. The field is case-sensitive and is typically configured to accept a string value from a designated attribute in your Microsoft Entra instance. This feature supports advanced workflows such as custom credential management, employee lifecycle automation, and consistent user mapping across orgs.

**Map externalId from Azure to Verkada**

To sync a custom externalId value from Microsoft Entra ID (Azure) to Verkada, follow these steps:

{% stepper %}
{% step %}
Log in to your **Azure portal.**
{% endstep %}

{% step %}
In the search bar, type and select **Enterprise Applications.**
{% endstep %}

{% step %}
Select your **Verkada SCIM application.**
{% endstep %}

{% step %}
On the left panel, click **Manage > Provisioning.**
{% endstep %}

{% step %}
Expand the **Mappings** submenu and select **Provision Microsoft Entra ID Users.**
{% endstep %}

{% step %}
Scroll to the bottom and click **Show advanced options > Edit attribute list for customappsso.**
{% endstep %}

{% step %}
**Add the following new attribute:**

`urn:ietf:params:scim:schemas:extension:verkada:core:2.0:User:externalId`

* Type: String
* Case-sensitive: Yes
  {% endstep %}

{% step %}
**Click Save.**
{% endstep %}

{% step %}
Go back to **Provision Microsoft Entra ID Users** and click **Add New Mapping.**
{% endstep %}

{% step %}
For **Source Attribute**, select the field from Azure AD where your external ID is stored (e.g., `extensionAttribute1`, `employeeId`, etc.).
{% endstep %}

{% step %}
For **Target Attribute**, use: `urn:ietf:params:scim:schemas:extension:verkada:core:2.0:User:externalId`
{% endstep %}

{% step %}
**Click OK and then Save.**
{% endstep %}
{% endstepper %}

Once provisioned, the external\_id value will be stored in the user's SCIM record within Verkada. This provides users with a flexible, API-queryable ID that remains unique to their org and fully under their control, without being tied to Verkada's internal identifiers or exposed in the user interface.

![](/files/fZYiZmFectsjXP3fgFpK)
{% endtab %}
{% endtabs %}


# Google Workspace

Configure SSO and user provisioning with Google Workspace

Depending on your use case, [Verkada Command](/command/getting-started/get-started-with-verkada-command) has the ability to integrate with Google Workspace, amongst other Identity Providers \[IdPs], in the following ways:

* OpenID Connect (OIDC)
* Security Assertion Markup Language (SAML)
* User and group provisioning

**OIDC** and **SAML** both handle authentication, allowing Google Workspace to manage access to Command the same way it manages access to other SaaS applications in your environment. Both protocols let you integrate Command into your existing identity framework and authorize users in line with your current policies.

**User and group provisioning** keeps your Google Workspace users and groups in sync with Command. Command provides a native Google Workspace integration that syncs users and groups from your selected organizational units and groups into Command. Other identity providers can use SCIM 2.0 for the same outcome.

{% hint style="info" %}
Verkada recommends OIDC over SAML for enhanced security and easier configuration.
{% endhint %}

***

{% tabs %}
{% tab title="OIDC (Recommended)" %}

## OIDC Based SSO for Google Workspace

Verkada Command supports Single Sign-On (SSO) through OpenID Connect (OIDC) with Google Workspace. This integration allows our users to seamlessly and securely authenticate using their existing Google credentials, streamlining access to Command and enhancing overall security.

{% hint style="info" %}
Enable [Enterprise Controlled Encryption (ECE)](/command/security/enterprise-controlled-encryption) for enhanced security.
{% endhint %}

***

### OIDC configuration

{% stepper %}
{% step %}
**Log in to your** [**Google Cloud console**](https://console.cloud.google.com/)**.**
{% endstep %}

{% step %}
**Click New Project to create a new project under your Google Workspace organization.**

<div align="left" data-with-frame="true"><img src="/files/2BVb4ndSS4LPBj0w1Ks4" alt="" width="697"></div>
{% endstep %}

{% step %}
**In your new project, navigate to APIs & Services > Library.**

<div align="left" data-with-frame="true"><img src="/files/z7NBna4Tan7xwnYI6XXs" alt="" width="800"></div>

a. Enable the following APIs:

1. Identity and Access Management (IAM) API

   <div align="left" data-with-frame="true"><img src="/files/3GkTjisuACJdL0yHNi6f" alt="" width="607"></div>
2. Admin SDK API

   <div align="left" data-with-frame="true"><img src="/files/8dq5XHCsW5af8pr0Hu6b" alt="" width="577"></div>

{% endstep %}

{% step %}
**Navigate to APIs & Services > OAuth Consent Screen. Select Internal for the User Type and click Create.**

<div align="left" data-with-frame="true"><img src="/files/drLIW7np9UH4ROqhb2KA" alt="" width="800"></div>
{% endstep %}

{% step %}
**Click Edit App.**

<div align="left" data-with-frame="true"><img src="/files/D1NHRPP2Wj1L9W8L06hR" alt="" width="800"></div>
{% endstep %}

{% step %}
**Configure your OAuth Consent Screen. Give your app an identifiable name (e.g., Verkada SSO OIDC), and put the email of the entity that manages your organization's Google Workspace (e.g., IT) as your app's user support email. Click Save and Continue.**

<div align="left" data-with-frame="true"><img src="/files/qTQcPilxYoYhonhfw5uw" alt="" width="800"></div>
{% endstep %}

{% step %}
**Configure your OAuth Scopes.**

<div align="left" data-with-frame="true"><img src="/files/stlhTDoVyxG8ZDEnsPwt" alt="" width="800"></div>
{% endstep %}

{% step %}
**Select the following scopes:**

* userinfo.email
* userinfo.profile
* openid
* <https://www.googleapis.com/auth/admin.directory.user.readonly>
  {% endstep %}

{% step %}
**Click Update.**

<div align="left" data-with-frame="true"><img src="/files/QPMLHxdymqwgxCnpz6II" alt="" width="669"></div>

If you do not see the last option, you may have to **Add To Table** under **Manually add scopes**.

<div align="left" data-with-frame="true"><img src="/files/uT2N8PdcgbVpnUFB64ep" alt="" width="659"></div>
{% endstep %}

{% step %}
**Click Save and Continue and return to your application's dashboard.**
{% endstep %}

{% step %}
**Navigate to Credentials. Click Create Credentials and create an OAuth client ID.**

<div align="left" data-with-frame="true"><img src="/files/73xqN9Nro6asbKOaJNk7" alt="" width="621"></div>
{% endstep %}

{% step %}
**Select Web application as your application type. Give your client an identifiable name, and add the following to the list of authorized redirect URIs:**

* <https://command.verkada.com/oidc/google/callback>
* [https://org-short-name.command.verkada.com/oidc/google/callback](http://org-short-name.command.verkada.com/oidc/google/callback) (where org-short-name is the short-name for your Command organization)

Click **Create**.

<div align="left" data-with-frame="true"><img src="/files/3BpND9gbQgmCpllfmKwk" alt="" width="407"></div>
{% endstep %}

{% step %}
**Copy your Client ID. Note that we will not be using the Client secret.**

<div align="left" data-with-frame="true"><img src="/files/YiaAvZbs013G9G7z0MB3" alt="" width="474"></div>
{% endstep %}
{% endstepper %}

***

### Verkada Command Configuration

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Login & Access.**
{% endstep %}

{% step %}
**Select Single Sign-On Configuration.**
{% endstep %}

{% step %}
**Under OIDC Configuration, click Add New.**

a. Toggle on **Enable.**\
b. (Optional) Toggle on **Require OIDC SSO.**\
c. Under **Select Provider**, select **Google**.\
d. Under **Add Client and Tenant,** click :plus:.

1. In the **Client ID** field, paste the Client ID you copied from Google Cloud Console.
2. In the **Tenant ID** field, enter the domain used by your organization's Google Workspace (if your Google email is <example@your-domain.com>, enter your-domain.com).
3. Click on **Done** to complete the configuration.

   <div align="left" data-with-frame="true"><img src="/files/jFg8zNgH2GXkH7T06YK9" alt="" width="476"></div>

h. **Email Domains,** click :plus:**.**

1. Enter your domain name present (e.g. @verkada.com).
2. Click **Done**.

   <div align="left" data-with-frame="true"><img src="/files/ntREdy9QuYSSp2bzdKya" alt="" width="215"></div>

{% endstep %}

{% step %}
**Under Login Test click Run Login Test.**
{% endstep %}

{% step %}
**A successful login test should redirect to the OIDC configuration page. Once you're logged in, add the domain that you need to whitelist under Associated Domains.**
{% endstep %}

{% step %}
**Once your domain is added, run the login test again. SSO will not be enabled until this second login test successfully completes.**
{% endstep %}

{% step %}
**Once your domain is verified, you should see it successfully validated.**
{% endstep %}
{% endstepper %}

***

### Log in via the mobile application

{% hint style="info" %}
Command on Android and iOS supports login through OIDC.
{% endhint %}

{% stepper %}
{% step %}
**In the email address field, type the user's email and click Next.**
{% endstep %}

{% step %}
**You should be redirected to your IdP (Google Workspace) to complete the login process.**
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="SAML" %}

## Google Workspace SAML Integration

Verkada Command has the ability to integrate with Google Workspace (among other Identity Providers \[IdPs]) for single sign-on (SSO) scenarios.\
\
Security Assertion Markup Language (SAML) handles the authentication side of things to allow Google Workspace to be used to manage access to Command.

***

#### Before you begin

{% stepper %}
{% step %}
**Ensure you have already registered on Verkada Command and an account exists for the user in the same custom domain. You can add Command as a custom application.**
{% endstep %}

{% step %}
**Familiarize yourself with these terms to maximize your integration:**

* **Client ID**—Client ID. To locate, go to **Admin > Privacy & Security > Single Sign-On Configuration > Add New**.
* **Federation Data XML**—The unique information from your Google Workspace instance that allows Verkada to set up the federation between Google Workspace and your Command instance (the steps to download this are provided later).
  {% endstep %}
  {% endstepper %}

***

### Google Workspace Configuration

{% stepper %}
{% step %}
**Go to Google Workspace > Google Admin dashboard and select Web and mobile apps.**

<div align="left" data-with-frame="true"><img src="/files/1YjHNqxu49eRTkYma9zw" alt="" width="882"></div>
{% endstep %}

{% step %}
**Select the Add app dropdown and select Add custom SAML app.**

<div align="left" data-with-frame="true"><img src="/files/DWFYOmZG70puYhstl7Qk" alt="" width="620"></div>
{% endstep %}

{% step %}
**Fill in the application information; you can use any name and description.**
{% endstep %}

{% step %}
**Get the** [**Verkada Command logo**](https://downloads.intercomcdn.com/i/o/115376791/162cbb458c1ceefd1aeed502/Verkada_logoSymbol_256x256+\(3\).png?expires=1759590000\&signature=c65fe8ed71111e37e851aeca0ee3054c090c8a01e3e24bf77816092e5bf0102b\&req=dSEiFc54moheFb4X1HO4gYAM81kpwT1YtLg28NWB3RV5Y2yu8G8cCA13ulLf%0A) **to add to your Google Workspace application.**
{% endstep %}

{% step %}
**Click Continue.**

<div align="left" data-with-frame="true"><img src="/files/pqpp04nSe4jhKHEkG2yW" alt="" width="515"></div>
{% endstep %}

{% step %}
**Use Option 1 to download the IdP metadata that corresponds to the federation metadata Extensible Markup Language (XML) and click Continue.**

<div align="left" data-with-frame="true"><img src="/files/9kpXUnvbB1uEyBZCIVwd" alt="" width="515"></div>

{% hint style="warning" %}
This file allows Verkada to configure SSO in Command. Save it in a convenient location for future use.
{% endhint %}
{% endstep %}

{% step %}
**Type the service provider details (as shown) to configure SSO or, you can copy the details from the New SSO Configuration page (in Verkada Command), and click Continue.**

a. For **ACS URL**:\
For US orgs: [https://vauth.command.verkada.com/saml/sso/\<client-id>](https://vauth.command.verkada.com/saml/sso/%3Cclient-id%3E)\
For EU orgs: [https://saml.prod2.verkada.com/saml/sso/\<client-id>](https://saml.prod2.verkada.com/saml/sso/%3Cclient-id%3E)\
For AUS orgs: [https://saml.prod-ap-syd.verkada.com/saml/sso/\<client-id>](https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-id%3E)\
b. For **Entity ID**:\
For US orgs: [https://vauth.command.verkada.com/saml/sso/\<client-id>](https://vauth.command.verkada.com/saml/sso/%3Cclient-id%3E)\
For EU orgs: [https://saml.prod2.verkada.com/saml/sso/\<client-id>](https://saml.prod2.verkada.com/saml/sso/%3Cclient-id%3E)\
For AUS orgs: [https://saml.prod-ap-syd.verkada.com/saml/sso/\<client-id>](https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-id%3E)\
c. For **Start URL**:\
For US orgs: [https://vauth.command.verkada.com/saml/login/\<client-id>](https://vauth.command.verkada.com/saml/login/%3Cclient-id%3E)\
For EU orgs: [https://saml.prod2.verkada.com/saml/login/\<client-id>](https://saml.prod2.verkada.com/saml/login/%3Cclient-id%3E)\
For AUS orgs: [https://saml.prod-ap-syd.verkada.com/saml/login/\<client-id>](https://saml.prod-ap-syd.verkada.com/saml/login/%3Cclient-id%3E)

{% hint style="warning" %}
[Refer to where your organization was created](/command/getting-started/get-started-with-verkada-command) to confirm which region your organization is located.
{% endhint %}
{% endstep %}

{% step %}
**Fill in the Attributes mappings (as shown below) and click Finish. This ensures that Command receives the correct information about the user. You should be redirected to the app configuration page.**

<div align="left" data-with-frame="true"><img src="/files/4SvNKbocXCusIB2wgQIO" alt="" width="515"></div>
{% endstep %}
{% endstepper %}

***

### Command Configuration

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select Login & Access > Single Sign On (SSO).**
{% endstep %}

{% step %}
**Click Add to start a new configuration or to edit an existing configuration.**
{% endstep %}

{% step %}
**Under Identity Provider XML Metadata, upload your metadata file.**
{% endstep %}

{% step %}
**Under Email Domains, add the email domains that will be used to log in to your organization.**
{% endstep %}

{% step %}
**Verify that you can access Command at one of these URLs (substitute the&#x20;*****client-id*****&#x20;with the one used during setup).**

* For US orgs: [https://vauth.command.verkada.com/saml/login/\<client-id>](https://vauth.command.verkada.com/saml/login/%3Cclient-id%3E)
* For EU orgs: [https://saml.prod2.verkada.com/saml/login/\<client-id>](https://saml.prod2.verkada.com/saml/login/%3Cclient-ID%3E)
* For AUS orgs: [https://saml.prod-ap-syd.verkada.com/saml/sso/\<client-id>](https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E)

{% hint style="warning" %}
See **Admin > Data Privacy > Data Residency > Data Processing Location** to confirm where your region is located.
{% endhint %}
{% endstep %}

{% step %}
**You'll be redirected to the Google Workspace app configuration page to complete the login.**
{% endstep %}
{% endstepper %}

***

### Log in via the mobile application

{% hint style="info" %}
Command on Android and iOS supports login through SAML.
{% endhint %}

{% stepper %}
{% step %}
**In the email address field, type the user's email and click Next.**
{% endstep %}

{% step %}
**You should be redirected to your IdP (Google Workspace) to complete the login process.**
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="User Provisioning" %}

## Google Workspace User Provisioning

The Google Workspace native integration allows organizations to automatically sync users and groups from Google Workspace into Verkada Command. This simplifies identity management and general user onboarding.

Unlike Verkada's SCIM integrations with Okta or Azure, this integration uses the Google Workspace Admin SDK and Reports API, authenticated through a Google service account with domain-wide delegation.

With the integration enabled, Command can:

* Import users and groups from selected Google Workspace Groups or Organizational Units (OUs)
* Sync them into Command as managed users and groups
* Maintain directory accuracy with scheduled background syncs and on-demand syncs from the Admin UI

***

### Create a Google service account

To allow Command to read user and group data from your Google Workspace domain, it must authenticate with Google's APIs using a service account. This type of account is designed for programmatic access and must be configured with the correct API scopes and domain-wide delegation. These settings are configured in your [Google Cloud console](https://console.cloud.google.com/?hl=en-au) account.

#### Verify policies & roles

You must first verify whether your user has permissions to create a service account and to generate the service account JSON Key. To ensure you are not blocked by security policies in your tenant:

{% stepper %}
{% step %}
**Go to the** [**Google Cloud console**](https://console.cloud.google.com/?hl=en-au) **and sign in with your Super Admin credentials.**
{% endstep %}

{% step %}
**In the top-left corner, open the Project Selector dropdown, and choose your top-level (Type: Organization) resource.**
{% endstep %}

{% step %}
**From the left-hand panel, navigate to IAM & Admin → IAM.**
{% endstep %}

{% step %}
**Click Grant Access under View by principals.**

a. Under **Add principals**, enter the user's email address.\
b. Under **Assign roles**, search for and select **Organization Policy Administrator**.\
c. Click **Save**.
{% endstep %}

{% step %}
**From the left-hand panel, select Organization Policies.**
{% endstep %}

{% step %}
**In the list of policies, search for and disable the following:**

{% code title="Organization policies to disable" %}

```
Disable service account creation | Managed
Disable service account creation | Managed (Legacy)
Disable service account key creation | Managed
Disable service account key creation | Managed (Legacy)
```

{% endcode %}
{% endstep %}
{% endstepper %}

#### Create a service account

{% stepper %}
{% step %}
**In the** [**Google Cloud console**](https://console.cloud.google.com/?hl=en-au)**, in the top left, open the Project Selector dropdown.**
{% endstep %}

{% step %}
**Click New Project.**
{% endstep %}

{% step %}
**Enter a project name (for example,&#x20;*****Verkada User Sync*****) and create the project.**
{% endstep %}

{% step %}
**Once the project is created, confirm it's selected in the navigation bar at the top left.**

<div align="left" data-with-frame="true"><img src="/files/IpSncf0CCrK4GAX9HLhJ" alt="" width="687"></div>
{% endstep %}

{% step %}
**From the left-hand sidebar, go to IAM & Admin → Service Accounts.**
{% endstep %}

{% step %}
**Click + Create Service Account.**
{% endstep %}

{% step %}
**Fill in the following fields:**

* **Name:** Enter a descriptive name (e.g., *Verkada User Provisioning*)
* **ID:** Leave as-is or customize (optional)
* **Description:** Add a note, such as *Used by Verkada to read Workspace directory data* (optional)
  {% endstep %}

{% step %}
**Click Create and Continue.**
{% endstep %}

{% step %}
**Skip the Grant Project Access step — no roles are required here.**
{% endstep %}

{% step %}
**Click Continue → Done.**
{% endstep %}

{% step %}
**From the list of service accounts, copy the OAuth 2 Client ID for the newly created account. You will need this ID later to complete your setup.**
{% endstep %}
{% endstepper %}

#### Generate a JSON key

{% stepper %}
{% step %}
**From the Service Accounts list, click the account name or select the three dots next to your new service account and choose Manage keys.**

<div align="left" data-with-frame="true"><img src="/files/ChuPgRy1FEXS2Ct1CGtf" alt="" width="800"></div>
{% endstep %}

{% step %}
**Under the Keys tab, click Add Key → Create new key.**
{% endstep %}

{% step %}
**Select JSON and click Create.**
{% endstep %}

{% step %}
**A `.json` file will download to your computer. Save it in a secure location for use later when setting up the integration in Verkada Command.**

<div align="left" data-with-frame="true"><img src="/files/skjsWVRs6wNAwZH2NXiy" alt="" width="800"></div>
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
This JSON file contains the credentials that the Google Workspace integration in Command uses to authenticate to Google APIs via OAuth 2.0. Keep this file secure, as it provides access to your Workspace data and should never be shared or made public.
{% endhint %}

#### Enable required Google APIs

Verkada Command requires access to specific Google Workspace APIs to read users, groups, domains, and audit logs. These APIs must be enabled in your Google Cloud project before the integration can function.

{% stepper %}
{% step %}
**Go to the** [**Google Cloud console**](https://console.cloud.google.com/)**, and sign in with your Super Admin credentials.**
{% endstep %}

{% step %}
**From the left-hand sidebar, go to APIs & Services → API Library.**
{% endstep %}

{% step %}
**In the search bar, find and select Admin SDK API, then click Enable.**

{% hint style="warning" %}
This API is required to read users, groups, and domain metadata.
{% endhint %}
{% endstep %}

{% step %}
**(Optional) Search for and enable the Reports API to allow audit log monitoring and detect directory changes.**
{% endstep %}
{% endstepper %}

***

### Enable Domain-wide delegation

To allow the service account to impersonate an administrator and access user and group data across your domain, you must grant it domain-wide delegation. This enables the service account to perform read operations on behalf of an admin without requiring manual re-authentication.

{% stepper %}
{% step %}
**Navigate to the** [**Google Admin Console**](https://admin.google.com/) **and sign in with your Super Administrator credentials for your Google Workspace tenant.**
{% endstep %}

{% step %}
**From the Admin Console homepage, go to Security →Access & data control → API Controls.**
{% endstep %}

{% step %}
**On the API Controls page, scroll to the Domain-wide Delegation section and click Manage Domain Wide Delegation.**
{% endstep %}

{% step %}
**Click Add New and enter the following details:**

* **Client ID:** Paste the OAuth 2 Client ID for your service account key file (the `client_id` field in the JSON).
* **OAuth Scopes (comma-separated):**

  <pre data-title="OAuth scopes for domain-wide delegation"><code>https://www.googleapis.com/auth/admin.directory.user.readonly,
  https://www.googleapis.com/auth/admin.directory.group.readonly,
  https://www.googleapis.com/auth/admin.directory.orgunit.readonly
  </code></pre>

{% endstep %}

{% step %}
**Click Authorize.**
{% endstep %}
{% endstepper %}

The new delegation entry will appear on the page, confirming that the service account can now be used by Verkada Command to query user, group, and audit data.

#### Set user attribute values

Before syncing users to Verkada Command, confirm that key attributes (such as first name, last name, email, and employee ID) are correctly populated in Google Workspace.

{% stepper %}
{% step %}
**Sign in to the** [**Google Admin Console**](https://admin.google.com/) **using your Super Admin account.**
{% endstep %}

{% step %}
**Go to Directory → Users.**
{% endstep %}

{% step %}
**Select the user profile you want to update.**
{% endstep %}

{% step %}
**Click User information, then expand the relevant sections (for example, Basic information or Employee information).**
{% endstep %}

{% step %}
**Update the following fields as needed:**

* **Primary email address**
* **First name** and **Last name**
* **Employee ID** (under *Employee information*)
* **Phone number** (under *Contact information*)
  {% endstep %}

{% step %}
**Click Save to apply your changes.**
{% endstep %}
{% endstepper %}

The following attributes can be synced from Google Workspace to Verkada Command:

| Google Workspace Attribute Name         | Command Field  |
| --------------------------------------- | -------------- |
| Email                                   | Email          |
| First name                              | First Name     |
| Last name                               | Last Name      |
| Department                              | Department     |
| Cost center                             | Department ID  |
| Employee ID                             | Employee ID    |
| Job title                               | Employee Title |
| Phone number (Primary Home/Work/Mobile) | Phone Number   |

{% hint style="danger" %}
Users and groups synced from Google Workspace are managed exclusively in Workspace and cannot be edited in Verkada Command. Users must have a first name, last name, and email address to sync successfully with Command.
{% endhint %}

{% hint style="info" %}
To ensure users' phone numbers sync correctly to Verkada Command, enter them in international format, including the country code and no spaces or hyphens.

**Example:** `+14155552671`
{% endhint %}

***

### Enable the integration in Command

{% hint style="danger" %}
You need **Org Admin** permissions to configure this integration.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**On Org Settings, select Login & Access → User Provisioning → Google Workspace.**

a. Enter the email address of your Google Workspace Super Admin. For security and continuity, Verkada recommends using a dedicated service account that has equivalent admin permissions, rather than a personal user account.\
a. Upload the JSON key you generated in your Google Cloud Console project.\
b. Once authentication succeeds, click **Add** to select the Groups and/or Organizational Units you want to sync to Command.\
c. Click **Enable**.
{% endstep %}

{% step %}
**Upon successfully completing the first sync, a Sync Now button will be available for on-demand updates at any time.**

<div align="left" data-with-frame="true"><img src="/files/2zolAD1nN3dd7k8fTG8V" alt="" width="800"></div>
{% endstep %}
{% endstepper %}

***

### FAQ

<details>

<summary>Do users sync automatically on a regular schedule?</summary>

Yes, users are synced from your Google Workspace account to Verkada Command automatically every 40 minutes.

</details>
{% endtab %}
{% endtabs %}


# OneLogin

Configure SSO using SAML and OneLogin as your IdP

Verkada supports Security Assertion Markup Language (SAML) authentication using OneLogin as your Identity Provider (IdP).

| Feature           | Supported |
| ----------------- | :-------: |
| OIDC SSO          |     —     |
| SAML SSO          |    Yes    |
| SCIM Provisioning |     —     |
| ECE Support       |     —     |

***

## Configure Verkada SSO with OneLogin

{% hint style="warning" %}
Before you can enable OneLogin SAML, you **must** [generate your client ID](/command/security/identity-providers#generate-client-id).
{% endhint %}

{% stepper %}
{% step %}
**Launch OneLogin and on the menu bar, select Applications > Add App.**

<div align="left" data-with-frame="true"><img src="/files/PtZ0N813E2VjTqYVYI1Q" alt="" width="948"></div>
{% endstep %}

{% step %}
**Search for SAML Custom Connector (Advanced).**

<div align="left" data-with-frame="true"><img src="/files/Tpa6RkmdUNVolOlWfepF" alt="" width="1143"></div>
{% endstep %}

{% step %}
**Choose a Display Name and click Save.**

<div align="left" data-with-frame="true"><img src="/files/h0QVAzlyxCj4tp8Ldov7" alt="" width="1792"></div>
{% endstep %}

{% step %}
**Go to Applications > SAML Custom Connector (Advanced), select Configuration, and use these values to copy and paste, where you replace `CLIENT-ID` with the client ID generated earlier.**

a. For **Audience (EntityID)** and **Recipient**:

* For US orgs: <https://vauth.command.verkada.com/saml/sso/%3Cclient-ID%3E>
* For EU orgs: [https://saml.prod2.verkada.com/saml/sso/](https://saml.prod2.verkada.com/saml/sso/%3CclientID%3E)
* For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E>

e. **Required**. For **ACS (Consumer) URL Validator**:

* For US orgs: [https://vauth.command.verkada.com/saml/sso/](https://vauth.command.verkada.com/saml/sso/%3CclientID%3E)
* For EU orgs: [https://saml.prod2.verkada.com/saml/sso/](https://saml.prod2.verkada.com/saml/sso/%3CclientID%3E)
* For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E>

i. **Required**. For **ACS (Consumer) URL**:

* For US orgs: [https://vauth.command.verkada.com/saml/sso/](https://vauth.command.verkada.com/saml/sso/%3CclientID%3E)
* For EU orgs: [https://saml.prod2.verkada.com/saml/sso/](https://saml.prod2.verkada.com/saml/sso/%3CclientID%3E)
* For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E>

m. For **SAML signature element**, click the dropdown and select **Both**.

{% hint style="warning" %}
To confirm which region you're located, [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}
{% endstep %}

{% step %}
**On Applications > SAML Custom Connector (Advanced), select Parameters.**
{% endstep %}

{% step %}
**Click the plus (+) icon, configure the parameters:**

a. For **Name**, enter the first and last name.\
b. Click the **Value** dropdown and select **Email** > **First Name**.\
c. Under **Flags**, check **Include in SAML assertion**, and click **Save**.
{% endstep %}

{% step %}
**Click the plus (+) icon and in the next open dialog, select Configured by admin.**

Your parameters should look like this:

<div align="left" data-with-frame="true"><img src="/files/f1M5VsfhW4NTB6YUcnk0" alt="" width="1503"></div>
{% endstep %}

{% step %}
**Return to Applications > SAML Custom Connector (Advanced) and select SSO.**
{% endstep %}

{% step %}
**Click the More Actions drop-down and select SAML Metadata to download the metadata.**

<div align="left" data-with-frame="true"><img src="/files/IBZNfPA9KogHDqG4WNNN" alt="" width="557"></div>
{% endstep %}

{% step %}
**Required. To complete the setup process, you must** [**upload the metadata to Command**](/command/security/identity-providers#upload-saml-xml-metadata)**.**
{% endstep %}

{% step %}
**Log in with the SAML Login URL.**
{% endstep %}
{% endstepper %}


# JumpCloud

Learn how to set up SAML with JumpCloud

Verkada supports Security Assertion Markup Language (SAML) authentication using JumpCloud as your Identity Provider (IdP).

| Feature           | Supported |
| ----------------- | :-------: |
| OIDC SSO          |     —     |
| SAML SSO          |    Yes    |
| SCIM Provisioning |     —     |
| ECE Support       |     —     |

### Before you begin

To integrate Security Assertion Markup Language (SAML), you must first [generate a client ID](/command/security/identity-providers#generate-client-id).

***

## Configuration

### Set up SSO

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin > Privacy & Security > Authentication & User Management.**
{% endstep %}

{% step %}
**Click Add New to set up single sign-on (SSO).**
{% endstep %}
{% endstepper %}

### Create your Verkada app

{% stepper %}
{% step %}
**Navigate to your JumpCloud dashboard and click SSO to view your SSO applications.**
{% endstep %}

{% step %}
**Click the plus (+) icon to create a new application.**

<div align="left" data-with-frame="true"><img src="/files/oPlk21LpswRzpWuTggwr" alt="" width="563"></div>
{% endstep %}

{% step %}
**Click Custom SAML App.**

<div align="left" data-with-frame="true"><img src="/files/XKaecWOSP1CTF0ixi7mf" alt="" width="563"></div>
{% endstep %}

{% step %}
**Name your application, add a description, and (optionally) change the icon. Use a name relevant to Verkada.**
{% endstep %}

{% step %}
**When you're finished, at the top menu, select SSO, and click activate.**

<div align="left" data-with-frame="true"><img src="/files/FZlSHnF6oTeDPrieAQKl" alt="" width="563"></div>
{% endstep %}

{% step %}
**Configure the IdP Entity ID, SP Entity ID, and ACS URL as follows:**

* For **IdP Entity ID**:\
  For US orgs: [https://vauth.command.verkada.com/saml/sso](https://vauth.command.verkada.com/sam/sso)\
  For EU orgs: <https://saml.prod2.verkada.com/saml/sso>

  For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso>
* For **SP Entity ID**:\
  For US orgs: [https://vauth.command.verkada.com/saml/sso](https://vauth.command.verkada.com/sam/sso)\
  For EU orgs: <https://saml.prod2.verkada.com/saml/sso>

  For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso>
* For **Sign on URL**:\
  For US orgs: <https://vauth.command.verkada.com/saml/login>\
  For EU orgs: [https://saml.prod2.verkada.com/saml/login](https://saml.prod2.verkada.com/saml/login/)

  For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/login>
* Alternatively, you can copy the fields from Command.

{% hint style="warning" %}
To confirm which region you're located, please [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}
{% endstep %}

{% step %}
**Click activate.**
{% endstep %}

{% step %}
**Scroll down and select the dropdown to set your SAML Subject NameID Format to `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`.**
{% endstep %}

{% step %}
**Check the Sign Assertion box, if not done already.**
{% endstep %}

{% step %}
**Set the Login URL where you can replace `<client-ID>` by your previously-generated client ID (in this application example, `cto` is the client ID):**

* For US orgs: <https://vauth.command.verkada.com/saml/login/%3Cclient-ID%3E>
* For EU orgs: <https://saml.prod2.verkada.com/saml/login/%3Cclient-ID%3E>
* For AUS orgs: <https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E>

{% hint style="warning" %}
To confirm which region you're located, please [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}
{% endstep %}

{% step %}
**Check the Declare Redirect Endpoint box, if not done already, and click activate.**

<div align="left" data-with-frame="true"><img src="/files/WXJJfrvrqtvjJtYJhE40" alt="" width="563"></div>
{% endstep %}
{% endstepper %}

### Configure SAML attributes

{% stepper %}
{% step %}
**Scroll down further and click add attribute THREE times to open 3 attribute fields.**
{% endstep %}

{% step %}
**Type the information exactly as it appears in the screen below; it is case-sensitive.**
{% endstep %}

{% step %}
**Select User Groups and confirm the groups you want to enable SSO access for are checked. In this JumpCloud instance, there is only one group named All Users.**

<div align="left" data-with-frame="true"><img src="/files/sB7zjuRvIBw5jderxavA" alt=""></div>
{% endstep %}

{% step %}
**Click activate to enable this group access to your Verkada application.**
{% endstep %}

{% step %}
**Click activate > confirm to complete your new SSO connector instance.**

<div align="left" data-with-frame="true"><img src="/files/vJ0VhBfqxpX3hFiFQ26E" alt=""></div>
{% endstep %}
{% endstepper %}

### Export XML metadata

{% stepper %}
{% step %}
**Once activated, go back to the featured application to download your XML metadata file.**

<div align="left" data-with-frame="true"><img src="/files/ps6p8zDDvY9ZlFIQdmrZ" alt=""></div>
{% endstep %}

{% step %}
**Select SSO and click Export Metadata to export the JumpCloud Metadata file.**

<div align="left" data-with-frame="true"><img src="/files/LgSsxjUSVV55fBZ3gl4G" alt=""></div>
{% endstep %}

{% step %}
**Save the exported file, give it a relevant name, and click OK > Save.**

<div align="left" data-with-frame="true"><img src="/files/074Q14a3kD8U7GNspjq2" alt=""></div>
{% endstep %}

{% step %}
**After downloading the XML file,** [**upload it to Command**](/command/security/identity-providers#command-sso-configuration)**.**
{% endstep %}
{% endstepper %}

### Ensure your SSO users are provisioned (optional)

{% hint style="warning" %}
Make sure your users using SSO are already provisioned in Command, whether you use SCIM or you create their accounts manually; otherwise, SSO does not work.
{% endhint %}

{% stepper %}
{% step %}
**Your users can access the** [**JumpCloud User Console**](https://console.jumpcloud.com/userconsole#/) **(IdP-initiated flow).**

<div align="left" data-with-frame="true"><img src="/files/7vfMEaxW8fsHpxWBqJlV" alt=""></div>
{% endstep %}

{% step %}
**Choose single sign-on via Command (Service Provider \[SP]-initiated flow).**
{% endstep %}
{% endstepper %}


# AD FS

Integrate SAML with Active Directory Federation Services

Verkada Command has the ability to integrate with Active Directory Federation Services (AD FS) to allow your users to log in using their existing AD credentials.

Security Assertion Markup Language (SAML) is the language that allows AD FS to communicate to Command to securely grant your users access to your organization.

| Feature           | Supported |
| ----------------- | :-------: |
| OIDC SSO          |     —     |
| SAML SSO          |    Yes    |
| SCIM Provisioning |     —     |
| ECE Support       |     —     |

{% hint style="warning" %}
SAML does not add or invite users to your organization. It simply allows previously provisioned users to log in with their AD credentials, rather than with a Verkada-managed username and password.

If you're interested in syncing domain users and groups to Command, learn more about [SCIM](/command/security/identity-providers/microsoft-entra-id).
{% endhint %}

### Before you begin

To begin the SAML integration, you must [generate your organization's client ID](/command/security/identity-providers#generate-client-id) (where the client ID is case-sensitive).

***

## Configuration

### Add relying party trust

{% stepper %}
{% step %}
**Open AD FS Management.**

<div align="left" data-with-frame="true"><img src="/files/N1FhBSP9wRsvUXcdExJ8" alt=""></div>
{% endstep %}

{% step %}
**Select Action > Add Relying Party Trust.**

<div align="left" data-with-frame="true"><img src="/files/hcx1j5VPaPKOjTZuDA2E" alt=""></div>
{% endstep %}

{% step %}
**Check Claims aware and click Start.**

<div align="left" data-with-frame="true"><img src="/files/9t0TixSyvgzbGsjEiPrO" alt=""></div>
{% endstep %}

{% step %}
**Select Enter data about the relying party manually and click Next.**

<div align="left" data-with-frame="true"><img src="/files/wyoxEO1gXv4bfaWa44NX" alt=""></div>
{% endstep %}

{% step %}
**Type a Display name (can be anything) and click Next.**

<div align="left" data-with-frame="true"><img src="/files/SoRErSqxMRalQo24vwln" alt=""></div>
{% endstep %}

{% step %}
**Specify and optional token encryption certificate (click Browse to specify), then click Next.**

<div align="left" data-with-frame="true"><img src="/files/4utRhVAkrC26B6LbAuHz" alt=""></div>
{% endstep %}

{% step %}
**Check Enable support for the SAML 2.0 WebSSO protocol and in the Relying party SAML 2.0 SSO service URL field (substitute&#x20;*****client-ID*****&#x20;with the client ID that was previously generated):**

* For US orgs: <https://vauth.command.verkada.com/saml/sso/%3Cclient-ID%3E>
* For EU orgs: [https://saml.prod2.verkada.com/saml/sso/](https://saml.prod2.verkada.com/saml/sso/%3Cclient-ID%3E)
* For AUS: <https://saml.prod-ap-syd.verkada.com/saml/sso/%3Cclient-ID%3E>

{% hint style="warning" %}
To confirm which region you're located, please [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}
{% endstep %}

{% step %}
**Click Next.**
{% endstep %}

{% step %}
**In the Relying party trust identifier field, type the same URL from step 7, and click Add > Next.**

<div align="left" data-with-frame="true"><img src="/files/c2f7gkE13tHEk6tsgFfJ" alt=""></div>
{% endstep %}

{% step %}
**Configure an appropriate access control policy for this application and click Next.**

<div align="left" data-with-frame="true"><img src="/files/aIxQAhY87U0VJtA9JOJP" alt=""></div>
{% endstep %}

{% step %}
**Review the relying party settings and click Next > Close.**

<div align="left" data-with-frame="true"><img src="/files/cAvIWJRJtgs237qOicsy" alt=""></div>
{% endstep %}
{% endstepper %}

### Edit the claim issuance policy

{% stepper %}
{% step %}
**Right-click the newly-created Relying Party Trust and select Edit Claim Issuance Policy.**

<div align="left" data-with-frame="true"><img src="/files/m3liuEkuDhh1GiNX135p" alt=""></div>
{% endstep %}

{% step %}
**Click Add Rule > OK.**

<div align="left" data-with-frame="true"><img src="/files/Y7v7dcT4LIVr0d3PXdcg" alt=""></div>
{% endstep %}
{% endstepper %}

### Add the transform claim rule

{% stepper %}
{% step %}
**Ensure that Send LDAP Attributes as Claims is selected and click Next.**

<div align="left" data-with-frame="true"><img src="/files/gVeHQnbqN8vkT7G9SmSb" alt=""></div>
{% endstep %}

{% step %}
**Configure these rule settings and (when done) click Finish:**

a. Enter a **Claim rule name** (can be anything).\
b. Under **Attribute store**, ensure that **Active Directory** is selected.\
c. Configure these LDAP attributes to map to the proper **Outgoing Claim Type**:

* E-Mail-Addresses > E-Mail Address
* Given-Name > Given Name
* Surname > Surname

<div align="left" data-with-frame="true"><img src="/files/gdPP0UTPvOAcMMUYonXj" alt=""></div>
{% endstep %}

{% step %}
**Under Claim rule template, select Transform an Incoming Claim to add another rule, and click Next.**

<div align="left" data-with-frame="true"><img src="/files/nVs4EhuFIMVYeij8SHCw" alt=""></div>
{% endstep %}

{% step %}
**Configure the claim rule:**

a. Type a **Claim rule name** (can be anything).\
b. Next to **Incoming claim type**, select **E-Mail Address**.\
c. Next to **Outgoing claim type**, select **Name ID**.\
d. Next to **Outgoing name ID format**, select **Transient Identifier**.\
e. Ensure that **Pass through all claim values** is selected.\
f. Click **Finish**.

<div align="left"><figure><img src="/files/vKV4RZiwp470kru6KKsv" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
**Go to `https:///FederationMetadata/2007-06/FederationMetadata.xml` to download your XML metadata file.**

{% hint style="danger" %}
**Do not** use Internet Explorer to complete this step; using Internet Explorer may cause issues with the XML file.
{% endhint %}
{% endstep %}
{% endstepper %}

***

### Complete the SAML setup on Command

Follow the steps in [Enable SAML for Your Command Account](/command/security/identity-providers#upload-saml-xml-metadata) to complete the SAML setup on Command.

### Test the integration

Once the integration is complete, test it.

{% stepper %}
{% step %}
**Open an incognito/private browsing window and go to (where you will replace clientID with the client ID you generated above):**

* For US: <https://vauth.command.verkada.com/saml/login/%3Cclient-ID%3E>
* For EU: [https://saml.prod2.verkada.com/saml/login/](https://saml.prod2.verkada.com/saml/login/%3Cclient-ID%3E)
* For AUS: [https://saml.prod-ap-syd.verkada.com/saml/sso/](https://saml.prod2.verkada.com/saml/login/%3Cclient-ID%3E)

{% hint style="warning" %}
To confirm which region you're located, please [refer to where your organization was created for Verkada](/command/getting-started/get-started-with-verkada-command).
{% endhint %}
{% endstep %}

{% step %}
**You should be taken to your AD FS login page. Try to sign in with your credentials.**
{% endstep %}

{% step %}
**If you are redirected to your Command organization, the SAML integration is successful.**
{% endstep %}
{% endstepper %}


# SCIM Token Management

Generate a new token for SCIM user provisioning

An organization's System for Cross-Domain Identity Management (SCIM) token authenticates your identity provider (Microsoft Entra ID or Okta) to dynamically provision users and groups in Verkada Command.

***

## Generate a SCIM token

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select Login & Access > SCIM Users Provisioning.**
{% endstep %}

{% step %}
**Click Add Domain and enter the desired email domains.**
{% endstep %}

{% step %}
**(Optional) Toggle off Send Email Invites if you do not want users to receive an email invite when their account is created.**

The newly generated SCIM token displays.

<div align="left" data-with-frame="true"><img src="/files/K6zWrHZNtKMYzKjahmzb" alt="" width="606"></div>
{% endstep %}

{% step %}
**Select the token to copy it to your clipboard.**
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
Immediately update your identity provider configuration with this new token. Once the page is reloaded, the token does not reappear.
{% endhint %}

***

## Refresh a SCIM token

If you need to regenerate your token (for example, if it's lost or compromised), you can do this in Command.

{% hint style="warning" %}
Once you refresh your SCIM token, the previous token is immediately invalidated. Copy the new token into your identity provider immediately to ensure no interruption to user provisioning.
{% endhint %}

### Requirements

* Your organization must already have SCIM provisioning enabled
* You must be an Organization Admin to refresh the SCIM token

### How it works

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select Login & Access > SCIM Users Provisioning.**
{% endstep %}

{% step %}
**Click Refresh.**
{% endstep %}

{% step %}
**When the warning message displays, click Continue to confirm.**

The newly generated SCIM token displays.
{% endstep %}

{% step %}
**Select the token to copy it to your clipboard.**

This new token revokes the previous one and cannot be undone.
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
Immediately update your identity provider configuration with this new token. Once the page is reloaded, the token does not reappear.
{% endhint %}


# User Provisioning Field Requirements and Formatting Rules

This article describes the formatting requirements for each field Verkada accepts via SCIM and other integrations for user provisioning. Use it to verify your values are valid before enabling the sync. For step-by-step attribute mapping instructions specific to your identity provider, see:

* [Okta](/command/security/identity-providers/okta#user-provisioning)
* [Microsoft Entra ID](/command/security/identity-providers/microsoft-entra-id#user-provisioning)
* [Google Workspace](/command/security/identity-providers/google-workspace#user-provisioning) — supports a subset of the fields below: email, first and last name, department, department ID, employee ID, employee title, and phone number

***

## Field requirements <a href="#field-requirements" id="field-requirements"></a>

The table below covers every field Verkada accepts. Fields marked **Required** must be present on every user creation request.

<table><thead><tr><th width="169.14453125">Field</th><th width="174.45703125">SCIM Attribute</th><th>Schema</th><th width="114.83984375">Required</th><th>Allowed characters</th></tr></thead><tbody><tr><td>Email address (username)</td><td><code>userName</code></td><td>Core</td><td>Yes</td><td>Valid email address. Maximum 255 characters.</td></tr><tr><td>First name</td><td><code>name.givenName</code></td><td>Core</td><td>Yes</td><td>Supports letters, numbers, spaces, <code>&#x26;</code> <code>'</code> <code>-</code> <code>.</code> <code>,</code> <code>(</code> <code>)</code> <code>/</code>. Maximum 100 characters.</td></tr><tr><td>Last name</td><td><code>name.familyName</code></td><td>Core</td><td>Yes</td><td>Supports letters, numbers, spaces, <code>&#x26;</code> <code>'</code> <code>-</code> <code>.</code> <code>,</code> <code>(</code> <code>)</code> <code>/</code>. Maximum 100 characters.</td></tr><tr><td>Middle name</td><td><code>name.middleName</code></td><td>Core</td><td>No</td><td>Maximum 255 characters.</td></tr><tr><td>Work phone*</td><td><code>phoneNumbers</code></td><td>Core</td><td>No</td><td>E.164 format with a country code (e.g., +14155552671) is required for reliable verification. Maximum 32 characters.</td></tr><tr><td>External ID</td><td><code>externalId</code> </td><td>Verkada</td><td>No</td><td>Supports letters, numbers, <code>_</code> <code>@</code> <code>-</code> <code>.</code> <code>+</code>. Maximum 128 characters.</td></tr><tr><td>Employee title</td><td><code>title</code></td><td>Core</td><td>No</td><td>Maximum 255 characters.</td></tr><tr><td>Department</td><td><code>department</code> </td><td>Enterprise</td><td>No</td><td>Maximum 255 characters.</td></tr><tr><td>Company name</td><td><code>organization</code> </td><td>Enterprise</td><td>No</td><td>Maximum 255 characters.</td></tr><tr><td>Employee ID</td><td><code>employeeNumber</code> </td><td>Enterprise</td><td>No</td><td>Maximum 255 characters.</td></tr><tr><td>Department ID</td><td><code>costCenter</code> </td><td>Enterprise</td><td>No</td><td>Maximum 255 characters.</td></tr><tr><td>Active status</td><td><code>active</code></td><td>Core</td><td>No</td><td>Supports <code>true</code> or <code>false</code></td></tr></tbody></table>

#### Schema types

**Core:** `urn:ietf:params:scim:schemas:core:2.0:User`

**Verkada extension:** `urn:ietf:params:scim:schemas:extension:verkada:core:2.0:User`

**Enterprise extension:** `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User`

{% hint style="warning" %}
The phone attribute syntax differs by identity provider.

* Okta: `phoneNumbers.^[type==work].value`&#x20;
* Entra ID: `phoneNumbers[type eq "work"].value`&#x20;

Verkada also accepts a phone number marked `primary: true` as the work phone, even if the `type` isn't explicitly set.
{% endhint %}

***

## Access card credentials (Verkada Access extension) <a href="#access-card-credentials-verkada-access-extension" id="access-card-credentials-verkada-access-extension"></a>

If your organization uses Verkada Access, you can provision access card credentials via SCIM using the custom **Verkada access extension:** `urn:ietf:params:scim:schemas:extension:verkada:access:2.0:User`&#x20;

| Field             | SCIM Attribute     | Schema         | Notes                                                                                                     |
| ----------------- | ------------------ | -------------- | --------------------------------------------------------------------------------------------------------- |
| Card format       | `cardFormat`       | Verkada access | Must match a format supported by your hardware (e.g., `"Standard 26-bit Wiegand"`, `"HID 37-bit"`, etc.)  |
| Card number       | `cardNumber`       | Verkada access | Integer; must fit within the bit range defined by the card format                                         |
| Card number (hex) | `cardNumberHex`    | Verkada access | Hex string; must fit within the bit range defined by the card format                                      |
| Facility code     | `facilityCode`     | Verkada access | Integer; must fit within the bit range defined by the card format; required only for formats that use one |
| Credential status | `credentialStatus` | Verkada access | `active`, `deactivated`, `deleted`                                                                        |

***

## Resolve common user provisioning errors

| Error message                                                                              | Cause                                                                      | Fix                                                                                         |
| ------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| *"User with this email domain cannot be managed"*                                          | The user's email domain is not in your identity provider's allowed list.   | Add the domain in Command under Organization Settings > Login & Access.                     |
| *"Invalid argument: name does not conform to valid name constraints"*                      | First or last name contains a disallowed character.                        | Update the name in your directory, or adjust your attribute mapping to strip the character. |
| *"Invalid argument: invalid characters in external ID, Alphanumeric, @, -, +, and . only"* | External ID contains a space or unsupported symbol.                        | Use only letters, numbers, `_` `@` `-` `.` `+`.                                             |
| *"Invalid argument: external ID is too long, max length is 128 characters"*                | External ID exceeds 128 characters.                                        | Shorten the value or use a different attribute.                                             |
| *"Invalid phone number, too long"*                                                         | Phone number string exceeds 32 characters.                                 | Remove formatting characters or shorten the value in your mapping.                          |
| *"Unsupported operations on fields: \[...]. Unmap these in your IdP to fix this error."*   | Your identity provider is syncing a field that Verkada does not support.   | Remove the listed fields from your IdP's attribute mapping.                                 |
| *"User already exists: {email}"*                                                           | A user with this email is already managed by this SCIM provider.           | No action needed.                                                                           |
| *"User cannot be managed {email}"*                                                         | The user is managed by a different SCIM provider in the same organization. | Check whether another SCIM integration is active.                                           |
| *"User with external id {id} already exists"*                                              | Another user in your organization already has this external ID.            | External IDs must be unique per organization. Check for duplicate values in your directory. |


# Data Protection

Learn how to enable privacy features to secure your Verkada Command organization

Privacy and security disclosures enable you to view which Verkada products are installed, what analytics features are enabled, and which features your organization has opted not to use to preserve privacy.

***

## Create a disclosure

You can create one disclosure for your entire organization or you can create individual disclosures for each site depending on the features being used at those locations.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Data Privacy > Public Disclosures.**
{% endstep %}

{% step %}
**At the top, click the disclosure dropdown and select Create New.**
{% endstep %}

{% step %}
**On the Create Disclosure panel:**

a. **Required**. Enter the site name and select a site for this disclosure.\
b. Upload your company logo.

<div align="left" data-with-frame="true"><img src="/files/RYU2rPjuk9CAIdArUJ3A" alt="" width="339"></div>

c. (Optional) Toggle on additional information (Feature Usage, Contact Info, Privacy Policy), as needed.

<div align="left" data-with-frame="true"><img src="/files/2DkgmccxisPimPEVzWec" alt=""></div>
{% endstep %}

{% step %}
**When you’re done, at the top right, click Publish. You’ll see a disclosure preview to confirm.**

<div align="left" data-with-frame="true"><img src="/files/k83o91Tx4hsCjePPhQBv" alt="" width="360"></div>
{% endstep %}
{% endstepper %}

***

## Share your disclosure

Once you publish the disclosure, you can share it.

{% stepper %}
{% step %}
**On your preview page, at the top right, click the meatball (3 vertical dots) icon.**
{% endstep %}

{% step %}
**From the list, you can choose a share method that generates one of these:**

* **QR Code**—Downloadable QR code that can be physically posted around the site or shared over the internet.
* **Copy Link**—Hyperlink that can be shared over the internet and provides a web version of the disclosure.
* **Print**—Downloadable PDF of the privacy disclosure that can be printed.
  {% endstep %}
  {% endstepper %}

{% hint style="warning" %}
Once you publish your privacy disclosure, the link is publicly available, but not advertised or automatically shared. If you plan to use the hyperlink to share the Privacy Disclosure, you need to publicize it yourself.
{% endhint %}


# Data Storage & Processing Locations

Select where your organization’s data will be stored and processed

### Before you begin

Refer to [Create a Command Organization](/command/getting-started/create-a-command-organization) to configure your organization’s data storage and processing locations.

{% hint style="danger" %}
The data processing location can only be set while creating an organization. Once the location is set, it CANNOT be changed. Read the information below before configuring your organization’s data processing location.
{% endhint %}

Data storage location refers to the physical or geographical location where an organization’s data is stored, and data processing location refers to the location where the data is being processed or analyzed. Verkada’s standard camera option includes on-camera storage retention for 30 days of continuously recorded video and image data. Verkada customers also have the flexibility to enable cloud backup storage for camera video and image data. When configuring cloud backup, customers can choose the region where their data is stored and processed in the cloud on a camera-by-camera or organization-wide basis.

By providing the option to choose cloud data storage on a camera-by-camera or organization-wide basis, Verkada provides flexibility to support customers’ data management preferences and operational needs. Additionally, by selecting a region closer to your operations, you experience reduced latency and improved access speeds, providing a more efficient and responsive experience.

### Supported data center locations

* The United States
* The European Union (EU)
* Australia

{% hint style="danger" %}
Authentication data will always be processed in the US during the organization's initial configuration.
{% endhint %}

### Cloud data center locations for camera video and image data storage (not processing)

For customers prioritizing regional storage of video and image data, Verkada supports the following locations for storage in addition to the locations provided above. If one of these locations for video and image data storage is selected, the corresponding data processing will still occur in the primary processing region for your org (United States, European Union (Ireland), or Australia):

* Canada
* Germany (Frankfurt)
* Japan (Tokyo)
* Singapore
* South Korea (Seoul)


# Set Data Storage Location

Set your default image and video data location in Verkada Command

Verkada’s standard camera option includes enough on-camera storage capacity for 30 days of continuously recorded video footage. Verkada systems enable you to store your organization’s data in the cloud on AWS, providing backup options worldwide. Learn how Verkada [manages and processes data](https://www.verkada.com/support/dpa/).

{% hint style="danger" %}
The data processing location can only be set while creating an organization. See [Data Storage & Processing Locations](/command/security/privacy-and-security-disclosure/data-storage-processing-locations) for more information.
{% endhint %}

***

## Set a default org-level cloud storage location for camera image and video data

Org Admins can set the default cloud storage location of image and video data for their organization. The dropdown is grouped by region: Americas (United States, Canada), EU (Ireland/Dublin, Germany/Frankfurt), and Asia Pacific (Australia, Japan/Tokyo, Singapore, South Korea/Seoul).

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Data Privacy > Data Residency.**
{% endstep %}

{% step %}
**Next to Default Image & Video Data Storage Location, click the dropdown and select the desired region for your camera image and video data to be stored. Available regions: United States, Canada, Ireland (Dublin), Germany (Frankfurt), Australia, Japan (Tokyo), Singapore, and South Korea (Seoul).**

<div align="left" data-with-frame="true"><figure><img src="/files/OILeCHI19p6djWJPoReF" alt="" width="215"><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
If a storage-only region (e.g., Canada, Germany/Frankfurt, Japan/Tokyo, Singapore, South Korea) is selected, the data is stored in that region; however, data processing will still occur in the primary processing region for your org (US, EU, or AU).

**This change is not retroactive**. Only data uploaded after the selection will be stored in the new location.

**Storage of the Incident Management feature’s camera image & video data**

* If you create a zip file using the [Incident Management](/verkada-cameras/video-streaming-and-sharing/incident-management) feature, copies of the archived clips are stored in the region associated with their original data storage location.
* If the archived clips are stored in the US, the copies used to generate the ZIP file are also stored in the US. If the archived clips come from other regions, the copies are stored in the EU or AU, depending on their original storage location.
* In addition, Incident Management creates a persistent copy of each archived clip in the organization’s selected data storage location when the incident is created. This copy is independent of the original archive and remains available until the incident report is deleted.
  {% endhint %}

***

## Set per-camera image and video data storage location

The per-camera storage setting takes precedence over the org-level default. In Verkada Command, from the **Admin** tab, Org Admins and Site Admins can choose to set the data storage location for [individual cameras](#h_c8b86a0616).

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**
{% endstep %}

{% step %}
**Select your camera.**
{% endstep %}

{% step %}
**At the bottom right of the camera live feed, click Settings.**
{% endstep %}

{% step %}
**Under Privacy > Camera Image & Video Data Storage Location, click the dropdown and select the desired region for your data to be stored.**

**Available regions: US, Canada, Ireland (Dublin), Germany (Frankfurt), Australia, Japan (Tokyo), Singapore, and South Korea (Seoul).**
{% endstep %}
{% endstepper %}


# Restricted Devices

Learn what to do when you discover a restricted device in your organization

When a device is *restricted*, it means that Verkada has determined that this device has been lost or stolen.

***

## How Verkada restricts a device

{% stepper %}
{% step %}
**We alert the Organization Admins (Org Admins) on the organization the device is claimed to.**
{% endstep %}

{% step %}
**After 48 hours, the device is removed from the Verkada Command org and blocked from being added to other orgs.**
{% endstep %}
{% endstepper %}

### Contact Verkada Support

If you receive an email about a restricted device, contact [Verkada Support](https://www.verkada.com/support/) as soon as possible.

{% hint style="warning" %}
For security reasons, we do not mention the device that has been restricted. Contact [Verkada Support](/command/need-help/contact-verkada-support) for assistance.
{% endhint %}

***

### Example emails you may receive

#### Example 1

**Subject**: \[Action Required]: Restricted Device Found

**Body**: One of the devices in the Organization has been marked as restricted. This device will be permanently removed from your organization 48 hours from the date this email is sent. If you believe this device has been restricted in error, please contact our support team immediately.

<div align="left" data-with-frame="true"><img src="/files/1xwoApOvjF0KPpEB9oBF" alt=""></div>

### Example 2

**Subject**: Restricted Device Removed from Command

**Body**: One or more of the devices in the Organization has been removed from your Command organization. This means the device was marked as restricted on or after and can no longer be added to an organization. If you believe this device has been removed in error, please contact our support team immediately.

<div align="left" data-with-frame="true"><img src="/files/syxtnnhg5Eousl0OcbB0" alt=""></div>


# Privacy and Security Checklist

Learn actions that your organization can take to ensure the highest level of security

To help make transparency, privacy, and compliance simpler for our customers, you can use a privacy and security checklist, along with the [Privacy and Security disclosure](/command/security/privacy-and-security-disclosure). Using this feature, you can communicate which products and features are being used in their organization.

***

## Access the Privacy and Security checklist

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Security & Logs.**
{% endstep %}

{% step %}
**Select Security Checklist.**
{% endstep %}

{% step %}
**On the Privacy & Security Checklist page, you can access the list of actions (see the table below) to ensure that Verkada Command is configured at the highest level of security.**

{% hint style="warning" %}
Some items are automatically marked complete once the task is complete.
{% endhint %}

|                                                                                                                                                                                                 |                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Setting**                                                                                                                                                                                     | **Action in Command**                                                                                                                                                                                                                                                         |
| [**Enforce 2FA**](/command/security/authentication-overview/two-factor-authentication)                                                                                                          | <p>Requires users in your organization to set up and use 2FA when logging in via a password.</p><p>Toggle on this enforcement in <strong>Admin</strong> > <strong>Privacy & Security</strong> > <strong>Authentication & User Management</strong>.</p>                        |
| **Review Session Duration**                                                                                                                                                                     | <p>Set the amount of time a user’s session lasts before having to log in again.</p><p>Review the configured session duration in <strong>Admin</strong> > <strong>Privacy & Security</strong> > <strong>Session Timeout</strong>.</p>                                          |
| [**Set Up and Enable SSO**](https://github.com/verkada/Verkada-Support-Docs/blob/main/en/command/single-sign-on-sso/authentication-and-provisioning-overview.md)                                | <p>1.</p><p><a href="https://command.verkada.com/admin/privacy-security/saml">Configure SSO</a> as an authentication method for your users.</p><p><br>2.</p><p>Complete the <strong>Run Login Test</strong> step to enable it (for enhanced security, make SSO required).</p> |
| [**Set Up SCIM**](/command/security/identity-providers/scim-token-management)                                                                                                                   | Configure SCIM to provision and manage your users and groups through Okta or Microsoft Entra ID identity management.                                                                                                                                                          |
| [**Add Primary Key Contact**](/command/organization-settings/manage-your-admin-page-settings/manage-contacts)                                                                                   | Add a [primary contact](https://command.verkada.com/admin/org-settings/org-details) who serves as the designated point of contact for general communications.                                                                                                                 |
| [**Add Billing Key Contact**](/command/organization-settings/manage-your-admin-page-settings/manage-contacts)                                                                                   | Add a [billing contact](https://command.verkada.com/admin/org-settings/org-details) who serves as the designated point of contact for billing-related communications.                                                                                                         |
| [**Add Security Key Contact**](/command/organization-settings/manage-your-admin-page-settings/manage-contacts)                                                                                  | Add a [security contact](https://command.verkada.com/admin/org-settings/org-details) who serves as the designated point of contact for security-related communications.                                                                                                       |
| **Review Users**                                                                                                                                                                                | Ensure your [users list](https://command.verkada.com/admin/users) and user roles are up to date and remove any users if necessary.                                                                                                                                            |
| [**Review Groups**](/command/users-and-permissions/manage-users-in-your-organization/manage-command-groups)                                                                                     | Ensure each user is added to the [group(s)](https://command.verkada.com/admin/groups) that grants the correct permissions.                                                                                                                                                    |
| [**Review Default Image and Video Data Location**](/command/security/privacy-and-security-disclosure/set-a-default-or-camera-specific-location-for-image-and-video-data-storage-and-processing) | <p>1.</p><p>Set the default geographic region where camera video and image data will be stored.</p><p><br>2.</p><p>Review the configured location in <strong>Admin</strong> > <strong>Privacy & Security</strong> > <strong>Data Residency</strong>.</p>                      |
| **Confirm Appropriate Notice**                                                                                                                                                                  | <p>Confirm that:</p><p>All physical sites have appropriate signage with regard to camera recordings.</p><p>The company receives appropriate consent from employees and guests.</p>                                                                                            |
| **Review People Analytics Notice**                                                                                                                                                              | Review and accept the Analytics Terms and Conditions, found in the **Admin > Cameras > Analytics**.                                                                                                                                                                           |
| [**Review Audit Logs**](/command/organization-settings/manage-your-admin-page-settings/manage-and-view-audit-logs)                                                                              | Review the [logged actions](https://command.verkada.com/admin/privacy-security/audit-log) of Command users in your organization to check for irregular activity.                                                                                                              |
| {% endstep %}                                                                                                                                                                                   |                                                                                                                                                                                                                                                                               |
| {% endstepper %}                                                                                                                                                                                |                                                                                                                                                                                                                                                                               |

***

## Dismiss an action from the checklist

If a specific action does not pertain to your organization, you can dismiss it from the list.

Next to the action item, click the checkmark and select **Complete** or **Dismiss**. If it has a dropdown arrow next to the item name, it does not count toward your completion percentage.

<div data-with-frame="true"><img src="/files/p0ruU4FAXgSA64hm9g57" alt=""></div>

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=vme3YdOdhsE).
{% endhint %}


# Bug Bounty Program

Information on the Verkada Bug Bounty Program

Verkada has a private security bug bounty program through Bugcrowd. If you would like to be invited to Verkada’s Bugcrowd program send an email to <security@verkada.com> with the subject line "Bugcrowd Invite" and be sure to include the email address associated to your Bugcrowd account. Verkada will only pay bounties for vulnerabilities reported through Bugcrowd.

If you would like to report a security vulnerability directly to Verkada outside of Bugcrowd, please fill out this form <https://www.verkada.com/security/report-issue/> . For issues with the form, contact <security@verkada.com>.


# Enable Data Sharing

Learn how to share data to help Verkada improve its products

## Share camera data with Verkada

Sharing your camera footage with Verkada develops and improves the analytics features across all Verkada cameras.

{% hint style="warning" %}
This is an opt-in feature and is disabled by default. This toggle is separate from the Enable Support Access [toggle](/command/need-help/contact-verkada-support/enable-support-access). Opting in allows Verkada Engineering to collect, store, view, and annotate images and video, and to create derivative works, for model training. All data is collected from our Amazon Web Services (AWS) backend and not directly from your cameras. This feature **does not** allow Verkada Support to access your camera’s images and video.

**This setting only applies to sharing camera footage with Verkada for research and development, including model training of our computer vision features. It does not include other event types or system data.**
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Data Privacy.**
{% endstep %}

{% step %}
**Toggle on Share camera data with Verkada.**
{% endstep %}

{% step %}
**When you are prompted with the User Agreement, click I Agree to confirm.**

<div align="left" data-with-frame="true"><img src="/files/SvhdikR5zXspFlCWLzRI" alt="" width="446"></div>
{% endstep %}
{% endstepper %}

***

## Share product data with Verkada

You can also optionally choose to share additional product data with Verkada to support the development and testing of new features. This includes device and event-specific data associated with various Verkada products, such as sensors, access events, alarms, and badge-ins.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Data Privacy.**
{% endstep %}

{% step %}
**Toggle on Share product data with Verkada**
{% endstep %}

{% step %}
**When you are prompted with the User Agreement, click I Agree to confirm.**

<div align="left" data-with-frame="true"><img src="/files/fyq6fVAo5kNGvkZ8rsem" alt="" width="375"></div>
{% endstep %}
{% endstepper %}


# Devices Page Overview

Learn about the details for Verkada devices

The **Devices** page in Verkada Command allows for a quick navigation through your Verkada devices. On this page, you can add devices to the org, see device information, change a camera’s site location, and access individual camera live streams. Devices are sorted by the site that they are placed in for easy visibility.

***

## Find the Devices page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Configure your device’s settings, as needed.**
{% endstep %}
{% endstepper %}

***

## Configure your device

### Add a device

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**At the top right, click** [**Add Devices**](/command/organization-settings/add-a-device-to-your-command-organization)**.**
{% endstep %}
{% endstepper %}

### Change devices view from sites to a list

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**On Devices, at the top right, toggle from the Sites view to the List view.**
{% endstep %}

{% step %}
**At the top right of the List view, click the ellipsis dropdown to add/remove columns from the view.**
{% endstep %}
{% endstepper %}

Alternatively, on the left navigation, click **Sites**<img src="/files/NxZP8lhf7eemZeqzvFkL" alt="" data-size="line">, where you can see a list of your devices on the right.

### Change a device’s site location

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Select a device.**
{% endstep %}

{% step %}
**In the Site field, select the pertaining site where you want the device to live.**
{% endstep %}

{% step %}
**Click the right arrow to open the Change Site dialog.**
{% endstep %}

{% step %}
**Click Save to confirm.**
{% endstep %}
{% endstepper %}

### Change a device’s physical address

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Select a device.**
{% endstep %}

{% step %}
**In the Site field, click Location and enter the address where you want this device to live.**
{% endstep %}

{% step %}
**Click Save to confirm.**
{% endstep %}
{% endstepper %}

***

## Export Device List

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Filter for devices of interest.**
{% endstep %}

{% step %}
**In the top right, click** ![](/files/84CvIKBi3uTodJ2uMVM4).
{% endstep %}

{% step %}
**A prompt will appear that the download has initiated. Check your email for a download link.**
{% endstep %}
{% endstepper %}

***

## Make bulk changes for multiple devices

Within a selected Device Type, you can bulk change settings, notifications, and specific device configurations.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Filter by a single Device Type.**

{% hint style="warning" %}
If you select multiple device types, the Edit Settings option will not appear.
{% endhint %}
{% endstep %}

{% step %}
**Check the box next to the devices you want to change.**
{% endstep %}

{% step %}
**In the top right, click Edit Settings.**

1. Edit the settings as needed.
2. Click **Apply** to save.
   {% endstep %}
   {% endstepper %}

#### Bulk-delete

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Check the box next to the devices you want to change.**

a. At the top right, click **Delete**.\
b. Enter the confirmation code.\
c. Click **Delete.**
{% endstep %}
{% endstepper %}

This table shows the fields that Command enables for bulk actions by Device Type.

| Device Type         | Bulk-actionable fields                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cameras             | <ul><li>Site</li><li>Location</li><li>Schedule Firmware Updates</li><li>Audio</li><li><a href="/spaces/ylYKicREo6JpuOJH4teK/pages/u6AgfMjDf6ga80Zo0z7g">Low bandwidth mode</a></li><li><a href="/spaces/ylYKicREo6JpuOJH4teK/pages/kY29P4owAUhcXKpKs8jR">RTSP streaming</a></li><li><a href="/spaces/ylYKicREo6JpuOJH4teK/pages/lZCkOgkWXsP3QZ7p7iVw">Motion events</a></li><li><a href="/spaces/ylYKicREo6JpuOJH4teK/pages/haNe7o4Ofgs6pbY8IaEa">Crowd events</a></li><li>Data storage location</li><li>Analytics features</li><li><a href="/spaces/ylYKicREo6JpuOJH4teK/pages/dxTzcSTsZw8Fb6CmrWfV">Cloud Backup</a></li></ul> |
| Air Quality Sensors | <ul><li>Site</li><li>Location</li><li>Sensors and Triggers</li><li>Notifications</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Intercom            | <ul><li>Site</li><li>Location</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Command Connector   | <ul><li>Site</li><li>Location</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Desk Station        | <ul><li>Site</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


# Add a Device

Add devices to Verkada Command for management

You need to add your devices to Command before you can access and manage them.

{% hint style="danger" %}
You need [Org Admin or Site Admin permissions](/command/users-and-permissions/roles-and-permissions-for-command) for a site to add a device.
{% endhint %}

***

## Add devices

{% stepper %}
{% step %}
**In Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**At the top right, click Add Devices.**
{% endstep %}

{% step %}
**Enter the serial numbers or order numbers of the devices.**
{% endstep %}

{% step %}
**Click Add Devices. The newly added devices will display on Devices > All Unassigned Devices.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Alternatively, you can add devices using **Scan QR** or **Upload CSV**. If you upload a comma-separated value (CSV) file, you can download a template for ease of use.
{% endhint %}

***

## Set up a device

You need to assign a device to a site and complete the setup to move it from the **Unassigned Devices** list. Devices can be set up individually or in bulk.

{% hint style="danger" %}
You can only set up one product type at a time. If devices from multiple product lines are selected, you will not see the **Set Up** option.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, select All Products > Devices.**
{% endstep %}

{% step %}
**Under All Unassigned Devices:**

a. Select the device(s) you want to set up.\
b. Click **Set Up**.
{% endstep %}

{% step %}
**Under General:**

a. Enter a unique name.\
b. Select a site.\
c. Enter a location.
{% endstep %}

{% step %}
**(For cameras only) Under Settings:**

a. (Optional) From the **Default** dropdown, select **Copy from another camera** and select a camera to copy its configuration.\
b. Confirm the configuration or make any necessary changes.
{% endstep %}

{% step %}
**Click Apply to configure the devices.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You can only copy configurations from cameras located in the same site as the new camera.
{% endhint %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=qcrS5i8_XR4).
{% endhint %}


# Buildings and Floors

Create buildings and floors to manage your Verkada devices

Buildings and floors are used to organize floorplans and access controllers in your organization. Every floorplan and access controller needs to be assigned to a building and floor in Command before they can be used.

Floorplans allow you to visually see where your cameras, access controllers, and air quality sensors are placed in your organization. Access controllers allow you to control access to the doors in your organization.

{% hint style="warning" %}
See the following articles for more information:

* [Create a Floorplan](/command/organization-settings/buildings-and-floors/create-a-floorplan)
* [Add an Access Controller to Command](/access-control/configuration/add-an-access-controller-to-command)
  {% endhint %}

***

## Create a building

### Floorplan page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top right, click > Create Floorplan.**
{% endstep %}

{% step %}
**In the top right, click Add Building.**

a. Enter a unique name.\
b. Enter the building address.\
c. Add a floor name.\
d. Click **Create.**
{% endstep %}
{% endstepper %}

### Access Settings page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Access.**
{% endstep %}

{% step %}
**In the left navigation, click Access Settings.**
{% endstep %}

{% step %}
**Select Buildings.**
{% endstep %}

{% step %}
**In the top right, click Add Building.**

a. Enter a unique name.\
b. Enter the building address.\
c. Add a floor name.\
d. Click **Create.**
{% endstep %}
{% endstepper %}

***

## Add a floor

### Floorplan page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top right, click > Create Floorplan.**
{% endstep %}

{% step %}
**Select your building, and click Add Floor.**
{% endstep %}

{% step %}
**Enter the floor name or number and click** <i class="fa-check">:check:</i>**.**
{% endstep %}
{% endstepper %}

### Access Settings page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Access.**
{% endstep %}

{% step %}
**In the left navigation, click Access Settings.**
{% endstep %}

{% step %}
**Select Buildings > your building.**
{% endstep %}

{% step %}
**In the top right, click Edit Building.**

a. Click **Add Floor.**\
b.Enter the floor name or number and click <i class="fa-check">:check:</i>.\
c. Click **Save.**
{% endstep %}
{% endstepper %}

***

## Delete a floor

{% hint style="danger" %}
You need to remove all devices from a floor before a floor can be deleted. Go to the device’s settings page to change the associated floor.
{% endhint %}

### Floorplan page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top right, click > Create Floorplan.**
{% endstep %}

{% step %}
**Select your building.**
{% endstep %}

{% step %}
**Hover over the floor you want to delete and click the trash can icon.**
{% endstep %}
{% endstepper %}

### Access Settings page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Access.**
{% endstep %}

{% step %}
**In the left navigation, click Access Settings.**
{% endstep %}

{% step %}
**Select Buildings > your building.**

a. In the top right of the floor tile, click <i class="fa-x">:x:</i>.\
b. Click **Delete** to confirm.
{% endstep %}
{% endstepper %}

***

## Delete a building

{% hint style="danger" %}
You need to [delete all floors](#h_d865055259) before you can delete a building.
{% endhint %}

### Floorplan page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top right, click > Create Floorplan.**
{% endstep %}

{% step %}
**Select your building.**

a. Click **Delete Building.**\
b. Click **Delete** to confirm.
{% endstep %}
{% endstepper %}

### Access Settings page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Access.**
{% endstep %}

{% step %}
**In the left navigation, click Access Settings.**
{% endstep %}

{% step %}
**Select Buildings.**

a. In the top right of your building tile, click.\
b. Click **Delete** to confirm.
{% endstep %}
{% endstepper %}


# Create a Floorplan

Learn how to configure your floorplans in Verkada Command

[Floorplans](https://www.verkada.com/blog/new-and-improved-floorplans-experience) help you plan and visualize your Verkada system. This feature can help you detect active motion and historical activity hotspots using heat maps. You can connect cameras, air quality sensors, and access-controlled doors so you can quickly view your devices directly from the floorplan.

***

## Create a floorplan

{% hint style="danger" %}
You must be an [Organization Admin](/command/users-and-permissions/roles-and-permissions-for-command) to add a floorplan.
{% endhint %}

### Create a building and floor

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**At the top right, click** ![](/files/n8ctpG5r3nbNgZvPxTZf) **and select Create Floorplan.**
{% endstep %}

{% step %}
**In the top right, click Add Building.**

a. Enter a unique name.\
b. Enter the building address.\
c. Enter the floor name.\
d. Click **Create** to finish.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
To create multiple floors, delimit each floor using commas. For example, enter **1, 2, 3** for floors 1, 2, and 3.
{% endhint %}

### Create a floorplan

{% hint style="danger" %}
The floorplan file must be:

* a .svg or .pdf file
* less than 5 MB in size
* less than 512 megapixels
  {% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**At the top right, click** ![](/files/n8ctpG5r3nbNgZvPxTZf) **and select Create Floorplan.**
{% endstep %}

{% step %}
**On Select Building and Floor:**

a. Select a building and floor.\
b. Click **Next.**
{% endstep %}

{% step %}
**On Upload File:**

a. Click **Browse** and select your floorplan file from your computer.\
b. Click **Next.**
{% endstep %}

{% step %}
**On Enter Address:**

a. Enter the address associated with your floorplan.\
b. Click **Next.**
{% endstep %}

{% step %}
**On Set Location:**

a. Orient and size the floorplan to match your building on the map.\
b. Click **Save.**

<div align="left" data-with-frame="true"><img src="/files/uyDaHTgzJHmulzi6BKUD" alt="" width="1081"></div>
{% endstep %}
{% endstepper %}

***

## Manage floorplans

### Add a device

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**In the top right, click Add.**
{% endstep %}

{% step %}
**Select the type of device you want to add.**

{% hint style="warning" %}
Only cameras, (air quality) sensors, and doors are supported on floorplans.
{% endhint %}
{% endstep %}

{% step %}
**Drag and place the device where you want on your floorplan.**&#x200B;

<div align="left" data-with-frame="true"><img src="/files/SLZSSYCGTSlOEAm03zkU" alt="" width="1079"></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
The devices you place on the floorplan inherit the GPS coordinates from the underlying Google Map. If you edit the location of a floorplan, Command prompts you to also move all devices placed on the floorplan. The devices will be assigned new GPS coordinates based on the new position of the floorplan. **If you change a camera’s location from the camera’s settings page it will remove it from the floorplan.**
{% endhint %}

### Remove a device

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**In the top right, click Device List.**
{% endstep %}

{% step %}
**Hover over the device and click** ![](/files/n8ctpG5r3nbNgZvPxTZf)**.**

a. Click **Remove**.\
b. Click **Remove** to confirm.
{% endstep %}
{% endstepper %}

### Edit building settings

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**At the top right, click and select Floor Settings.**
{% endstep %}

{% step %}
**Under Floorplan, click Edit and edit your floorplan settings as needed.**
{% endstep %}
{% endstepper %}

### Reposition a device

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**In the top right, click Device List.**
{% endstep %}

{% step %}
**Hover over the device and click.**
{% endstep %}

{% step %}
**Once the device icon turns blue, click and drag the device to the position.**
{% endstep %}
{% endstepper %}

### Rotate a camera view

The direction of a camera’s field of view does not always match the direction shown on the floorplan. If this is the case for your floorplan, you can manually set the orientation of the camera icon for greater accuracy.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**At the top right, click Device List.**
{% endstep %}

{% step %}
**Click next to the camera you want to rotate.**
{% endstep %}

{% step %}
**Drag the cone , representing the field of view of the camera and adjust to the desired direction.**
{% endstep %}
{% endstepper %}

### Label a floorplan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**At the top right, click and select Floor Settings.**
{% endstep %}

{% step %}
**Under Add New Label:**

a. Select **Abc** for a bold label.\
b. Select Abc for a regular label.
{% endstep %}

{% step %}
**Under Label Settings:**

a. In the **Text** field, enter the text for your label.\
b. Drag and drop the label where you want it on your floorplan.
{% endstep %}
{% endstepper %}

### Floorplan icon colors

* Blue: Device selected
* Green: Online
* Orange: Offline

### Delete a floorplan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**In the top left, select your floorplan from the dropdown.**
{% endstep %}

{% step %}
**At the top right, click and select Floor Settings.**
{% endstep %}

{% step %}
**Under Floorplan, click Delete.**
{% endstep %}

{% step %}
**Click Confirm to delete.**
{% endstep %}
{% endstepper %}


# People Heat Maps

Learn how to access people heat maps for floor plans

People Heatmaps provide a detailed view of activity within a building by visualizing individuals’ movement history on floor plans with color-coded contours. This helps businesses analyze space utilization, identify high-traffic areas, and understand movement patterns and behavior.

### Before you begin

* You need at least **one** [floor plan](/command/organization-settings/buildings-and-floors/create-a-floorplan) uploaded with cameras placed on it.
* The cameras must be [calibrated](/command/organization-settings/buildings-and-floors/calibrate-cameras-for-floorplan-heat-maps) to set up regions of interest.
* [People analytics](/verkada-cameras/analytics/people-analytics) must be enabled on a camera before it can be calibrated.

***

## Access the People Heatmap

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans .**
{% endstep %}

{% step %}
**Select the desired building and floor you want to view.**
{% endstep %}

{% step %}
**At the bottom right, click People Heatmap.**

a. Select the desired time interval. The default is 1 hour, but you can increase it up to 1 day.

<div align="left" data-with-frame="true"><img src="/files/EDI9LKVg4c77aiSM4ncd" alt=""></div>

b. Select a date and time from the calendar menu.
{% endstep %}

{% step %}
**At the bottom left, play a timelapse to see people’s movement over time.**

{% embed url="<https://player.vimeo.com/video/795728557>" %}
{% endstep %}
{% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=wtpgjmmTnXc).
{% endhint %}


# View Live Motion

Learn how you can view live motion on your floor plan in real-time

Verkada’s motion display feature offers two ways to see live motion on your site’s floor plans in real-time.

***

## Set up motion detection

With motion detection, the camera’s field of view pulses when motion is seen. This happens in real-time.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans.**
{% endstep %}

{% step %}
**Select the building and floor plan you want to monitor.**
{% endstep %}

{% step %}
**On Floorplans, at the bottom right, click** <img src="/files/GBRPHlwSNf7wVSGjwxLr" alt="" data-size="line"> **Motion Detection.**

<div align="left" data-with-frame="true"><img src="/files/hLuFng3vyjex5ASCdcWO" alt=""></div>
{% endstep %}
{% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=wtpgjmmTnXc).
{% endhint %}


# Calibrate Cameras for Heat Maps

Calibrate cameras to use the heat maps feature on floorplans

Org Admins need to calibrate cameras to use people heat maps on floorplans. People heat maps only show on a floorplan for motion detected by cameras that have been calibrated.

{% hint style="danger" %}
People heat maps are not compatible with the following:

* D30, D50, D80, CF81, and CF83
* Cameras with analytics disabled
* Cameras configured for license plate recognition (LPR)
  {% endhint %}

***

## Calibrate cameras

{% hint style="info" %}
For best results, the camera’s field of view should be pointed straight down towards the floor/ground as much as possible. An angle of at least 70 degrees from the horizontal is recommended.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Floorplans .**
{% endstep %}

{% step %}
**Select a floorplan to calibrate cameras.**
{% endstep %}

{% step %}
**In the bottom right, select(People Heatmap).**
{% endstep %}

{% step %}
**Select the camera you want to calibrate and click Calibrate for heatmap.**
{% endstep %}

{% step %}
**In the floorplan, click and drop 4 points to select the area where you want to track people’s motions with the camera.**
{% endstep %}

{% step %}
**In the camera view, click to drop 4 points in the same order and for the same area as in the last step to complete the calibration.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
The sequence of the dropped points is important and should be identical between the floorplan and the camera floor footage. The video below illustrates how to calibrate cameras with dropped points in the correct sequence.
{% endhint %}

{% embed url="<https://player.vimeo.com/video/795748911>" %}


# Admin Settings

Manage the settings in your Verkada Command organization

The Verkada Command **Admin** page allows you to easily access everything you need to manage your Command organization.

{% hint style="warning" %}
Only Org Admins see all settings under the Admin page.
{% endhint %}

***

## Access the Admin page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select one of the following options.**

* Admin
* [Sites](/verkada-cameras/configuration/manage-sites-and-subsites)
* [Devices](/command/organization-settings/devices-page-overview)
* [Support](#h_e21edc3cc3)
  {% endstep %}
  {% endstepper %}

### Admin

|                                                                                                       |                                                                                                                                                                                                                        |
| ----------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Setting**                                                                                           | **What You Can Do**                                                                                                                                                                                                    |
| General                                                                                               | View and manage key organization contacts, partner access, and organization deletion.                                                                                                                                  |
| [Users & Permissions](/command/users-and-permissions/manage-users-in-your-organization)               | Manage users, groups, external contacts, and customize roles.                                                                                                                                                          |
| [Licenses & Renewals](/command/licensing/manage-your-licenses)                                        | View, claim, and purchase Command licenses, manage trials, and view all license transactions.                                                                                                                          |
| [Feature Manager](/command/organization-settings/manage-your-admin-page-settings/feature-manager)     | Enable, disable, or permanently remove select features from your organization for compliance, security, and/or privacy purposes.                                                                                       |
| Login & Access                                                                                        | Manage your organization’s Login & Access settings such as Enterprise Controller Encryption (ECE), Single Sign On (SSO), SCIM Configuration, Org-wide two factor authentication, and User Session Management settings. |
| Security & Logs                                                                                       | Access audit logs, manage Alerts and live links, and review the Security & Privacy Checklist.                                                                                                                          |
| [Data & Privacy](/command/security/privacy-and-security-disclosure/data-storage-processing-locations) | View public disclosures, data you’ve chosen to share with Verkada, and data residency settings.                                                                                                                        |
| [API & Integrations](/command/organization-settings/verkada-command-api)                              | Manage your organization’s API keys, integrations (Slack, Teams, etc), Webhooks, and view a list of all supported integrations.                                                                                        |
| My Account                                                                                            | Manage your personal information, password, login settings, two-factor authentication options, and view other settings such as your active sessions.                                                                   |

### Support

|                                                                                           |                                                                                                                                                                                                                                                                       |
| ----------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Setting**                                                                               | **What You Can Do**                                                                                                                                                                                                                                                   |
| [Contact Verkada Support](/command/need-help/contact-verkada-support)                     | See the 24/7 available methods to contact Verkada Support.                                                                                                                                                                                                            |
| [Enable Support Access](/command/need-help/contact-verkada-support/enable-support-access) | Temporarily allow Verkada Support to access your Command account and Verkada devices accessible by your account for troubleshooting purposes. You can revoke this access at any time.                                                                                 |
| Access Token (if Support Access is Enabled)                                               | When Verkada Support begins to use your access token, we will notify the designated Support Access Communication Recipients in the Organization Details section of Admin. If there is no custom designation of recipients, we will notify all Org Admins in your org. |
| Support Cases                                                                             | View details of open and closed support cases (chat only) for your org in the last 3 months.                                                                                                                                                                          |


# Feature Manager

Learn how to manage features for compliance requirements

With Verkada’s [Feature Manager](https://www.verkada.com/blog/control-and-oversee-features-at-the-organization-level-with-feature-manager), Org Admins can [enable](#h_f5989e7369), [disable](#h_5236e7e732), or permanently [remove](#h_c81e53f874) certain features at the organization level. Feature Manager currently controls the sharing of video links, audio recording, [People](/verkada-cameras/analytics/people-analytics) and [Vehicle Analytics](/verkada-cameras/analytics/vehicle-analytics) features, and [License Plate Recognition (LPR)](/verkada-cameras/analytics/vehicle-analytics/license-plate-recognition-overview-faq).

***

## View and set Feature Manager options

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Feature Manager.**
{% endstep %}

{% step %}
**On Feature Manager, you can manage your settings (enable, disable, remove), as needed.**
{% endstep %}
{% endstepper %}

***

## Enable a feature

When you enable a feature, it allows it to be used on devices in your organization. By default, only an [Org Admin](/command/users-and-permissions/roles-and-permissions-for-command) can enable and turn on all features.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Feature Manager.**
{% endstep %}

{% step %}
**On Feature Manager, select a feature and to the right of the feature, click the dropdown and select Enable.**
{% endstep %}
{% endstepper %}

***

## Disable a feature

When you disable a feature, it hides the ability for it to be enabled for any device in the org. For example, this prevents a Site Admin from inadvertently enabling capabilities that go against internal company guidelines.

{% hint style="warning" %}
This feature cannot be turned on for devices in your org, but is still displayed under your device’s **Settings**.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Feature Manager.**
{% endstep %}

{% step %}
**On Feature Manager, select a feature and to the right of the feature, click the dropdown and select Disable.**
{% endstep %}

{% step %}
**When prompted to confirm, click Disable.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
If necessary, any Org Admin can re-enable the disabled feature for your org.
{% endhint %}

***

## Remove a feature

The ability to completely remove a feature provides extra assurance that the feature is not being used within the org.

When you remove a feature, that feature (or features) is removed from your org and is not visible under your device’s **Settings**. When you remove a feature, it cannot be managed or reinstated within Command. Because feature removal is less easily reversible, it requires the consent of one other Organization Admin.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Feature Manager.**
{% endstep %}

{% step %}
**On Feature Manager, select a feature and to the right of the feature, click the dropdown and select Remove.**
{% endstep %}

{% step %}
**When prompted to confirm, click Next.**
{% endstep %}
{% endstepper %}

### Re-enable a removed feature

{% hint style="danger" %}
To re-enable a removed feature in your organization, an Org Admin must contact [Verkada Support](https://www.verkada.com/support/). The Org Admin will be required to sign a document to request to re-enable the feature.
{% endhint %}

***

## Download a compliance report

Feature Manager also includes a Compliance Report PDF view that provides a succinct summary of all feature settings at both the org and device level, including information on when the feature status was last modified and by whom. This report is designed to be a resource organizations can use for compliance and audit processes.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Feature Manager.**
{% endstep %}

{% step %}
**On Feature Manager, at the top right, click Compliance Report.**
{% endstep %}

{% step %}
**A report will be downloaded to your default downloads folder.**

<div align="left" data-with-frame="true"><img src="/files/TrChdhzIfPci87h0WVPU" alt="" width="563"></div>
{% endstep %}
{% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=I7CkRvFzbIY).
{% endhint %}


# Audit Logs

Learn how to access and view audit logs per camera or organization

Verkada’s audit log feature captures user and device activities that occur within the [Verkada Command](/command/getting-started/get-started-with-verkada-command) platform. These logs are maintained at 2 levels:

* **Organization level** - From the time the org is created
* **Individual camera level** - From the time the camera is added

***

## Audit log functions

The audit log tracks system access and ties each action to a user. Examples of types of events that are logged include:

* User logins
* User management (add, edit, delete users)
* Organization, site, and group creation
* Cameras moved between sites
* Video footage (live, historical, archives) viewed
* Verkada Support actions

Events contain specific information, such as:

* Timestamp of when the action took place
* IP address of the user or device that performed the action
* Username, phone number, or device that performed the action

To find what you’re looking for when reviewing system activity, filters available on the Audit Log page break down event data into the following categories:

* **What action was taken**
* **What it impacted** (user, device, or setting)
* **Who did it** (user, admin, or system)

The search interface includes a side panel with the following filter categories:

* **Time Range**
* **Actor** (User/System Initiated)
* **Event**: Admin, User Management, Device Management, Cameras, Access Control, Sensors, Alarms, New Alarms, Intercoms, Workplace, Gateway, Integrations, Others
* **Target**: User or Device
* **Device Type**:
* **Serial Number**

{% hint style="warning" %}
The **Event** filter groups related actions, making it easier to find specific event types. You can query up to 90 days of logs at once to support quarterly audits or long-term investigations.
{% endhint %}

***

## View the organization audit log

Users with [Org Admin](/verkada-cameras/getting-started/roles-and-permissions-for-cameras) permissions can access the audit log, as follows:

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Security & Logs.**
{% endstep %}

{% step %}
**Click Audit Log.**
{% endstep %}

{% step %}
**(Optional) Use AI Search to find and filter audit log events.**

{% hint style="danger" %}
Your organization must have AI-powered Search enabled to use AI Search in Audit Log. Org Admins can enable AI-powered Search by navigating to **Admin > Feature Manager > AI Features**. See [Feature Manager](/command/organization-settings/manage-your-admin-page-settings/feature-manager) for more information.
{% endhint %}
{% endstep %}

{% step %}
**(Optional) Use the default category filters to quickly view common audit log events by category.**

{% hint style="info" %}
These pre-filtered views prioritize relevant data over high-volume system logs, making it easier to focus on what matters.
{% endhint %}
{% endstep %}

{% step %}
**(Optional) Create a Custom Scheduled Report.**

1. Apply your desired filters to narrow the audit log to the relevant data.
2. Click **Save as Report** to create a custom report based on your selected filters.
3. Select **Schedule Report** to automatically email the audit log to designated recipients daily, weekly, or monthly.
   {% endstep %}

{% step %}
**Click Export to download the audit events as a CSV file.**
{% endstep %}
{% endstepper %}

***

## View per-camera audit logs

Users with [Site Admin](/verkada-cameras/getting-started/roles-and-permissions-for-cameras) permissions to the camera’s site can access the per-camera audit logs.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**
{% endstep %}

{% step %}
**Select a camera.**
{% endstep %}

{% step %}
**To the right of the camera feed, click Settings.**
{% endstep %}

{% step %}
**Under General, select Audit Log.**
{% endstep %}

{% step %}
**(Optional) Use the filters or search bar to narrow events.**
{% endstep %}

{% step %}
**Click Export to download the camera’s audit events as a CSV.**
{% endstep %}
{% endstepper %}

***

## Export the camera audit log for all cameras

Users with [Org Admin](/verkada-cameras/getting-started/roles-and-permissions-for-cameras) permissions can export a single CSV of all the camera audit logs for their organization.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**
{% endstep %}

{% step %}
**On the left navigation, click Camera Settings.**
{% endstep %}

{% step %}
**Under Export Camera Audit Log, click the dropdown and set the timeframe.**
{% endstep %}

{% step %}
**Select Export CSV.**

<div align="left" data-with-frame="true"><img src="/files/g6ScZxHgqHZHIsHSTZVV" alt="" width="595"></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
The export is limited to 30 days. To export a wider date range, multiple exports need to be performed.
{% endhint %}

***

## Export camera list

Users with [Org Admin](/verkada-cameras/getting-started/roles-and-permissions-for-cameras) permissions can export a CSV file of all camera information.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**
{% endstep %}

{% step %}
**On the left navigation, click Camera Settings.**
{% endstep %}

{% step %}
**Under Export Camera List, select Export CSV.**
{% endstep %}
{% endstepper %}

The CSV includes:

* Name of the camera
* Site
* Location
* Model
* Serial number
* Date added to org
* Device retention
* Cloud backup retention
* Firmware status
* Local IP
* Media Access Control (MAC) address
* Status
* Last online date

{% hint style="warning" %}
The export process may take up to one minute, depending on the number of cameras and the selected date range.
{% endhint %}

***

## Understand all audit log events

<details>

<summary>User logins</summary>

* **User attempted login**: Displays login success or failure, with reason
* **User attempted logout**: Displays logout success or logout failure, with reason

</details>

<details>

<summary>Verkada Support access</summary>

When a member of the Verkada Support team is granted access by a customer, the event along with the details (time, access window size, and so on) alongside the actions taken by the Support team member (for example, configuration changes) are logged. Notifications can be set for when these actions are taken.

* **Support Access**: A Verkada Support team member was granted access to the organization by an Admin user.
* **Support Access Granted**: An Admin created or modified a Verkada Support access window. This event occurs when an Admin creates or modifies the duration in which a Verkada Support team member can access the organization.

</details>

<details>

<summary>User management</summary>

* **Export Users CSV**: User list was exported from this organization
* **User Added to Organization**: User was added
* **User Removed from Organization**: User was removed
* **Users Removed from Organization**: Multiple users were removed
* **Organization User Provisioned**: User added by SCIM
* **Resent invitation for User to join Organization**: Invitation was sent to an existing user in the org
* **User Created**: New user created within the organization
* **User Invited**: New user was invited to the organization
* **User Login**: User attempted a login
* **User Logout**: User logged out
* **User Email Modified**: User’s email was changed
* **User Employment Modified**: Access user’s employee information was changed
* **User Name Modified:** User’s first and/or last name was changed
* **User Changed Password**: User changed their password
* **User Permissions Modified**: Permissions were modified for a user
* **User Roles Modified**: Permissions, including access role permissions, were modified for a user
* **User Modified RTSP Credentials**: User made an Real-Time Streaming Protocol (RTSP) change on a camera
* **User Preference Set**: User set or changed preferences
* **Two-Factor Reset**: Two-factor authentication was reset
* **SAML Config Created**: New Security Assertion Markup Language (SAML) configuration was created
* **SAML Config Deleted**: SAML configuration was deleted
* **SAML IDP Initiated:** SAML identity provider (IDP) was initiated
* **SAML Config Updated**: SAML configuration was updated
* **SCIM Provider Created**: New System for Cross-domain Identity Management (SCIM) provider created
* **SCIM Provider Deleted**: SCIM provider was deleted
* **SCIM Provider Modified**: SCIM provider was modified
* **SCIM Token Regenerated**: SCIM token has been regenerated
* **User Group Action Taken**: User group has been created, modified, or deleted
* **Users Removed from Organization**: User or set of users were removed from the organization
* **Force Logout Requested**: Admin force logged out a user

</details>

<details>

<summary>Organization, site, and group actions</summary>

* **Organization Modified**: Organization renamed in Verkada Command
* **Organization Property Modified**: Property or setting of the organization was modified
* **Site Action Taken**: Site has been created, modified, or deleted
* **Webhook Toggled**: Webhooks were enabled or disabled
* **API Key Modified**: API key was created or modified

</details>

<details>

<summary>Device management</summary>

* **Devices Installed**: User added a new device to Command
* **Devices Uninstalled**: User removed a device from Command
* **Device Remotely Accessed**: Support accessed this device
* **License Claim Event**: License key was added to the organization
* **License Grant Event**: Additional licensing was added to the organization by Verkada
* **Override Trial Event**: Verkada added more days to this organization’s trial
* **Viewing Station Grid Updated**: Change was made to a Viewing Station

</details>

<details>

<summary>Camera events</summary>

* **Archive Action Taken**: User created, modified, or deleted a video archive
* **Camera Config Modified**: User modified a camera configuration. See details for which configuration
* **Profile Image Downloaded**: User downloaded still image from camera footage
* **Profile Image Uploaded**: User uploaded an image into a profile
* **Profile Results Searched By Identity**: Profile was used for people search
* **Profile Photo Added:** User added a people profile photo
* **Profile Created**: User created and named a people profile in Command
* **Profile Deleted**: People profile was deleted
* **Profile Viewed**: User viewed a profile/person
* **Profile Merged**: User merged two profiles/people into a single profile
* **Profile Unmerged**: User unmerged a profile
* **Profile Updated**: User updated a profile
* **Profile Searched**: User searched for a profile/person
* **Profile Searched with Details**: User searched for a profile/person with attributes included
* **Profile Details Viewed**: User viewed details of a profile/person
* **Profile Searched by Uploading Image**: User uploaded an image to perform a search in Command
* **Profile Suggestions Viewed**: Suggested profiles/people were viewed by a user
* **Profile Suggestions Updated**: Suggested profiles/people were updated
* **Vehicle Searched**: A user searched for a vehicle
* **History Viewed:** User viewed historical video
* **Live Stream Started**: User started a live video stream
* **Embed Link Created**: User created a video embed link
* **Live Link Created**: User created a shareable link
* **Timelapse Action Taken**: User created, modified, deleted, or downloaded a video time lapse
* **Camera Retention Settings Updated**: A camera’s retention was changed
* **Camera Site Changed**: A camera site was modified
* **Helix Event Modified**: A helix event change was made through API
* **Video Sharing Agreement Updated**: Video sharing policy agreement has been changed.
* **Shared resource created**: An archive was shared

</details>

<details>

<summary>Access events</summary>

* **Access Alert Modified:** Access alert-related change was made
* **Aux Input Modified**: AUX input-related changed was made
* **Door Created**: New access door was created
* **Door Deleted**: Access door was deleted
* **Door Modified**: Change was made on an access door
* **Door Moved**: Door’s settings was moved to another door port
* **Elevator Modified**: Elevator-related changed was made
* **Access Group User Added**: User was added to an access group
* **Access Group Created**: New group was created for access
* **Access Group User Removed**: User was removed from an access group
* **Access Level Modified**: Access level-related change was made
* **Access Lockdown Modified**: Lockdown was modified
* **Access Muster Report Modified**: Roll call report was ran
* **Access Muster Template Modified**: Roll call template related changed was made
* **Access Device nearby Camera Modified**: Door’s camera was changed
* **Access Org Badge Template Modified**: Badge template-related change was made
* **Access Schedule Created**: User created an access schedule
* **Access Schedule Deleted**: User deleted an access schedule
* **Access Schedule Modified**: User modified an access schedule
* **Access Site Config Modified**: Access site-related change was made
* **Access Device Moved**: Access controller was moved to a different site
* **Access Method Added**: New method (badge, Bluetooth, and so on) of unlocking a door was added to a user
* **Access Method Removed**: Method of unlocking a door was removed from a user
* **Access Method Modified**: Method of unlocking a door was modified in a user
* **Access Roles Granted**: User granted access roles
* **Access Roles Revoked**: User revoked access roles
* **Access Users Exported**: User exported Access user list
* **Access Org Config Modified**: An access organization setting was changed

</details>

<details>

<summary>Alarm events</summary>

* **Alarm Settings Modified:** An alarm related change was made

</details>

<details>

<summary>Sensor events</summary>

* S**ensor Alert Config Modified**: Change was made on a sensor alert
* **Sensor Calibration**: Sensor calibration-related event was made on the org (calibrating a sensor reading and/or generation of a certificate)
* **Sensor Config Modified**: Change was made on an air quality sensor
* **Sensor Dashboard Modified**: Change was made on an air quality dashboard
* **Sensor Device Details Modified**: Air quality sensor’s name, location, and so on was changed
* **Sensor Site Changed**: Air quality sensor was moved to another site

</details>

***

### Get Audit Logs API

Command audit logs can also be retrieved via the REST API call.

The [Get Audit Logs](https://apidocs.verkada.com/reference/getauditlogsviewv1) API call returns audit logs for an organization within the time range specified. All audit logs include a timestamp in UTC format, user info, IP address, event info, and device info. See [apidocs.verkada.com](https://apidocs.verkada.com/reference/introduction) for more information.

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=J71I4rpf8Dg).
{% endhint %}


# Contacts

Learn how to manage key contacts and external contacts in your organization

Verkada Command provides multiple ways to manage contacts for your organization. You can configure key contacts that Verkada can reach, create contacts for sharing video feeds, and set up external contacts for sharing events and incidents.

***

## Key contacts

With the **Key Contacts** feature, you can designate who Verkada can contact within your organization. Key contacts ensure that we reach the appropriate person to handle billing, security, and other matters.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under General > Key Contacts, configure the desired contacts.**

<div align="left" data-with-frame="true"><img src="/files/O0r2pIpL9cmP9or7u9xh" alt=""></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You can only configure one contact per category.
{% endhint %}

***

## Create contacts

Creating contacts is a great way to save time when sharing video feeds with users on a consistent basis.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Users & Permissions > Contacts.**
{% endstep %}

{% step %}
**In the top right, click Add.**
{% endstep %}

{% step %}
**On Add Contact:**

1. Enter the person's contact details. For international users' phone numbers, click the flag (next to Phone) dropdown to change the country code.
2. Click **Save**.
   {% endstep %}
   {% endstepper %}

You can do this for each contact you want to add. The contacts then appear when you share video clips.

***

## Manage contacts

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Users & Permissions > Contacts.**
{% endstep %}

{% step %}
**Find the contact you want to manage.**
{% endstep %}

{% step %}
**At the far right of the contact's name, click** <i class="fa-ellipsis">:ellipsis:</i> **> Manage Access.**
{% endstep %}

{% step %}
**From this screen, you can revoke or edit the expiration dates for any links shared with the contact. You can also revoke all links for the contact at once.**

<div align="left" data-with-frame="true"><img src="/files/9fQo9mR80IMR84jtM3Xt" alt=""></div>
{% endstep %}
{% endstepper %}


# Delete an Organization

Learn how to delete an organization

When an organization is accidentally created or is no longer required, you can delete it. However, [all devices must be deleted from the org](/verkada-cameras/configuration/view-and-edit-camera-settings/delete-a-camera), and [all users must be removed from the org](/command/users-and-permissions/manage-users-in-your-organization) before you can delete an organization.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select General.**
{% endstep %}

{% step %}
**Under Organization Details, select Delete Organization.**
{% endstep %}
{% endstepper %}


# Create Alerts Across Verkada Products

Set up alerts to stay informed about events in your organization

Alerts notify you of important events from your organization. This allows you to shift from reactive to proactive monitoring.

The [Alerts](https://command.verkada.com/alerts/device-events) page lets users view their subscribed alerts to find important events and relevant footage. You can set up alerts for events across the [cameras](/verkada-cameras/analytics/create-camera-event-alerts), intercom, [access control](/access-control/integrations-and-alerts/configure-access-control-event-alerts), [alarms](/classic-alarms/events-and-alerts/configure-alarms-event-alerts), [gateway](/connectivity/events-and-alerts/configure-gateway-status-alerts), and [air quality](/air-quality/events-and-alerts/configure-air-quality-event-alerts) product lines.

***

## Create alerts

{% stepper %}
{% step %}
**On the Command homepage, left navigation, click Alerts.**
{% endstep %}

{% step %}
**At the top, click New Alert.**
{% endstep %}

{% step %}
**Configure the following settings:**

a. [**Events**](#h_6f8eb30046)—Events to include in the alert (type, device, site).\
b. [**Recipients**](#h_df511adc52)—Users or groups to receive the alert and their preferred forms of communication.\
c. [**Notification Schedule**](#h_ca2c27da3c)—Set when the alert sends notifications.\
d. [**Device Action**](#h_7981f1b996)—(Optional) Configure a message to play from your horn speaker when an alert triggers.\
e. [**Finish the alert**](#h_39077490ec)—Name and save the alert.
{% endstep %}
{% endstepper %}

### Create Alert > Events

{% stepper %}
{% step %}
**On Select Event, select a Verkada product and event to configure.**
{% endstep %}

{% step %}
**(Optional) Some event types are general and have more specific options once you select them. If prompted, complete the steps and click Next.**
{% endstep %}

{% step %}
**Select your devices/sites, based on the alert type you can configure events to be device-specific, site-specific, or for all devices.**

* New devices added after alert creation will automatically generate alerts if you select **Sites** or **All Devices.**
* The alarm badge designates an Alarms site if you select events by site.

Click **Done** to continue.
{% endstep %}

{% step %}
**(Optional) Some event types have additional setup steps. If that is the case, click the additional steps and follow the prompts in the configuration window.**
{% endstep %}

{% step %}
**Click Done and continue with the alert** [**recipients**](#h_df511adc52)**.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You cannot select wired sensors as individual devices. You can configure alerts for them by selecting **Sites** or **All Devices**.
{% endhint %}

### Create Alert > Notification Schedule

{% stepper %}
{% step %}
**On Notification Schedule, specify the days and times for the alerts to send notifications. Alerts generate 24/7 by default.**

<div align="left" data-with-frame="true"><img src="/files/do7C4OIhYgxUar9vnRdj" alt=""></div>
{% endstep %}

{% step %}
**Click Done and continue with the alert** [**notification**](#create-alert-greater-than-notification)**.**
{% endstep %}
{% endstepper %}

### Create Alert > Notification

{% stepper %}
{% step %}
**On Notification, add users individually or assign the alert to a group.**
{% endstep %}

{% step %}
**Select the dropdown menu next to a user or group to choose their notification method(s). Recipients can be notified via push, SMS, messaging platform alerts, or email notifications.**

<div align="left" data-with-frame="true"><figure><img src="/files/joJ6V2JNVhYtAyRboJyi" alt="" width="438"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Any recipient added to this alert will see it appear under the **Shared Alerts** section of their **Alerts** page.
{% endhint %}
{% endstep %}

{% step %}
**(Optional) By default, you will be an alert recipient. Select the dropdown menu and click Delete to remove yourself.**
{% endstep %}

{% step %}
**Click Done and continue with the alert's** [**optional settings**](#optional-settings)**, or** [**finish the alert**](#finish-the-alert)**.**
{% endstep %}
{% endstepper %}

### Optional settings

#### Create Alert > Operations

{% stepper %}
{% step %}
**Toggle on Route to Operations to create a ticket from the alert.**
{% endstep %}

{% step %}
**(Optional) Select Ticket Instructions to add information to the ticket and click Done.**
{% endstep %}

{% step %}
**Click Done and continue to** [**finish the alert**](#finish-the-alert)**.**
{% endstep %}
{% endstepper %}

#### Create Alert > Device Action

In addition to notifying individuals, you can configure your horn speaker to play when an alert is triggered. These alerts can be text-to-speech or an uploaded MP3 file.

{% stepper %}
{% step %}
**On Device Action, select the horn speaker(s) you want to play your message.**
{% endstep %}

{% step %}
**Select your notification preference (Text to Speech or Audio File).**

a. For **Text to Speech,** enter a message up to 200 characters.\
b. For **Audio File,** drag and drop the file or click **choose a file** to upload your audio clip.

<div align="left" data-with-frame="true"><img src="/files/cmdMXVOCnchM5sxvJbCQ" alt="" width="395"></div>
{% endstep %}

{% step %}
**Click Done and continue to** [**finish the alert**](#finish-the-alert)**.**
{% endstep %}
{% endstepper %}

### Finish the alert

{% stepper %}
{% step %}
**In the bottom right of the configuration window, click Next.**
{% endstep %}

{% step %}
**Enter a descriptive name for the alert.**
{% endstep %}

{% step %}
**Click Done to complete the setup.**

<div align="left" data-with-frame="true"><figure><img src="/files/T5Nvt7tMTQqgMsGZ7Vuh" alt="" width="436"><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=b697WsAOqW4).
{% endhint %}


# Manage Alerts Across Verkada Products

Edit, mute, or delete your alerts

Alerts notify you of important events from your organization. This allows you to shift from reactive to proactive monitoring.

The [Alerts](https://command.verkada.com/alerts/device-events) page lets users view their subscribed alerts to easily find important events and relevant footage. You can set up alerts for events across the cameras, intercom, [access control](/access-control/integrations-and-alerts/configure-access-control-event-alerts), [alarms](/classic-alarms/events-and-alerts/configure-alarms-event-alerts), [gateway](/connectivity/events-and-alerts/configure-gateway-status-alerts), and [air quality](/air-quality/events-and-alerts/configure-air-quality-event-alerts) product lines.

***

## Edit alerts

{% stepper %}
{% step %}
**On the Command homepage, in the left navigation, click Alerts.**
{% endstep %}

{% step %}
**Under My Alerts:**

1. Hover over the alert you want to edit.
2. To the right of the alert, click <i class="fa-ellipsis">:ellipsis:</i>.
3. Select **Edit Alert**.
4. Select the event setup step you want to edit and make any needed changes.
5. Click **Done** and repeat with other event setup steps as needed.
   {% endstep %}

{% step %}
**Click Save once all changes have been made.**

{% hint style="success" %}
Alerts configured with the old alert system containing multiple event times are not supported under the new alert system. If you see the message **Editing this alert is no longer supported,** recreate the alert to update its configuration or contact [Verkada Support.](/command/need-help/contact-verkada-support)

<img src="/files/FXBKXv9Qpt5tjkaW3IVn" alt="" data-size="original">
{% endhint %}
{% endstep %}
{% endstepper %}

***

## Mute alerts

#### Mute an alert

{% stepper %}
{% step %}
**On the Command homepage, in the left navigation, click Alerts.**
{% endstep %}

{% step %}
**Under My Alerts:**

1. Hover over the alert you want to mute.
2. To the right of the alert, click <i class="fa-ellipsis">:ellipsis:</i>.
3. Select **Mute Alert** and choose the duration. If you choose **Custom**, set the duration and click **Apply**.
   {% endstep %}
   {% endstepper %}

#### Mute all alerts

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**On Org Settings, select Manage Alerts.**
{% endstep %}

{% step %}
**In the top right, click the mute icon to mute all alerts.**

1. Choose the duration for the alert to mute.
2. (Optional) If you choose **Custom**, set the duration and click **Apply**.
3. Click **Yes** to confirm and mute all alerts.
   {% endstep %}
   {% endstepper %}

{% hint style="warning" %}
Muting an alert will only mute it for your account and not other alert recipients.
{% endhint %}

***

## Delete alerts

{% stepper %}
{% step %}
**On the Command homepage, left navigation, Alerts.**
{% endstep %}

{% step %}
**Under My Alerts:**

1. Hover over the alert you want to delete.
2. To the right of the alert, click <i class="fa-ellipsis">:ellipsis:</i>.
3. Select **Delete Alert**.
   {% endstep %}

{% step %}
**Click Delete when prompted to confirm the deletion.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You can only delete alerts that you created. Contact the admin who created a shared alert to delete it.
{% endhint %}

***

## Manage editors

You can add editors to an alert you create so other admins can also view and manage the alert. Editors can view, modify, or delete the alert from the [**Manage Alerts**](https://command.verkada.com/admin/manage-alerts) page.

{% stepper %}
{% step %}
**On the Command homepage, left navigation, Alerts.**
{% endstep %}

{% step %}
**Under My Alerts:**

1. Hover over the alert you want to manage editors.
2. To the right of the alert, click <i class="fa-ellipsis">:ellipsis:</i>.
3. Select **Manage Editors**.
4. Add or remove users or groups as needed.
   {% endstep %}

{% step %}
**Click Save to confirm the changes.**
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
Editors are **not** added as alert [recipients](/command/organization-settings/create-alerts-across-verkada-products) by default. This means editors can not see the events on their Alerts page and will not receive notifications for alerts unless they are also added as alert recipients.
{% endhint %}

***

## Find events

The Alerts page contains more information about notifications, including date and time, notification type, site, and location.

{% stepper %}
{% step %}
**On the Command homepage, left navigation, click Alerts.**
{% endstep %}

{% step %}
**(Optional) Use the filters in the search bar to narrow down the events.**
{% endstep %}

{% step %}
**Select an event to view the associated video clip.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Historical footage and thumbnails are **only** accessible for the duration of the camera’s retention.
{% endhint %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=b697WsAOqW4).
{% endhint %}


# Command Mobile App

Learn the basics of the Verkada Command mobile app

{% hint style="info" %}
If your organization uses Directories for Access Control, see [Manage Users with Directories](/command/users-and-permissions/manage-users-in-your-organization/directories-for-user-group-management) before making changes. It explains how Directories affect where users are managed and what permissions apply.
{% endhint %}

The Verkada Command mobile app allows you to access your Verkada devices right at your fingertips.

***

## Command app home screen

Once you log in to the Command mobile app, you see the homepage for cameras (organized by sites), similar to the Command web platform. At the top, you can choose to filter, search, and adjust the tile layout.

### Access the product menu

On the top left, tap <img src="/files/06yNudhP71wZrYolNS6s" alt="" data-size="line"> to open an expanded menu, where you can see products on the left and subpages on the right.

{% hint style="info" %}
To switch products faster, swipe right and tap the product icon.
{% endhint %}

{% stepper %}
{% step %}
**In the top left click** <img src="/files/IsEZMJrKcnuk8jPI5rN7" alt="" data-size="line">**.**
{% endstep %}

{% step %}
**Select the product icon to redirect to its homepage.**

<div align="left" data-with-frame="true"><img src="/files/YNzK3VoJLaxszs2701Hn" alt="" width="357"></div>
{% endstep %}
{% endstepper %}

### Additional Settings

{% stepper %}
{% step %}
**In the top left click** <img src="/files/IsEZMJrKcnuk8jPI5rN7" alt="" data-size="line">**.**
{% endstep %}

{% step %}
**At the bottom, select any of the following settings:**

a. [Help](/command/need-help/contact-verkada-support)\
b. [Scenarios](/access-control/integrations-and-alerts/configure-access-control-event-alerts/emergency-lockdown)\
c. [Devices](/command/organization-settings/devices-page-overview)\
d. [Add Device](/command/organization-settings/add-a-device-to-your-command-organization)

<div align="left" data-with-frame="true"><figure><img src="/files/6SM1UUEjyqEIYGMrtbu9" alt="" width="563"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
**Tap your organization name to introduce more information about your account and switch the organization/account.**
{% endstep %}
{% endstepper %}

### Org Settings

Org Admins can access the **Org Settings** page from the mobile app to make changes to user roles and permissions.

{% stepper %}
{% step %}
**In the top left click** <img src="/files/IsEZMJrKcnuk8jPI5rN7" alt="" data-size="line">**.**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings.**
{% endstep %}

{% step %}
**Edit the following settings as needed:**

a. Organization Details\
b. [Users](/command/users-and-permissions/manage-users-in-your-organization)\
c. [Groups](/command/users-and-permissions/manage-users-in-your-organization/manage-command-groups)
{% endstep %}
{% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=04h7HpOk7nk).
{% endhint %}


# Version Support and Updates

The Verkada Command mobile app allows users to view cameras, manage access control, receive alerts, and interact with Verkada devices from anywhere. To ensure the best experience, confirm your device meets the following requirements.

### Before you begin

Download the Command mobile app:

* [Download for iOS (App Store)](https://apps.apple.com/us/app/verkada-command/id1157022527)
* [Download for Android (Google Play)](https://play.google.com/store/apps/details?id=com.verkada.android\&hl=en_US)

***

## Supported operating systems

To ensure security, performance, and access to the latest features, we support:

* **iOS:** Current major version (e.g., iOS 17) **+ the two prior major versions**\
  **​**\*(Recommended: iOS 17 or later)\*
* **Android:** Current major version (e.g., Android 14) **+ the two prior major versions**\
  **​**\*(Recommended: Android 14 or later)\*

{% hint style="warning" %}
Devices running older OS versions may experience degraded performance or limited access to new features.
{% endhint %}

***

## Mobile app version support policy

Verkada only supports Command app versions released within the past 3 months to ensure all users have access to the latest features, performance updates, and security enhancements.

### What this means:

* Users on versions older than 3 months will be required to update to continue using the app.
* App updates are enforced on a quarterly cadence (every 3 months).

{% hint style="warning" %}
Always keep your app updated via the App Store (iOS) or Google Play (Android) to access the latest features and fixes.
{% endhint %}

### Quarterly update flow

To maintain a secure and consistent mobile experience, Verkada enforces a quarterly update cadence:

{% stepper %}
{% step %}
**Soft Reminder:**

* During the final month of the 3-month support period, users receive a full-screen notification prompting them to update.
* This prompt can be temporarily dismissed, but a persistent reminder banner will appear in the app’s **Account** tab.

  <div align="left" data-with-frame="true"><img src="/files/YC9iIzc3RPVYBqGPNMTm" alt="" width="369"></div>

{% endstep %}

{% step %}
**Forced Update:**

* Once the quarter ends, the app requires an update before it can be used.
* Users **cannot skip** the update at this stage.

  <div align="left" data-with-frame="true"><img src="/files/NrN0FTgDHCffQYZ5xJ2H" alt="" width="369"></div>

{% endstep %}
{% endstepper %}

This process ensures that all users stay current with the latest features, performance improvements, and security enhancements.


# Integrations

Connect Verkada Command with third-party services

Extend Verkada Command by connecting with your existing business tools and platforms.

***

## Available integrations

| Integration                                                                                                              | Type            | Description                                    |
| ------------------------------------------------------------------------------------------------------------------------ | --------------- | ---------------------------------------------- |
| [Slack](/command/organization-settings/integrations/set-up-verkada-alerts-for-slack-and-teams)                           | Alerts          | Send Verkada alerts to Slack recipients        |
| [Microsoft Teams](/command/organization-settings/integrations/set-up-verkada-alerts-for-slack-and-teams)                 | Alerts          | Send Verkada alerts to Teams recipients        |
| [InformaCast](/command/organization-settings/integrations/initiate-informacast-notifications-with-verkada-device-alerts) | Notifications   | Trigger mass notifications from Verkada events |
| [Axon Evidence](/command/organization-settings/integrations/set-up-the-axon-evidence-integration-in-command)             | Video export    | Export video clips to Axon Evidence            |
| [Axon Fusus](/command/organization-settings/integrations/axon-fusus-cloud-to-cloud-streaming-integration)                | Video streaming | Cloud to Cloud Streaming Integration           |
| [Fusus Camera](/command/organization-settings/integrations/set-up-the-verkada-fusus-camera-integration)                  | Video sharing   | Share camera feeds with Fusus                  |
| [Fusus LPR](/command/organization-settings/integrations/set-up-the-verkada-fusus-lpr-integration)                        | LPR             | Share license plate data with Fusus            |
| [HiveWatch](/command/organization-settings/integrations/set-up-the-verkada-hivewatch-integration)                        | Security ops    | Connect to HiveWatch platform                  |
| [Auror](/command/organization-settings/integrations/set-up-the-auror-integration-in-command)                             | Retail security | Connect to Auror retail crime platform         |
| [Splunk](/command/organization-settings/integrations/verkada-splunk-integration)                                         | SIEM            | Send audit logs to Splunk                      |

***

## Which integration should I use?

* **Want alerts in your team chat?** Use [Slack](/command/organization-settings/integrations/set-up-verkada-alerts-for-slack-and-teams) or [Microsoft Teams](/command/organization-settings/integrations/set-up-verkada-alerts-for-slack-and-teams)
* **Need mass emergency notifications?** Use [InformaCast](/command/organization-settings/integrations/initiate-informacast-notifications-with-verkada-device-alerts)
* **Using body cameras?** Use [Axon Evidence](/command/organization-settings/integrations/set-up-the-axon-evidence-integration-in-command)
* **Need centralized security ops?** Use [Fusus](/command/organization-settings/integrations/set-up-the-verkada-fusus-camera-integration) or [HiveWatch](/command/organization-settings/integrations/set-up-the-verkada-hivewatch-integration)
* **Retail loss prevention?** Use [Auror](/command/organization-settings/integrations/set-up-the-auror-integration-in-command)
* **Security monitoring/SIEM?** Use [Splunk](/command/organization-settings/integrations/verkada-splunk-integration)


# Messaging Platform Alerts

Integrate Verkada with your preferred messaging platform to receive alerts directly in your communication channels. Through these integrations, users can receive any alerts generated by Verkada Command, including Person of Interest events, AI-powered alerts, door forced open events, TVOC alerts, and more!

***

{% tabs %}
{% tab title="Slack" %}
{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API and Integrations.**
{% endstep %}

{% step %}
**Under Integrations, click Add Integration.**
{% endstep %}

{% step %}
**Select Slack.**

a. This will redirect you to the authentication page for Slack. Link your Verkada Command account with the Slack account you are currently logged into on your workstation.\
b. Review the requested permissions required for this integration and click **Allow.**

<div align="left" data-with-frame="true"><img src="/files/eXrOgSMTYy0JT1tlhF34" alt="" width="563"></div>
{% endstep %}

{% step %}
**When creating a new alert or editing an existing alert, users will now be able to add their Slack account as a recipient to their configured alert. These alerts will be sent directly to the user who has configured the notification.**

<div align="left" data-with-frame="true"><figure><img src="/files/vp5PcqVnjaslQqzdsyGe" alt="" width="375"><figcaption></figcaption></figure></div>

{% hint style="info" %}
See [Create Alerts Across Verkada Products](/command/organization-settings/create-alerts-across-verkada-products) for more information.
{% endhint %}
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="Microsoft Teams" %}
{% hint style="danger" %}
You need to [enable permissions for third-party apps](https://learn.microsoft.com/en-us/microsoftteams/manage-apps) to be installed on the Teams platform before you can set up the Verkada integration.
{% endhint %}

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API and Integrations.**
{% endstep %}

{% step %}
**Under Integrations, click Add Integration.**
{% endstep %}

{% step %}
**Select Microsoft Teams.**

a. This will redirect you to the sign-in page for Microsoft Teams. Enter your email address and password associated with your Microsoft account.

<div align="left" data-with-frame="true"><img src="/files/YHigBnlzRHiECOuvJ8wH" alt=""></div>

b. Review the requested permissions required for this integration and click **Accept**.

<div align="left" data-with-frame="true"><img src="/files/0xERvmJ0DXhxRZdyxHbG" alt=""></div>
{% endstep %}

{% step %}
**When creating a new alert or editing an existing alert, users will now be able to add their Microsoft Teams account as a recipient to their configured alert. These alerts will be sent directly to the user who has configured the notification.**

<div align="left" data-with-frame="true"><img src="/files/53ldBDDahyZpFFNukdl0" alt=""></div>

{% hint style="info" %}
See [Create Alerts Across Verkada Products](/command/organization-settings/create-alerts-across-verkada-products) for more information.
{% endhint %}
{% endstep %}
{% endstepper %}
{% endtab %}
{% endtabs %}


# InformaCast Notifications

Utilize InformaCast’s inbound emails to initiate mass notifications for Verkada alerts

You can configure Verkada devices to generate alerts based on important events in your organization. Verkada can integrate with InformaCast to consume this email and generate a mass notification.

### What you need

* An active InformaCast Fusion subscription
* Command account with at least one device

***

## Configure a message template

{% hint style="danger" %}
You need InformaCast Admin permissions for the [InformaCast Admin Portal](https://admin.icmobile.singlewire.com/) to complete this setup.
{% endhint %}

The message template is a container for the InformaCast notification content and recipients.

{% stepper %}
{% step %}
**Search for Message Templates in the left navigation search bar or navigate to Notifications > Message Templates.**
{% endstep %}

{% step %}
**Copy or create a new message template and give it a name that’s easy to recognize, such as&#x20;*****Verkada Event Notification*****.**
{% endstep %}

{% step %}
**Ensure the Subject and Body fields are customizable, indicated by the unlock icon.**
{% endstep %}

{% step %}
**In the Subject field, add placeholder text such as "\<placeholder\_text>" that will be overwritten later by the inbound email event.**

<div align="left" data-with-frame="true"><figure><img src="/files/G0xVR8vsZ6WbvQKXFSir" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
**Configure other message content settings as needed.**
{% endstep %}

{% step %}
**Click the Users tile to enable user recipients.**
{% endstep %}

{% step %}
**Add yourself as the only notification recipient. Once you create an InformaCast Verkada Command user, add the account as a notification recipient.**
{% endstep %}

{% step %}
**Click Save.**
{% endstep %}
{% endstepper %}

***

## Configure an inbound email rule set and rule

Inbound email rule sets are a list of rules that tell InformaCast to send a notification when a monitored email address receives an email.

#### Inbound email rule set

{% stepper %}
{% step %}
**Search for Email in the left navigation search bar or navigate to Notifications > Event Sources > Email.**
{% endstep %}

{% step %}
**Click Create Inbound Email Rule Set.**

a. Enter a unique name.\
b. **Set Source Email Addresses** to <no-reply@command.verkada.com>.\
c. Leave **Email Validation Level** off.\
d. Toggle on **Enable Inbound Email Rule Set.**
{% endstep %}

{% step %}
**Click Save to see an autogenerated To Address. Store this value** [**to use later in Verkada Command**](#h_8d41e7a20b)**.**

<div align="left" data-with-frame="true"><figure><img src="/files/j3ZVTh2jbY7LBgnYYYUn" alt=""><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

#### Inbound email rule

{% stepper %}
{% step %}
**Navigate to the Rules tab to set up the notification.**
{% endstep %}

{% step %}
**Click Create Inbound Email Rule.**

* Enter a unique name.
* Select the **Message Template** created in the previous section.
  {% endstep %}

{% step %}
**Toggle on Enable Inbound Email Rule.**

<div align="left" data-with-frame="true"><figure><img src="/files/ZQToYHikrx04hSP16Drl" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
**Click Save.**
{% endstep %}
{% endstepper %}

***

## Add InformaCast as a Verkada User

{% hint style="danger" %}
You need Org Admin permissions in Command to complete this setup.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Users.**
{% endstep %}

{% step %}
**In the top left, select Add User.**

a. Enter an informative name, such as InformaCast.\
b. Enter the [generated InformaCast email](#h_177b712a3c).\
c. (Optional)Assign a group to grant the user permissions.\
d. Click **Add** to create the user. **Note:** Ignore the automated invite email sent. You will verify the email address later.\
a. Click **Add** to create the user.
{% endstep %}

{% step %}
**The user profile will open. Click Assign Roles to grant the needed permissions.**
{% endstep %}
{% endstepper %}

***

## Verify the InformaCast user in Verkada Command

When a new user is added to Command, they are emailed an account setup link. Since the InformaCast email is a monitored system email that does not belong to a person we cannot access this email.

Instead, we can request a password reset to access the InformaCast user account.

{% stepper %}
{% step %}
**Log out of your Command Org Admin account.**
{% endstep %}

{% step %}
**From the Command homepage, enter the generated InformaCast email address and click Continue.**
{% endstep %}

{% step %}
**Click Forgot password? > reset via Email.**

a. An InformaCast notification via Inbound Email is generated with a link to reset your password.\
b. Click the link and set the password for the InformaCast user.
{% endstep %}

{% step %}
**Log back into your Command Org Admin account to** [**configure alerts.**](#h_7e55b69916)
{% endstep %}
{% endstepper %}

***

## Configure Verkada email alerts

Enable alerts in Command to send emails to the monitored InformaCast email to complete the integration. See [Create Camera Event Alerts](/verkada-cameras/analytics/create-camera-event-alerts) for more information on creating alerts. You can view the events from all the alerts you are subscribed to from the [Alerts](https://command.verkada.com/alerts) page in Command.

Once the alert is created:

* The Inbound Email event notification initiates in InformaCast.

{% hint style="warning" %}
You can configure the [Message Template](#h_142ffc3379) to notify any InformaCast recipient.
{% endhint %}

* A push notification will be sent to the Verkada Command mobile app.


# Axon Evidence

Axon Evidence is a digital evidence management platform designed to securely store, manage, and share critical video and multimedia evidence collected from body cameras, drones, and other devices. It streamlines workflows for law enforcement and public safety agencies, ensuring efficient collaboration and compliance with legal standards.

Through this integration, Verkada customers can seamlessly export video archives from Command to their Axon Evidence agencies to simplify digital evidence gathering and management. Using Command’s powerful investigation tools, such as AI-powered search, users can quickly find the relevant incident and add it as evidence to their Axon Evidence agency.

***

## Create Axon Evidence API client credentials

{% stepper %}
{% step %}
**Log in to your Axon Evidence account.**
{% endstep %}

{% step %}
**Navigate to Admin > Security Settings > API Settings (**[**MyAxon Documentation**](https://my.axon.com/s/article/API-Settings)**)**
{% endstep %}

{% step %}
**Select CREATE CLIENT.**

a. Name the client **Verkada Command.**\
b. Select **Evidence > any.create.**\
c. Select **Users > read.**\
d. Select **Cases > any.list**\
e. Select **Partner > category.view**\
f. Click **SAVE.**
{% endstep %}

{% step %}
**Store this value to use later in Verkada Command.**
{% endstep %}
{% endstepper %}

***

## Configure the Axon Evidence integration in Command

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Under Integrations, click Add Integration.**
{% endstep %}

{% step %}
**Select Axon.**

<div align="left" data-with-frame="true"><img src="/files/tzJmCwSHa1bM8q2ecYWw" alt=""></div>
{% endstep %}

{% step %}
**Enter your Evidence Client ID, Client Secret, Agency URI, and Agency ID, and click Connect.**

{% hint style="info" %}
Follow the [steps above](#h_fc14da2a93) to retrieve these credentials directly from the Axon Evidence Admin workflow.
{% endhint %}

<div align="left" data-with-frame="true"><img src="/files/HwNMKvRxrY3Qkggs0G6d" alt=""></div>
{% endstep %}

{% step %}
**Command will perform an authentication check to verify that the entered credentials are valid.**

<div align="left" data-with-frame="true"><img src="/files/GDlRq1nPCFDtKgdPA2CY" alt=""></div>
{% endstep %}
{% endstepper %}

***

## Export archives to Axon Evidence

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**
{% endstep %}

{% step %}
**In the left navigation, select Archives.**
{% endstep %}

{% step %}
**Hover over an archive and click** ![](/files/n8ctpG5r3nbNgZvPxTZf)**.**

1. Click **Prepare for Download.**
   1. Select the position for the **Timestamp Location.**
   2. (Optional) Toggle on [Blur Faces](/verkada-cameras/configuration/security-and-privacy/enable-face-blur-on-verkada-cameras).
2. Click **Next > Prepare Download.**
3. Click **Start Download** to save the archive to your default Downloads folder.
   {% endstep %}

{% step %}
**Hover over the archive again and click** ![](/files/n8ctpG5r3nbNgZvPxTZf)**.**

1. Select **Upload to Axon.**
2. Enter the **Axon user email** used in your Evidence account.
3. (Optional) Users can also associate the exported Archive to existing Evidence Case IDs and Categories through the corresponding dropdown menus.

{% hint style="info" %}
You may need to refine your search if you do not see the Case ID when searching in Command.
{% endhint %}

4. Click **Upload.**
   {% endstep %}

{% step %}
**You will also be able to access the video directly from your Axon Evidence account by following the link in the confirmation email. The video will also be searchable from within Axon Evidence by using the associated Case ID or Category.**

<div align="left" data-with-frame="true"><img src="/files/L3zawW2juUND6evVU6xa" alt=""></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You can find the Verkada archive in your agency’s Evidence account. All Verkada archives exported to Evidence will have a **Verkada** tag and be listed under the user who initiated the export from Command.
{% endhint %}


# Fusus Camera

Fusus by Axon is a real-time public safety platform that integrates live video feeds, data, and communication from various sources to provide a unified view for first responders and law enforcement agencies.

Through this integration, law enforcement agencies can combine Verkada’s hybrid cloud architecture with Fusus’ open platform. The integration enables users to stream both live and historical footage from Verkada cameras directly to the Fusus platform.

***

## Verkada RTSP configuration

The Fusus integration relies on RTSP streams to retrieve footage from Verkada cameras. Users must first enable RTSP in Command before adding their cameras to the Fusus platform.

Follow the steps outlined in [Verkada's Low-Latency RTSP](/verkada-cameras/video-streaming-and-sharing/live-streaming/low-latency-rtsp-streaming) to enable RTSP on your Verkada cameras.

#### Export device list

Command allows you to export a CSV list of all RTSP-enabled cameras in your organization with their respective URLs.

{% stepper %}
{% step %}
**Navigate to the Cameras page in Command.**
{% endstep %}

{% step %}
**In the navigation bar, select Camera Settings.**
{% endstep %}

{% step %}
**Next to Export List of Cameras with RTSP Enabled, click Export CSV.**
{% endstep %}
{% endstepper %}

***

## FususONE setup

Once you have enabled and retrieved the RTSP URLs for your Verkada cameras, you are ready to add them to your FususONE account.

{% stepper %}
{% step %}
**Navigate to the Fusus Locations tab and select the location to add your Verkada cameras.**

<div align="left" data-with-frame="true"><img src="/files/CKIaIOctN2jK0BvnPT2M" alt="" width="1279"></div>
{% endstep %}

{% step %}
**In the top right, the Cameras tab. This menu will allow you to add devices to the selected location.**

<div align="left" data-with-frame="true"><img src="/files/XFfYjUMtNlbZ2sZzdDVY" alt="" width="1279"></div>
{% endstep %}

{% step %}
**Enter the camera’s information in the General configuration menu. The following details are required:**

a. Camera name\
b. Type\
c. Make/Model\
d. Disposition
{% endstep %}

{% step %}
**Select the Stream tab and enter the Verkada RTSP stream details. The following parameters are required to configure the camera stream:**

a. FususCore for RTSP connection\
b. Hostname or IP address of Verkada camera\
c. Port number\
d. Verkada RTSP credentials\
e. Path (`/standard or /high` - depending on desired image quality)

{% hint style="warning" %}
For multisensor cameras, add the camera ID before the image quality in the path `<camera-id>/</standard or /high>` .
{% endhint %}

<div align="left" data-with-frame="true"><img src="/files/DywYdSE9w8x8c8AJlYhb" alt="" width="227"></div>
{% endstep %}

{% step %}
**(Optional) Enable historical footage to be stored on their connected FususCore devices and set a custom recording retention**

Your Verkada camera footage is now accessible in Fusus and ready to be streamed!

<div align="left" data-with-frame="true"><img src="/files/VHphtnuxEfG5d0uiDcUo" alt="" width="868"></div>
{% endstep %}
{% endstepper %}


# Axon Fusus

This document outlines the step-by-step setup for the Axon cloud-to-cloud streaming integration. This is a no-hardware, cloud-to-cloud solution that communicates with Axon Fusus' platform to provide access to camera streams for both live and historical footage.

{% hint style="warning" %}
This integration supports live and historical streaming from Verkada cameras and cameras connected through the Command Connector. PTZ controls are not supported.
{% endhint %}

{% hint style="danger" %}
You need [Organization Admin](/command/users-and-permissions/roles-and-permissions-for-command) permissions to set up this integration.
{% endhint %}

***

### Generate the Verkada API key

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select API & Integration > API Keys.**
{% endstep %}

{% step %}
**Copy the Organization ID, found at the top of the page.**
{% endstep %}

{% step %}
**Select** <i class="fa-plus">:plus:</i> **Add to create a new API key.**

1. Enter a name for your API Key (ex, Axon Fusus Integration)
2. Configure the following endpoints for the API Key:
   * *Cameras - Read-Only*
   * *Streaming - Live/Historical*
     * *Select the specific cameras, specific sites to include, or all sites.*
3. Select an expiration date in accordance with your security policies.
4. Click **Generate API.**
   {% endstep %}

{% step %}
**Copy and securely store the API key.**

{% hint style="danger" %}
The API key will only be shown once. If you lose it, you will have to restart the integration.
{% endhint %}
{% endstep %}
{% endstepper %}

***

### FususONE configuration

The Verkada integration is self-serve via the Fusus App Store.

{% stepper %}
{% step %}
**Open the Fusus App Store in a new browser tab.**
{% endstep %}

{% step %}
**Select Verkada from the Available section.**
{% endstep %}

{% step %}
**Select Request Integration.**
{% endstep %}

{% step %}
**Choose I am a customer of Verkada Cloud-to-Cloud.**
{% endstep %}

{% step %}
**Enter Credentials:**

* Input the Verkada Organization ID.
* Input the Verkada API Key.
  {% endstep %}

{% step %}
**Select Request Integration to establish the connection.**

<div align="left" data-with-frame="true"><figure><img src="/files/n2YB0PS7MYWKLVjPFQue" alt=""><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

***

### Verify the Integration

Once the page reloads and the integration is active, you will see the following options:

* **Camera Layer:** A new Verkada Camera layer appears. Enable the layer to display all associated cameras.
* **Live Stream:** Select a camera to open a live stream in a floating window. You can expand the stream to full screen if needed.
* **Historical Video:** Select the calendar icon to open the historical video viewer.
  * Historical streams are limited to 1-hour durations
  * A 30-minute buffer is added before and after the selected time

***

### Troubleshooting

{% hint style="info" icon="triangle-exclamation" %}
Session Management: Fusus refreshes tokens every 30 minutes. Users will be prompted to refresh or close the stream before a token expires.
{% endhint %}

* If streams fail to load, verify:
  * The API Key is valid and not expired.
  * The specific cameras were included during API Key creation.
  * The Organization ID and API Key were entered correctly in FususONE.
* Reach out to <helpdesk@fusus.com> if you need further assistance.


# Fusus LPR

Fusus by Axon is a real-time public safety platform that integrates live video feeds, data, and communication from various sources to provide a unified view for first responders and law enforcement agencies.

Through this integration, law enforcement agencies can combine Verkada’s hybrid cloud architecture with Fusus’ open platform. The integration enables real-time license plate reads from Verkada cameras to appear directly within the Fusus platform.

### What you need

* [Verkada Organization ID](#h_2670e08018)
* [Verkada Read Only API Key](#h_87b251319f)
* [Verkada Webhook Secret](#h_2dc96e9c63)

***

## Organization configuration

### **Locate your organization ID**

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Copy the Organization ID and store it in a secure place.**
{% endstep %}
{% endstepper %}

### Create an API key

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Read Only key:**

a. Click **Add API Key.**\
b. Enter a unique name.\
c. Set **Select Permission** to **Read only.**\
d. Set the **Expiration.Note:** We recommend setting the API key’s expiration date to a year from the current date. It is recommended to rotate API keys at least once a year.
{% endstep %}

{% step %}
**Copy the read only API key from Command and store it in a secure place.**
{% endstep %}
{% endstepper %}

### Create Verkada Webhook

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Click Add Webhook and enter the following information:**

a. **Webhook URL:** <https://fusus-alarms.fususone.com/verkada/webhook/>**.**\
b. **Shared Secret:** Auto-generate a password and keep a copy stored in a secure location. This shared secret will need to be added later in FususOne.\
c. Click **Add Webhook.**
{% endstep %}
{% endstepper %}

***

## Add the integration in FususOne

Provide the following details to the Fusus technical team to finalize the integration configuration.

* Verkada Organization ID
* Verkada Read Only API Key
* Verkada Webhook Secret


# HiveWatch

The HiveWatch Global Security Operations Center (GSOC) Operating System (OS) is a comprehensive Security Operations Management Platform designed to centralize and streamline various security systems, enhancing operational efficiency. This platform empowers physical security teams to make informed, data-driven decisions.

By integrating with Verkada, Command users can seamlessly connect their HiveWatch GSOC OS with Verkada security cameras and access control devices, providing a unified interface for security operators. This integration allows users to review access control events in real-time through synchronized Verkada camera feeds within the HiveWatch GSOC OS.

### What you need

* [Verkada organization ID](#h_da42c17b67)
* [Verkada API Keys](#h_611b1b0a99):
  * Read Only
  * Streaming - Live/Historical
* [Cameras](#h_ab28f0de7b)
  * Camera names
  * Camera IDs
* [Access control](#h_9aab16a63e)
  * Access controller IDs
  * Door names
  * Door IDs
* [Verkada Webhook Secret](#h_d5448bc001)

***

## Organization configuration

### Locate your organization ID

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Copy the Organization ID and store it in a secure place.**
{% endstep %}
{% endstepper %}

### Create an API key

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Read Only key:**

a. Click **Add API Key.**\
b. Enter a unique name.\
c. Set **Select Permission** to **Read only.**\
d. Set the **Expiration.Note:** We recommend setting the API key’s expiration date to a year from the current date. It is recommended to rotate API keys at least once a year.\
e. Click **Generate API Key > Copy.** The API key is only displayed once. Copy the key and store it in a secure place.
{% endstep %}

{% step %}
**Streaming - Live/Historical key:**

a. Click **Add API Key.**\
b. Enter a unique name.\
c. Set **Select Permission** to **Streaming - Live/Historical.**\
d. Set the **Expiration.Note:** We recommend setting the API key’s expiration date to a year from the current date. It is recommended to rotate API keys at least once a year.\
e. Select the sites/devices the key will apply to.\
f. Click **Generate API Key > Copy.** The API key is only displayed once. Copy the key and store it in a secure place.
{% endstep %}
{% endstepper %}

***

## Gather device info

### Cameras

You need to retrieve the camera name and camera ID for each camera that will be part of the HiveWatch organization.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**

**Note:** The HiveWatch team can assist in collecting this information for large-scale deployments. Reach out to your HiveWatch representative for assistance.
{% endstep %}

{% step %}
**Select a camera site and below the video player, click Settings.**
{% endstep %}

{% step %}
**Under General, copy the camera name and store it in a secure location.**
{% endstep %}

{% step %}
**The camera ID can be found in the browser URL. Copy the camera ID and store it with the camera name.**

<div align="left" data-with-frame="true"><img src="/files/Vzp9zwUyyNPI7EcdIwil" alt="" width="607"></div>
{% endstep %}
{% endstepper %}

### Access control

You need to retrieve the access controller ID, door name, and door ID from Command for each door that will be a part of the HiveWatch integration.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Access.**
{% endstep %}

{% step %}
**Gather controller info:**

a. At the top, select **Controllers.**\
b. Select a controller and click the controller image on the right.\
c. The controller ID can be found in the browser URL. Copy the controller ID and store it in a secure location.

<div align="left" data-with-frame="true"><img src="/files/6sYKNxj9QJVRdCtz9W9d" alt="" width="736"></div>
{% endstep %}

{% step %}
**Gather door info:**

a. Hover over a door and click .\
b. Under **General,** copy the door name and store it with the controller ID.\
c. The door ID can be found in the browser URL. Copy the door ID and store it with the door name.
{% endstep %}

{% step %}
**Click into a controller that will be used for the HiveWatch integration and copy the controller’s ID from the browser URL.**

<div align="left" data-with-frame="true"><img src="/files/wbA1cf7zqMZo4vsMy2u5" alt="" width="648"></div>
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
Contact your HiveWatch representative and provide them with the corresponding Verkada device information and API keys to complete the integration setup.
{% endhint %}

***

## Create a Verkada Webhook

{% hint style="warning" %}
The HiveWatch Implementation team will provide a unique integration URL and Shared Secret for the Webhook.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Click Add Webhook.**

a. Enter the provided **Webhook URL.**\
b. Enter the provided **Shared Secrect.**\
c. Click **Add Webhook.**
{% endstep %}
{% endstepper %}

Users now have all the required Verkada information to integrate with Verkada devices into HiveWatch’s GSOC.

The image below shows a completed integration between Verkada and HiveWatch. It displays a Verkada Door Held Open event raised within the HiveWatch GSOC, accompanied by the corresponding Verkada camera feed. This setup allows for efficient event review and response.

<div align="left" data-with-frame="true"><img src="/files/UgdWXP5HwdkQUMqfSsaB" alt=""></div>


# Auror

Auror is a retail crime intelligence platform that empowers retailers to report, solve, and prevent crimes like theft and fraud. By integrating with Verkada Command, users can seamlessly export video archives to Auror, providing visual context to incidents. With Command’s AI-powered search tools, relevant footage can be quickly identified and added as evidence to an Auror event.

***

## Configure the Auror integration

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Verkada API.**
{% endstep %}

{% step %}
**Under Integrations, click Add Integration.**
{% endstep %}

{% step %}
**Select Auror.**

<div align="left" data-with-frame="true"><img src="/files/J5faYaAmFvNMRBOjNree" alt=""></div>
{% endstep %}

{% step %}
**Set the Auror Location and enter the Client ID, Client Secret, and Subscription Key and click Connect.**

<div align="left" data-with-frame="true"><img src="/files/4LPBtaX59OVGiWY7dKtI" alt=""></div>
{% endstep %}

{% step %}
**Command will perform an authentication check to verify that the credentials entered are valid. Click Got it once the setup is complete.**

<div align="left" data-with-frame="true"><img src="/files/GfIxct0MHEm4ZamxlHNB" alt=""></div>
{% endstep %}
{% endstepper %}

***

## Export archives to Auror

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Cameras.**
{% endstep %}

{% step %}
**In the left navigation, select Archives.**
{% endstep %}

{% step %}
**Hover over an archive and click** ![](/files/n8ctpG5r3nbNgZvPxTZf)**.**

1. Click **Prepare for Download.**
   1. Select the position for the **Timestamp Location.**
   2. (Optional) Toggle on [Blur Faces](https://help.verkada.com/verkada-cameras/configuration/security-and-privacy/enable-face-blur-on-verkada-cameras).
2. Click **Next > Prepare Download.**
3. Click **Start Download** to save the archive to your default Downloads folder.
   {% endstep %}

{% step %}
**Hover over the archive again, then click**![](/files/n8ctpG5r3nbNgZvPxTZf)**.**

1. Select **Upload to Auror.**
2. Enter the **Auror Event ID** to associate with the archive.
3. Click **Upload.**

<div align="left" data-with-frame="true"><img src="/files/BFHJjUTger0Rgnv1YyNZ" alt=""></div>
{% endstep %}

{% step %}
**You will receive an email notifying you once the footage is available in Auror after a successful export. You will also be notified if the export is unsuccessful.**
{% endstep %}
{% endstepper %}

***

## View an archive in Auror

{% stepper %}
{% step %}
**Log in to your Auror account.**
{% endstep %}

{% step %}
**Open the incident associated with the archive.**
{% endstep %}

{% step %}
**Select Evidence Locker to access the archive.**

<div align="left" data-with-frame="true"><img src="/files/gAH2Ue0EXmIho8gKNlj9" alt=""></div>
{% endstep %}
{% endstepper %}


# Splunk

Learn how to set up the Verkada Splunk integration

Splunk is a software platform that helps organizations search, monitor, and analyze data from various third-party sources. Verkada allows users to build out efficient workflows to push information from their Command organizations into their Splunk instances through a built-in integration.

When you integrate Verkada with Splunk, it allows you to centralize and analyze your video surveillance data within the broader context of your operational data, which enables better insights and decision-making. You can use this implementation to bring in people and vehicle counts across all cameras in your organization, including device notifications.

{% hint style="danger" %}
Before you begin, you must have:

* An active Splunk instance with Admin access. Learn more about [Roles and Permissions for Command](/command/users-and-permissions/roles-and-permissions-for-command).
* Org Admin permissions to your Verkada organization.
* A valid Verkada API key. Learn how to [generate a Verkada API key](https://apidocs.verkada.com/reference/quick-start-guide)
  {% endhint %}

There are 2 ways you can set up the integration:

* [Download and install the Splunk Enterprise software](#h_c45403a4de)
* [Download and install the software on Splunkbase](#h_7b8e057156)

***

## Download and install the Splunk Enterprise software

{% stepper %}
{% step %}
**Download the Splunk Enterprise software at** [**https://www.splunk.com/en\_us/download.html**](https://www.splunk.com/en_us/download.html)**. If you already have a Splunk Enterprise account installed and setup, proceed to step 4.**

<div align="left" data-with-frame="true"><img src="/files/tYh2yxlN0DPbpdcVXXTk" alt="" width="800"></div>
{% endstep %}

{% step %}
**Select the corresponding installation package, depending on the operating system you are running (Windows, Linux, or MacOS). We recommend downloading the .dmg package for an easier setup process.**

<div align="left" data-with-frame="true"><img src="/files/2tNGF5K1qnOducv3Ly5l" alt="" width="800"></div>
{% endstep %}

{% step %}
**Once the Splunk Enterprise package is installed, open the application. You should be redirected to a Terminal or PowerShell window where you can create your account credentials (username and password).**

​\
​**Important**: Keep these credentials. You need them (later) to log in to Splunk and set up the Verkada integration. Once you create your account, you should receive an email to verify your account. Be sure to check your inbox and complete this step before moving forward with the setup process.
{% endstep %}

{% step %}
**The Splunk application should open automatically after setting your username and password. Log in using the credentials you set up in step 3. If the Splunk Enterprise window does not open, navigate to the following URL to log in:**

​\ <kbd><http://localhost:8000/en-US/account/login?return\\_to=%2Fen-US%2Fapp%2Flauncher%2Fhome></kbd>

<div align="left" data-with-frame="true"><img src="/files/j6nJ8P1EU7UDowqJVIr2" alt="" width="753"></div>

The Splunk homepage is where all of your applications for various integrations, including Verkada, are managed and configured.
{% endstep %}

{% step %}
**At the top left, click the Apps dropdown and select Find more apps.**

<div align="left" data-with-frame="true"><img src="/files/qzRvY3zlBFhYwt3XzGdI" alt="" width="800"></div>
{% endstep %}

{% step %}
**On Browse More Apps:**

a. In the search box, enter **Verkada**. This returns 2 applications.\
b. Install the Verkada application that has been most recently updated (**verkada add-on**).\
c. Click **Install** for the Verkada app.

<div align="left" data-with-frame="true"><img src="/files/PkpTOZglnrtcaytKSltO" alt="" width="800"></div>
{% endstep %}

{% step %}
**On Login and Install:**

1. Enter your Splunk account credentials to verify your account.

{% hint style="info" %}
These credentials are different from those created in step 3. To install the app, use the email and password used to log in to your general Splunk account. (<https://www.splunk.com/>).
{% endhint %}

2. Click **Agree and Install**.
   {% endstep %}
   {% endstepper %}

***

## Download and install the software on Splunkbase

If the [above install method](#h_c45403a4de) does not work, there is an alternative way described here.

{% stepper %}
{% step %}
**Download the app at** [**https://splunkbase.splunk.com/app/6971**](https://splunkbase.splunk.com/app/6971)**.**
{% endstep %}

{% step %}
**Click Download to download the Verkada add-on application.**

<div align="left" data-with-frame="true"><img src="/files/1kylCHTJq1cQhSd0MMOY" alt="" width="800"></div>
{% endstep %}

{% step %}
**When the package is downloaded:**

a. Go back to your Splunk Enterprise account.\
b. Under the **Apps** dropdown, select **Manage Apps**.
{% endstep %}

{% step %}
**On Manage Apps, at the top right, click Install app from file.**

<div align="left" data-with-frame="true"><img src="/files/Mvf6qDx0TL2O45GNKbYh" alt="" width="1727"></div>
{% endstep %}

{% step %}
**You are then redirected to a new page that prompts you to choose the install file for the application you want to add to your Splunk instance.**
{% endstep %}

{% step %}
**On Install App From File:**

a. Click **Choose File**.\
b. In your **Downloads** folder, find the recently downloaded file (**verkada-add-on\_126.tgz**).\
c. Select the file and click **Upload**.

<div align="left" data-with-frame="true"><img src="/files/maLFANx5k8RnAT3IWLMl" alt="" width="691"></div>
{% endstep %}

{% step %}
**Once the app is downloaded, under Apps, you should see the Verkada Add-On tab on your homepage.**

<div align="left" data-with-frame="true"><img src="/files/YlTbG5VONwL0QGUonihp" alt="" width="800"></div>
{% endstep %}

{% step %}
**Click the Verkada Add-On tab. This redirects you to a new page which is where you can set up and manage your Verkada integration.**

<div align="left" data-with-frame="true"><img src="/files/MEcEvQV2vEJ6wv4ObaUI" alt="" width="1728"></div>
{% endstep %}

{% step %}
**On your Verkada App page, at the top right, click Add Input. This allows you to create 2 different types of inputs:**

* **verkada\_insights** provides the object-detection information for each camera in your organization. At regularly scheduled intervals, it displays the count for both people and vehicles that were detected, and the associated timestamp for those counts.
* **verkada\_notifications** provides the full list of all notifications generated by your Verkada devices.
  {% endstep %}

{% step %}
**Depending on your use case with Verkada’s Splunk integration, create a new input for verkada\_insights, verkada\_notifications, or both.**

{% hint style="warning" %}
​To generate results for both options, you need to create 2 separate inputs for each feature.\
​
{% endhint %}
{% endstep %}

{% step %}
**Once you have selected your input, you are prompted to enter the following settings:**

a. Unique name for your data input\
b. Time interval (in seconds) for each processed input\
c. Index (recommended **default**)\
d. Your Verkada Command organization ID\
e. Your [Verkada API key](https://apidocs.verkada.com/reference/quick-start-guide).\
f. Click **Add**.
{% endstep %}

{% step %}
**Once you have added this new data input, you can see it under the Verkada app’s Input tab, with the corresponding name that you created in step 11.**

<div align="left" data-with-frame="true"><img src="/files/GSUex5qjGwTxdvW4ESSm" alt="" width="800"></div>
{% endstep %}

{% step %}
**Verify that the integration is successful:**

a. Go to the **Search** tab.\
b. Enter **source="verkada\_insights"** or **source="verkada\_notifications"**, depending on the data input you configured.

<div align="left" data-with-frame="true"><img src="/files/HeTYp47SvlrRXm3yBEPD" alt=""></div>

<div align="left" data-with-frame="true"><img src="/files/s8wv3ttZujQyXvKRe795" alt=""></div>

<div align="left" data-with-frame="true"><img src="/files/LgQPMSgHgFxRC79bq2X7" alt=""></div>
{% endstep %}
{% endstepper %}

***

## Troubleshooting

When updating from version 1.1.0 to version 1.2.6, there may be some new inputs which may not show up immediately. If this is the case, please follow the steps below to resolve the issue:

* Restart your Splunk instance and log back into your account.
* If all 3 inputs are still not showing up, delete and reinstall the Verkada Add-On App:
  1. Navigate to your Splunk Application directory.
  2. Delete the folder `SPLUNK_HOME/etc/apps/TA-verkada-add-on`.

{% hint style="info" %}
You may need to restart your Splunk instance for the change to take effect.
{% endhint %}

3. Proceed back to step 1 of this setup guide to download the Verkada Add-On application from Splunk.
4. You should now see the new inputs under the Verkada application.

There may be other common issues that could lead to errors in data pulling:

* Expired Verkada API key.
* Incorrect Command Organization ID

For a more detailed view and understanding of ongoing integration issues, users can access the full Splunk logs located in `SPLUNK_HOME/var/log/splunk`. You can adjust the logging level in the add-on configuration tab.


# Verkada Command API

Learn how the Verkada API allows other applications to interface with Verkada

The [Verkada Application Programmer Interface (API)](https://apidocs.verkada.com/reference/introduction) allows you to programmatically interact with the Command platform and Verkada devices. This enables you to extract data, automate tasks, and integrate with other products in a secure and scalable way.

The API is **RE**presentational **S**tate **T**ransfer (REST)-based, returns JavaScript Object Notation (JSON)-encoded responses and uses standard Hypertext Transfer Protocol Secure (HTTP) response codes.

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=pfpREEcj11M).
{% endhint %}


# Personalized Subdomain URLs

Subdomain URLs make it easy to login, share links, and access Command

Verkada provides unique Command URLs for each organization based on your organization’s short name. You can log in using your organization’s subdomain (short-name.command.verkada.com) instead of command.verkada.com.

{% hint style="info" %}
If you are unsure of your subdomain, log in to command.verkada.com, and you will be automatically redirected to your subdomain home page.
{% endhint %}

***

### Benefits

* **Direct login**: Dedicated login URL to simplify access by allowing users to go directly to their organization’s Verkada page, eliminating the need to manually select an organization after logging in.
* **Easy access**: Bookmark and deep-link directly to your desired organization (short-name.command.verkada.com vs. command.verkada.com).
* **Better password management**: Unique URLs let your password manager save distinct credentials.
* **Simplified multi-org management**: Seamlessly switch between different organizations.

{% hint style="warning" %}
Your organization’s short name is different from its organization name. If you would like to edit your organization’s short name, contact [Verkada Support](/command/need-help/contact-verkada-support).
{% endhint %}

***

### Functionality

With the implementation of subdomains, most Command functions remain the same.

* **Bookmarks**: Existing bookmarks and saved credentials will continue to work. For users in multiple organizations, Command will automatically redirect users to the correct subdomain (short-name.command.verkada.com).
* **Single Sign-On (SSO)**: Existing SSO configurations remain unchanged. Although users logging in via SSO should update any bookmarks to their new subdomain.
* **API integrations**: Integrations previously using command.verkada.com will continue to work, with requests automatically redirected.

***

## FAQs

<details>

<summary>Will my bookmarks still work?</summary>

Yes, any links to command.verkada.com will automatically redirect to your organization’s subdomain login page.

</details>

<details>

<summary>Does this change how I log in?</summary>

No, your login credentials and authentication process remain the same—only the URL is different.

</details>

<details>

<summary>What if I manage multiple organizations?</summary>

Each organization has a unique subdomain to make it easier to navigate between them. Users can bookmark multiple subdomains for quick access.

</details>

<details>

<summary>Does this impact security?</summary>

No, this is strictly a change to the login experience. All existing security measures, including SSO and multi-factor authentication (MFA), remain the same.

</details>


# Manage Your Licenses

Learn how to manage your licenses in Verkada Command

To have access to Verkada Command, you must have valid Verkada licenses for all your Verkada products.

## How Verkada licensing is applied

Verkada licensing is applied for each Command organization, and the licenses co-term to a single expiration date. This means that all of the licenses in an organization are combined, and the expiration date for the organization is the weighted average of all the individual licenses. Learn more about how to [calculate a license expiration date](/command/licensing/manage-your-licenses/calculate-license-expiration-date).

***

## View licenses and active products

Licenses and active products are available on the Command [License Manager page](https://command.verkada.com/admin/org-settings/license-manager).

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, select Licenses & Renewals > Dashboard.**
{% endstep %}
{% endstepper %}

For each product type that requires a license, you see a count of the active products and claimed licenses. If you have *less* claimed licenses than active products *for any of your product types*, your license state is **Invalid**, which means you’ll need to [claim your license key](/command/licensing/manage-your-licenses/find-and-add-license-keys-to-command) to continue using Command. Learn more about how to [manage your licenses](/command/licensing/manage-your-licenses).

{% hint style="warning" %}
If you uninstall or replace a product, for example due to a warranty replacement, you must remember to delete the product from Command. If you do not delete the product, it will continue to count against your active products. Please note that deleting a product also removes all data associated with the product (e.g., footage, camera settings), so do not delete the product before you’re absolutely certain that you will not re-add that specific device to Command.
{% endhint %}

### View the license state and expiration date

At the top left of the **Manage Licenses** page, you can see the expiration date for your licenses and the current License state of your organization. All Verkada licenses [co-term to a single expiration date](/command/licensing/manage-your-licenses), so you will only see a single expiration date even if you have bought and claimed multiple license keys.

### View license audit log

The transaction shows a log of all license actions taken in your organization, such as [claiming a new license key](/command/licensing/manage-your-licenses/find-and-add-license-keys-to-command), or unclaiming a key if it was claimed by mistake. If you have any questions regarding the transactions in your log, contact [Verkada Support](/command/need-help/contact-verkada-support).

***

## Move devices between Command organizations

Licenses do not automatically move with the device. If you need to move devices from one Command organization to another, you need to move the license keys separately. Contact <licensing@verkada.com> for support in moving device licenses between Command organizations.

***

## License requirements by product family

Refer to this table for an overview of the license requirements of each product family:

|                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Product Family**    | **License requirement**                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Access Control        | <p>One door license per door on:</p><p>AC62</p><p>AC42</p><p>AC41</p><p>AC12</p><p>AX11 IO Controller: One access IO controller license per controller</p><p>Mobile NFC: One mobile NFC credentials license per 20 users</p>                                                                                                                                                                                                                                                    |
| Alarms                | <p>One alarm license per location (physical address). Alarm licensing covers a limited number of devices and video verification events.</p><p>In addition, <strong>one license per device</strong> for the following:</p><p>BZ11 Horn speaker</p><p>Cellular backup module</p><p>Learn more about each <a href="/spaces/9tIFgMOGbY4p9wWaKQhl/pages/03s9Fw3xuxxuH2HmZbIO">alarm license each tier offered</a>.</p>                                                               |
| Cameras               | <p>One camera license per Verkada camera</p><p>One camera license per non-Verkada camera (channel) connected to a Command Connector</p><p>Optional: One Cloud Backup License per 30-day increments on a single device’s cloud retention. Learn more about <a href="https://github.com/verkada/Verkada-Support-Docs/blob/main/en/video-security/video-streaming-and-sharing/view-historical-footage/extended-cloud-backup-licensing.md">Extended Cloud Backup Licensing</a>.</p> |
| Multisensor cameras   | <p>One MLT2 camera license per two-camera multisensor</p><p>One MLT4 camera license per four-camera multisensor</p>                                                                                                                                                                                                                                                                                                                                                             |
| Environmental sensors | One sensor license per environmental sensor                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Gateway               | <p>One cellular gateway license per cellular gateway</p><p>One Wi-Fi gateway license per Wi-Fi gateway</p><p>Optional: One data plan license per connected camera or intercom. A multisensor camera needs four data licenses.</p>                                                                                                                                                                                                                                               |
| Intercom              | <p>One Intercom license per intercom device</p><p>One Desk Station license per iPad running the Verkada Desk Station app</p>                                                                                                                                                                                                                                                                                                                                                    |
| Viewing station       | One viewing station license per viewing station                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Workplace             | One Workplace license grants you access to use one Guest iPad and one Mailroom site.                                                                                                                                                                                                                                                                                                                                                                                            |

***

## Purchase Command licenses

{% hint style="warning" %}
Command licenses are available in 1, 3, 5, and 10-year terms.
{% endhint %}

There are two types of licenses: capacity increase (CAP) and renewal (RNW).

* **Capacity Increase (CAP) licenses**: Verkada CAP licenses are automatically activated when the associated Verkada hardware order is shipped. New device licenses include a 30-day extension beyond the purchased term to accommodate shipping and installation. The extension period is fixed and does not depend on when the device is installed or activated.
* **Renewal (RNW) licenses:** Verkada RNW licenses extend an organization’s existing term but remain inactive until the earlier of:
  * The date they are claimed within a Command organization or
  * One year after the purchase date. If unclaimed after one year, the license automatically activates, and its term begins to run. Any license claimed beyond this one-year period results in a shortened remaining term. This policy ensures compliance with the intended service period.

Licenses are usually sold with your Verkada devices, but you can also purchase them separately from your Verkada reseller or sales representative. See the latest [licensing prices](https://www.verkada.com/pricing/).

***

## Renew your licenses

When your licenses are soon to expire, you need to renew your license to avoid losing access to Verkada Command. You can renew your license by contacting your Verkada Sales Representative or your Verkada Reseller.

### Renewal notifications and license expiration

30 days before expiry, you will expect to:

* Receive an email notifying you that your licenses are about to expire.
* See a banner in Command.

{% hint style="danger" %}
You will lose access to Command if you haven’t renewed your license within 30 days after your expiration date.
{% endhint %}

***

## Licensing overcap policy

An organization is considered to be in overcap when it has more devices commissioned than the number of licenses claimed.

### Overcap policy

Verkada enforces software compliance by requiring each hardware product to have a valid, claimed software license(see requirements above). The Overcap policy introduces an **Invalid** status for organizations that exceed their claimed licenses, ensuring compliance across all Verkada products. After a 90-day grace period, organizations without proper licensing lose access to critical functions, including device management and notifications.

### How it works

Verkada will notify all Command users 90 days **before** an organization loses access, prompting them to claim additional licenses. Organization Admins will receive in-product banners and emails over 90 days to ensure they restore compliance.

{% hint style="danger" %}
All devices will remain functional when access to Command is restricted. However, users will still have access to the **License Manager**, **Devices**, and **Technical Support** pages when an organization is no longer compliant.
{% endhint %}

### Restore compliance

Organization Admins can perform **one** of the following actions to restore compliance:

* Claim any unused licensing keys.
* Remove any unused devices from the organization.
* Contact your Sales Representative or email <licensing@verkada.com> if you believe there has been an error with the licensing implementation on your account.

***

## FAQ

<details>

<summary>What happens if I have insufficient or expired licenses?</summary>

Verkada will send you an email notification and add a banner notification to your Command Organization.

You need valid licenses to use Command. If you don’t [claim your licenses](/command/licensing/manage-your-licenses/find-and-add-license-keys-to-command) when adding new devices or products or renew them when they expire, you will lose access to most of your Command functionality after a 30-day grace period.

* For expired organizations, you have a 30-day grace period before you lose access.
* For organizations with insufficient licenses, you have a 90-day grace period before you lose access.
* Contact your Verkada Partner or Sales Representative to purchase additional licenses.

At the end of this grace period, you will no longer have access to any of your devices or configure any settings. Alarms and Event notifications will also be disabled. You will, however, be able to delete devices and products so you get back into compliance in case you have insufficient licenses.

</details>

<details>

<summary>How will I know if my licenses are soon to expire?</summary>

30 days before your license is set to expire, Verkada will send you an email notification and add a banner notification to your Command Organization.

</details>

<details>

<summary>How do I regain full access to Command?</summary>

If your access to Command was limited due to insufficient licenses, you can:

* Delete the products that are above your license cap to get back into compliance
* Contact your Verkada Partner or Sales Representative to purchase additional licenses.

If your access to Command was limited due to expired licenses, you can contact your Verkada Partner or Sales Representative to renew your licenses.

</details>

<details>

<summary>Will my devices still record data?</summary>

As long as your Verkada devices are still connected, they will continue to record data. This data will be available when you regain access to Command (as long as you’re still within the retention period for the given device). Badges and Verkada Pass will still work as before, but you’ll be unable to change your settings via Command.

</details>

<details>

<summary>What happens if I don’t return my expired trial devices?</summary>

Trialing a Verkada device is the best way to experience how our products and platform works. You can initiate a free trial for most of our devices through your Verkada Sales Rep, or your Verkada Partner.

The free trial lasts for 30 days. After the 30 days are up, you’ll see a banner in Command reminding you to return or purchase your trial devices. If you don’t return the devices within 30 days of the expiry date they will stop working as expected.

If you need additional time to test our trial devices and platform, you can ask your Verkada Sales Rep for an extension.

</details>

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=uzn7B9k2qpU).
{% endhint %}


# License Groups

Learn how to set up and manage license groups in Verkada Command

All licensing in your Command organization typically co-terminates on a single expiration date. This limits your ability to distribute licenses across sites, budgets, or departments with different renewal dates and budget cycles.

License groups let you organize licenses and devices by site, region, or cost center, providing flexibility, improved visibility, and easier administration. Each group has its own renewal date and license capacity while remaining part of the same Command organization.

{% hint style="info" %}
We recommend starting with [Manage Licenses](/command/licensing/manage-your-licenses) to learn how organization-wide license management works if you are new to Verkada licensing.
{% endhint %}

***

### What is a license group?

License groups enable you to organize licenses into separate groups based on your specific needs, providing enhanced visibility, simplified administration, and support for internal budgeting, particularly for larger organizations with multiple departments or independently managed buildings.

Each license group serves as a container for Org Admins to organize licenses by site, budget, or cost center. Rather than managing all licenses at the organization level, you must assign them to specific groups, each with its own renewal date, while keeping everything within a single organization.

{% hint style="warning" %}
Licenses within each group still co-term to a single expiration date.
{% endhint %}

***

## Unassigned licenses

All unassigned licenses and sites are managed in the **Unassigned Licenses** section of the License Group dashboard. This section lets you review and assign unassigned resources to specific license groups, improving license management.

Licenses in this section continue to burn individually and are not co-termed with other groups until assigned. Sites display their creation date and a countdown of days remaining before their licenses begin co-terming.

<div align="left" data-with-frame="true"><img src="/files/5joSbcVb4Iu49fKpZxnn" alt=""></div>

***

## Default license group

All licenses are added to the default license group called *Group 1.* You can move licenses once you [create new groups](#h_721299d040). You can also rename the default group to reflect its purpose, such as a region or department.

***

## Enable license groups

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Feature Manager.**
{% endstep %}

{% step %}
**Under Administration, select Enable next to License Groups.**
{% endstep %}
{% endstepper %}

***

## Create a license group

{% hint style="danger" %}
You need Org Admin permissions to create a license group.
{% endhint %}

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select License Groups.**
{% endstep %}

{% step %}
**At the top, click** <i class="fa-plus">:plus:</i> **Groups.**

You can create a new license group or create one from a site.
{% endstep %}

{% step %}
**Create a new group:**

1. Select **Create New License Group.**
2. Enter a name for the group.
3. Click <i class="fa-check">:check:</i> to create the group.
   {% endstep %}

{% step %}
**Create a group from a site.**

1. Select **Create License Groups from Sites.**
2. Select a site and click **Create.**
   {% endstep %}
   {% endstepper %}

***

## Claim a new license key to a group

You can assign new purchases to the appropriate license group when you claim your license key. You can [find the license key](/command/licensing/manage-your-licenses/find-and-add-license-keys-to-command) in your Verkada order email.

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select License Keys.**
{% endstep %}

{% step %}
**In the top right, click Claim.**

1. Enter the license key from your order email and click **Next**.
2. Review the license key details and click **Claim**.
3. Select your license group and click **Next**.
4. You’ll see a preview of how the license will be co-terminated within the license group. Click **Claim Licenses** to confirm.

<div align="left" data-with-frame="true"><img src="/files/t4FpZTxzTtukMLaDSxyp" alt=""></div>
{% endstep %}
{% endstepper %}

{% hint style="info" %}
You can transfer license keys between license groups to match capacity with your devices and sites.
{% endhint %}

***

## Add an existing license key to a group

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select License Keys.**

1. Select the checkbox next to your license key.
2. At the top right, click **Move.**
3. Review the license key overview and click **Move.**
4. Select a license group and click **Next.**
5. Review the summary of how the active devices will be updated and their impact on the original group. Click **Move** to confirm.

<div align="left" data-with-frame="true"><img src="/files/aHccXoVo1Fy6Vmo1Q9qa" alt=""></div>
{% endstep %}
{% endstepper %}

***

## Manage license group renewals

You can manage license groups from the **All License Groups** tab, which shows an overview of each group and its upcoming renewal date. Each group handles the renewal of its assigned licenses.

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select License Groups.**

1. Select a license group.
2. Here you can view all the product types in the group and their compliance state.
   {% endstep %}
   {% endstepper %}

***

## Link an existing site to a license group

You must assign existing sites to license groups to link their devices with the corresponding licenses, allowing you to track active device counts against each group’s license capacity. All devices in a site linked to a license group will have their licenses co-terminated.

{% hint style="warning" %}
A site can only be assigned to one license group, while a license group can contain multiple sites.
{% endhint %}

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select Sites.**

1. Select a site with an Unassigned license group.
2. At the top right, click **Move.**
3. Select a license group and click **Next.**
4. Review the summary of how the active devices will be updated and its impact on the original group. Click **Move Si**tes to confirm.

<div align="left" data-with-frame="true"><img src="/files/lf8rTBFnEHJU7v4qRUcQ" alt="" width="563"></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Moving a site and its devices to a new License Group updates the active device counts. Licenses are not moved automatically, so you must transfer license keys separately to keep device counts and license capacity aligned.
{% endhint %}

***

## Split license keys

License key splitting lets you divide a single license key into multiple keys to allocate capacity across license groups more precisely. This is useful for aligning historical bulk orders with your organizational structure.

### How it works

* You can split one license key into two new keys.
* Splitting automatically unclaims the original key; you must manually claim the new keys to the appropriate license groups.
* Split keys inherit the original order number and creation date.
* The system calculates proportional credit allocation for each split key, preserving the total credit count.

### Split a license key

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select License Keys.**
{% endstep %}

{% step %}
**Next to the license key you want to split, click** <i class="fa-shuffle">:shuffle:</i>**.**

1. Enter the quantities to allocate to each new license key, then click **Next**.
2. Select the license group for each new license key and click **Next.**
3. Review the new allocations and click **Confirm Split.**
   {% endstep %}
   {% endstepper %}

***

## License group enforcement and access restrictions

When a license group becomes non-compliant due to expiration or exceeding license capacity, the linked sites and their devices, including any sub-sites, become inaccessible to users.

This enforcement affects only the non-compliant license group and its associated sites and devices, not the entire organization. License groups operate independently for access and compliance, minimizing disruption across the broader organization.

***

## FAQ

<details>

<summary>Can a site be assigned to multiple license groups?</summary>

No. Each site can be assigned to only one license group at a time, but a license group can include multiple sites.

</details>

<details>

<summary>Can I remove a license key from a group?</summary>

You can’t fully remove a license key from a group, but you can reassign it to a different license group at any time.

</details>

<details>

<summary>What happens if I move a site without transferring its corresponding licenses?</summary>

Devices move with the site, updating device counts in the license groups. Licenses remain in the original license group until moved manually, so you must transfer license keys to maintain compliance.

</details>


# Find and Add License Keys

Add license keys to Command to keep your organization compliant

When you add new products to Verkada Command, you **must** also claim your license key so those products can continue using Command and remain in compliance.

If you don’t claim your licenses when adding new devices or products - or renew your licenses when they expire, you will lose access to most of your Command functionality after a 30-day grace period.

***

## Find your license key

You can find the license key in your Verkada order email.

<div align="left" data-with-frame="true"><img src="/files/6Gzq8IZPHnOiEby1Ab2W" alt="" width="375"></div>

***

## Claim your license key

{% hint style="danger" %}
You need [Org Admin](/command/users-and-permissions/roles-and-permissions-for-command) permission to claim a license key in Command.
{% endhint %}

{% stepper %}
{% step %}
**In Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Admin, select Licenses & Renewals.**
{% endstep %}

{% step %}
**Select License Keys.**

1. At the top right, click **Claim.**
2. Enter the license key.

{% hint style="info" %}
License keys typically start with “CAP,” “RNW,” or “LAR.”
{% endhint %}

3. Review the license key details, then click **Proceed.**
4. Click **Claim Licenses** to complete.

<div align="left" data-with-frame="true"><img src="/files/uBMPpZ2YQwOcODDqr5qx" alt="" width="540"></div>
{% endstep %}

{% step %}
**license key typically starting with 'CAP’, ‘RNW’, or ‘LAR’)**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Contact [Verkada Support](/command/need-help/contact-verkada-support) or <licensing@verkada.com> for assistance if you need to change how you claimed your licenses.
{% endhint %}

***

## FAQ

<details>

<summary>What if I did not receive an order email?</summary>

If you did not receive an order email from Verkada with the license key, we recommend that you:

* Check your spam folder: Sometimes, the order email might be sent to your spam folder.
* Ask the person who ordered the cameras: If the order was placed by someone else in your organization, they might have received the order email.
* Ask your Verkada reseller: If your Verkada reseller handled the order, they might have received the order email.

</details>

<details>

<summary>What do I do if I am unable to locate the order email?</summary>

If you or your reseller are unable to locate the order email, contact [Verkada Support](/command/need-help/contact-verkada-support).

**What happens if I don’t claim my license?**

If you don’t claim your license after adding new products to Command, you’ll see a banner reminding you to claim your license key. All organization admins will also receive an email reminder to claim the license key after 5 days. If you don’t claim your license keys within 36 days of adding the new products, you’ll lose access to Command.

</details>

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=uzn7B9k2qpU).
{% endhint %}


# Calculate License Expiration

Learn how Verkada co-term licenses are calculated

Verkada licensing is organization-wide, and the licenses co-term to a single expiration date. The co-termination date is a weighted average of the licenses purchased and claimed by your organization.

<div align="left" data-with-frame="true"><img src="/files/zf8W52Mf3Aqd6onUFYux" alt=""></div>

#### Example

If an organization has 2 separate camera licenses:

* One 1-year (365 days) camera license intended for one CD41 camera
* One 3-year (1,095 days) camera license intended for one CB51 camera

The co-terminated expiration date would be calculated as ((1095\*1)+(365\*1))/2= 730 days total.

Assuming the 2 licenses were purchased on the same day, the organization would have a co-term expiration date of 730 days from the start date of the licenses.

***

## FAQs

<details>

<summary>What happens if I have multiple product types?</summary>

Verkada licenses are co-termed **to a single expiration date even if you have multiple product types**. The combined expiration date is still the weighted average of the individual licenses claimed into that organization. Each product is weighted by the MSRP of the license cost for that product.

For example, if an organization has 2 licenses:

* One 1-year (365 days) camera license
* One 3-year (1095 days) air quality sensor license

Because the camera license MSRP is US$199 and the air quality sensor license MSRP is US$249, the co-termination date would be calculated as:

((365\*3\*249) + (365\*1\*199)) / ((1\*249) + (1\*199)) = 771 days

Assuming the 2 licenses were bought on the same day, the co-term expiration date would be 771 days from the start of the license. If you compare that to the 730 days in the camera-only example above, you see that the co-term expiration date is at a future time. This is because Verkada Air Quality Sensor licenses are more expensive than camera licenses and, therefore, are given more weight in the co-term calculation.

</details>

<details>

<summary>What happens if I add devices in the middle of my license term?</summary>

Verkada sells 1, 3, 5, and 10-year licenses. When you add a license to an existing organization, the co-terminating expiration date is extended for all of your devices, accordingly.

**Example scenario**: You originally purchased 10 x 1-year camera licenses. Upon purchase, you have 10\*12 = 120 camera months.

120 camera-months / 10 cameras = 12 remaining months

4 months into the license term, you decide to purchase 3 x 1-year camera licenses. Immediately prior to purchase, you have 10\*8=80 camera months.

80 camera-months / 10 cameras = 8 remaining months

After purchase, you have extra credit of 3\*12=36 camera months for a total of 80+36=116 camera months. Verkada automatically applies those 36 camera months for your new 13 camera organization.

116 camera-months / 13 cameras = 8.92 remaining months

So with this new purchase, your organization’s expiration date moved forward by 0.92 months.

In this way, your organization only has a single co-terminating expiration date, avoiding the confusion associated with multiple expiration dates.

</details>

<details>

<summary>What if I want to manage multiple license renewal dates for my org?</summary>

You can create license groups to organize licenses and devices by site, region, or cost center, providing flexibility, improved visibility, and easier administration. Each group has its own renewal date and license capacity while remaining part of the same Command organization.

{% hint style="warning" %}
See [License Groups](/command/licensing/manage-your-licenses/license-groups) for more information.
{% endhint %}

</details>

<details>

<summary>What happens if I claim a license key as renewal?</summary>

When you claim a license key as a renewal, your overall expiration date will be extended based on the proportion of the renewal license purchased.

Before February 2025, renewal licenses appeared in a separate "Renewed" tab under License Manager, and Cellular Data Plan licenses were managed in a separate table in license manager with its own renewal date.

Starting in February 2025, the two renewal dates and products will be merged into a single date and table in the License Manager. This may update your licensing terms once these merge into a single, organization-wide renewal date.

</details>

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=uzn7B9k2qpU).
{% endhint %}


# Delete Unused Devices

You will need to remove unused devices to keep your licensing in compliance

To use Verkada Command, you need valid licenses for your devices and products. If you have unused devices or products, you can delete them to avoid exceeding your license cap. Follow the instructions below to delete unused devices and products.

{% hint style="warning" %}
Once your device has been deleted, all associated information, such as recorded history, will also be deleted. Please ensure you have backed up all required data before deletion.
{% endhint %}

***

## Access all unused devices to delete

You can delete all hardware that requires a license (cameras, viewing stations, alarm consoles) on the [Devices page](https://command.verkada.com/devices).

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Select the device(s) you want to delete.**
{% endstep %}

{% step %}
**At the top, click Delete.**
{% endstep %}
{% endstepper %}

### Delete an unused camera

See [Delete a Camera](/verkada-cameras/configuration/view-and-edit-camera-settings/delete-a-camera).

### Delete a unused door

See [Remove a Door from Verkada Access](/access-control/configuration/configure-a-door-in-command/remove-a-door-from-verkada-access).

### Delete an unused IO controller

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Search for "model: AX11 IO Controller".**
{% endstep %}

{% step %}
**Select the IO Controller that you want to delete, then click the controller image.**
{% endstep %}

{% step %}
**At the top right, click Settings.**
{% endstep %}

{% step %}
**At the bottom left, click the Decommission link to remove the device.**
{% endstep %}
{% endstepper %}

### Delete an unused Air Quality Sensor

See [Delete Air Quality Sensors](/air-quality/configuration/delete-air-quality-sensors-from-command).

### Delete an unused Alarms location

You can delete alarm locations on the [**Manage Sites**](https://command.verkada.com/admin/sites) page.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**On the left navigation, click the Sites icon.**
{% endstep %}

{% step %}
**On Sites, filter for the Alarm site name.**
{% endstep %}

{% step %}
**On the right panel, select the ellipsis (3 horizontal dots) icon and click Delete.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
You will need to delete all of the devices and subsites before you can delete the alarm site location.
{% endhint %}

### Delete an unused Alarms device

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Alarms.**
{% endstep %}

{% step %}
**Select the site where the alarm device lives.**
{% endstep %}

{% step %}
**At the top, select the Devices tab.**
{% endstep %}

{% step %}
**Select the device that you want to remove.**
{% endstep %}

{% step %}
**On the right panel, select the ellipsis (3 horizontal dots) icon and click Delete.**
{% endstep %}
{% endstepper %}

### Delete an unused viewing station

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Search for your Viewing Station. You can also type "vx52" in the search bar.**
{% endstep %}

{% step %}
**Click the image of the Viewing Station.**
{% endstep %}

{% step %}
**At the top right, select the kebab (3 vertical dots) icon and click Delete.**
{% endstep %}
{% endstepper %}

### Delete an unused intercom

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Intercom.**
{% endstep %}

{% step %}
**Select the Intercom that you want to delete.**
{% endstep %}

{% step %}
**At the top, click Settings.**
{% endstep %}

{% step %}
**Click Delete.**
{% endstep %}
{% endstepper %}

### Delete an unused desk station

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Intercom.**
{% endstep %}

{% step %}
**Select the Desk Station that you want to delete.**
{% endstep %}

{% step %}
**At the top right, select the kebab (3 vertical dots) icon and click Delete.**
{% endstep %}
{% endstepper %}

### Delete an unused Alarms speaker

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Devices.**
{% endstep %}

{% step %}
**Search for the Alarm Speaker that you want to delete. Alternatively, you can filter your search by typing "BZ" in the search box.**
{% endstep %}

{% step %}
**Check the box for the Alarm Speaker, and at the top right, click Delete.**
{% endstep %}
{% endstepper %}

### Delete an unused Guest tablet

You can delete a Guest tablet via the [Guest page](https://command.verkada.com/guest/), under the settings for each Guest site.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Select a Guest site that contains the unused tablet.**
{% endstep %}

{% step %}
**On the Guest menu, click Admin.**
{% endstep %}

{% step %}
**Click the dropdown and select the desired site.**
{% endstep %}

{% step %}
**In the site settings, click Tablets > the unused tablet.**
{% endstep %}

{% step %}
**Click Delete Tablet to delete the tablet.**

<div align="left" data-with-frame="true"><img src="/files/oxutzeffKN3igM2Gsdep" alt="" width="673"></div>
{% endstep %}
{% endstepper %}

### Delete an unused cellular gateway

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Gateways.**
{% endstep %}

{% step %}
**Select the gateway that you want to delete.**
{% endstep %}

{% step %}
**At the top, click Settings.**
{% endstep %}

{% step %}
**Under Device, click Delete.**
{% endstep %}
{% endstepper %}


# Product Warranty

Learn about the product warranty for all Verkada products

At Verkada, we stand by our products and are pleased to offer warranties included with the purchase of your Verkada products. Full warranty details (including hardware) are outlined in our [End User Agreement](https://www.verkada.com/support/end-user-agreement/). This agreement defines our relationship with you and our services.

Our warranties are up to 10 years, depending on the model of your Verkada device. Please check the datasheet for your device for its specific warranty information, found on our [Docs](https://www.verkada.com/docs/?contentType=datasheet) page.

Reach out to our [Support team](http://verkada.com/support) anytime you need to use the warranty.

{% hint style="warning" %}
For all products, the primary warranty limitation is that they are not damaged due to an accident, abuse or misuse, acts of God, or any unauthorized use of the hardware.
{% endhint %}


# Contact Verkada Support

Learn how to contact Verkada Support or Sales for help and questions

Your Verkada license includes enterprise support. Verkada Support is available 24/7 via phone or [live chat](#h_926781db34).

***

## Contact Verkada Support

{% hint style="danger" %}
Before you contact Verkada Support, it is best to have a support token ready. See [Enable Support Access](/command/need-help/contact-verkada-support/enable-support-access) for more information on creating a support token.
{% endhint %}

### Command navigation

{% stepper %}
{% step %}
**Log in to Verkada** [**Command**](http://command.verkada.com/login)**.**
{% endstep %}

{% step %}
**At the bottom left, click > Contact Us.**
{% endstep %}

{% step %}
**Connect with:**

* Verkada Support via live chat or phone (available 24/7).
* Verkada Sales Representative via email or phone listed for your organization.
  {% endstep %}
  {% endstepper %}

### Admin page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, click Support.**
{% endstep %}

{% step %}
**Connect with:**

* Verkada Support via live chat or phone (available 24/7).
* Verkada Sales Representative via email or phone listed for your organization.
  {% endstep %}
  {% endstepper %}

### Command app

{% stepper %}
{% step %}
**Open your Verkada Command app.**
{% endstep %}

{% step %}
**In the top left, click the menu icon.**
{% endstep %}

{% step %}
**At the bottom right, tap** <i class="fa-question">:question:</i> **> Live Chat.**

a. Tap **Messages** to open an existing case.\
b. Tap **Send us a Message** to start a new chat.
{% endstep %}
{% endstepper %}

***

### Verkada Support phone numbers

* North America: +1 (650) 514-2500
* Latin America: +52 55 9990 8275
* Europe: +44 (0)20 3048 6050
* Asia / Pacific: +61 (2725) 99300


# Enable Support Access

Allow Verkada Support temporary access to your account

[Verkada Support](/command/need-help/contact-verkada-support) may request access to your Verkada Command account to assist with troubleshooting.

{% hint style="warning" %}
Any action taken by Verkada Support in your account is included in your organization's[ audit log](/command/organization-settings/manage-your-admin-page-settings/manage-and-view-audit-logs).
{% endhint %}

***

## Enable support access

Org Admins, Site Admins, and Access Site Admins can generate and share a support access token to allow Verkada Support to access their accounts.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, click Support.**
{% endstep %}

{% step %}
**Select Enable Support Access.**
{% endstep %}

{% step %}
**Toggle on Enable Support Access and configure these additional settings as needed:**

1. [Access Duration](#access-duration)
2. [Access Token](#access-token)
3. [Enable Video and Image Access](#video-and-image-access)
4. [Limit Access to Sites](#limit-access-to-sites)

<div align="left" data-with-frame="true"><figure><img src="/files/4Wtg2dS0tkajFI1desgS" alt="" width="375"><figcaption></figcaption></figure></div>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Verkada Support **does not** automatically gain access to your account when you enable an access token. You will need to open a support case and share this token with them before they can access your account.
{% endhint %}

### Access duration

The support access duration is set to auto-expire after 24 hours by default. Admins have the option to extend access for up to 90 days.

### Access token

Access tokens are unique to each admin user account and must be provided to Verkada Support before they can access your account.

{% hint style="warning" %}
The access token grants the same permissions as the account that generated it. Verkada Support will have access to the same devices and settings that the active user has. If **Enable Video and Image Access** is toggled on, Verkada Support is able to see video and image data.
{% endhint %}

### Video and image access

Verkada Support does not have access to footage, thumbnails, archives, or audio by default. This means that Verkada Support can’t view images, video, or audio, unless you explicitly grant permission.

### Limit access to sites

Org Admins can select the sites they want to grant Verkada Support access to for enhanced privacy.

{% stepper %}
{% step %}
**From the Enable Support Access page, toggle on Limit Access to Sites.**
{% endstep %}

{% step %}
**Select the site(s) you want Verkada Support to be able to access.**
{% endstep %}

{% step %}
**Click Done when finished.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Verkada Support will not be able to access any sites within the organization if this setting is toggled on and no sites are selected.
{% endhint %}

## Revoke support access

Verkada Support will immediately lose access to your account when the access token duration expires. You can end access at any time by revoking the access token.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, click Support.**
{% endstep %}

{% step %}
**Select Enable Support Access.**
{% endstep %}

{% step %}
**Toggle off Enable Support Access.**
{% endstep %}

{% step %}
**Click Revoke to confirm.**
{% endstep %}
{% endstepper %}

## Enable support access from the Command app

{% stepper %}
{% step %}
**Open the Verkada Command app.**
{% endstep %}

{% step %}
**In the top left, click.**
{% endstep %}

{% step %}
**In the bottom left, click Help > Support Token.**
{% endstep %}

{% step %}
**On Support Access click Enable.**
{% endstep %}

{% step %}
**Configure these settings as needed:**

1. [Access Duration](#access-duration)
2. [Access Token](#access-token)
3. [Enable Video and Image Access](#video-and-image-access)
4. [Limit Access to Sites](#limit-access-to-sites)
   {% endstep %}
   {% endstepper %}

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=TbR7z6Ub-fI).
{% endhint %}


# Locate Customer ID

Locate your customer ID to share with Verkada representatives

{% hint style="danger" %}
Before you contact Verkada, you need your **Customer ID** ready to share with your representative. Your Customer ID is "C", followed by 8 digits; for example: C-XXXX-XXXX.
{% endhint %}

## Account menu

{% stepper %}
{% step %}
**Log in to your Verkada Command account.**
{% endstep %}

{% step %}
**At the bottom left, select your organization name.**
{% endstep %}

{% step %}
**Your Customer ID will be displayed at the top of the page.**
{% endstep %}
{% endstepper %}

## Help icon

{% stepper %}
{% step %}
**Log in to your Verkada Command account.**
{% endstep %}

{% step %}
**At the bottom left, click the Help (?) icon > Contact Us.**
{% endstep %}

{% step %}
**Your Customer ID will be displayed at the top of the pop-up that appears.**
{% endstep %}
{% endstepper %}

## Admin page

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**In the left navigation, click Support.**
{% endstep %}

{% step %}
**Your Customer ID will be displayed at the top of the page.**
{% endstep %}
{% endstepper %}


# Required Network Settings

Learn about the network settings you need to allow for Verkada devices to work on your network

Verkada devices need to communicate with Verkada Command, and they use the network they are connected to to do this. In most cases, minimal updates to your network settings are needed. Additional configuration may be required for complex or highly secure networks.

{% hint style="info" %}
Use the [Verkada Network Tester](https://network-tester.support.verkada.com/) to verify your devices can connect to Verkada Command. Select your region and product type to run the check.

The following endpoints must be allowed on your network for the test to work:

* speed.cloudflare.com
* network-tester.support.verkada.com
  {% endhint %}

***

## Device-specific network settings

Each device type has required domains to allow them to properly operate on the network. Select a product from the list below for more information on its required network settings.

* [Access Control Network Settings](/access-control/getting-started/access-control-network-settings)
* [Air Quality Sensor Network Settings](/air-quality/getting-started/air-quality-sensor-network-settings)
* [Alarms Network Settings](/new-alarms/getting-started/alarms-network-settings)
* [Camera Network Settings](/verkada-cameras/configuration/camera-network-settings)
* [Classic Alarms Network Settings](/classic-alarms/getting-started/classic-alarms-network-settings)
* [Command Connector Network Settings](/command-connector/getting-started/command-connector-network-settings)
* [Gateway Network Settings](/connectivity/getting-started/gateways-network-settings)
* [Guest Network Settings](/guest/getting-started/guest-network-settings)
* [Intercom Network Settings](/intercom/getting-started/intercom-network-settings)
* [Mailroom Network Settings](/mailroom/getting-started/mailroom-network-settings)
* [Viewing Station Network Settings](/viewing-station/getting-started/viewing-station-network-settings)

{% hint style="warning" %}
Some firewalls do not allow wildcards (\*), so you may need to allow each endpoint individually.
{% endhint %}

## Compatibility

Verkada devices are incompatible with local area networks (LANs) that require proxy servers or Secure Socket Layer (SSL)/Transport Layer Security (TLS) inspection. If either is in use, a bypass for all Verkada devices must be implemented for your Verkada devices to communicate with Verkada Command.

## IP address

Verkada devices must be assigned an IPv4 address to communicate on the LAN and to Verkada Command through the internet. By default, all Verkada devices use Dynamic Host Configuration Protocol (DHCP) and User Datagram Protocol (UDP) to obtain their IP addresses and network configurations.

If you require your device to have a specific IP address, create a DHCP reservation using the device’s Media Access Control (MAC) address (found on the device’s label). You can also set up [static IP addresses](/verkada-cameras/configuration/view-and-edit-camera-settings/configure-static-ip-addresses-for-cameras) in Command for cameras.

## Domain Name System

Verkada devices use the Domain Name System (DNS) server to resolve Verkada’s fully qualified domain names (FQDN) to IP addresses to communicate with them. Your DHCP server tells the Verkada device where the DNS server is on the network and the device communicates using UDP port 53.

{% hint style="warning" %}
**Note**: DNS over HTTPS (DoH) is currently not supported.
{% endhint %}

## Power

Most Verkada devices are powered through Power over Ethernet (PoE). You can use the product [datasheets](https://www.verkada.com/docs/?contentType=datasheet) to figure out the power requirements for your Verkada devices.

These are the most common power requirements:

* IEE 802.3af, Type 1 PoE
* IEEE 802.3at, Type 2 PoE+
* IEEE 802.3bt, Type 3 PoE++
* 100–240 VAC, 50/60 Hz


# Verkada Command System Requirements

Learn about requirements and supported browsers for Verkada Command

You can use [Verkada Command](https://www.verkada.com/command/#overview) to interact with and monitor all of your Verkada devices. Command allows the ability to review video from cameras, monitor alarms and device events, configure your devices, and administrate your organization.

## Guidelines for using Verkada Command

To make sure your use of Verkada Command is secure and efficient, there are certain minimum system requirements and recommendations to consider and to ensure an optimal experience with Verkada Command.

{% hint style="info" %}
We recommend regularly checking to make sure your setup meets or exceeds all of these criteria.
{% endhint %}

### Recommended compatible browsers

Command is compatible with the latest versions of these browsers:

* Google Chrome
* Safari
* Microsoft Edge
* Mozilla Firefox

{% hint style="info" %}
Ensure hardware acceleration is enabled for chromium-based browsers for best performance.
{% endhint %}

{% hint style="warning" %}
Other browsers might be able to load Command fully or partially, but this is the list of recommended browsers for an optimal experience.
{% endhint %}

### Recommended compatible operating systems

* **Windows**: Windows 10 or later
* **Mac**: MacOS 10.12 (Monterrey) or later

{% hint style="warning" %}
For newer Apple Mac models using the M series processors, all will be compatible with Command.
{% endhint %}

### Required endpoints and ports

To allow Command to load from a computer, you should allowlist the parent domain `*.verkada.com` for TCP port 443 in any filtering device between the computer and your Internet Service Provider (ISP).

We recommend allowlisting these domains:

```
verkada.com
*.verkada.com
*.*.verkada.com
*.command.verkada.com
```

For logging purposes, which help us improve the Command experience, we recommend allowlisting these domains:

```
*.datadoghq.com
*.browser-intake-datadoghq.com
```

{% hint style="warning" %}
Verkada devices have their own set of [required network settings](/command/need-help/required-network-settings), and certain functions in Command, such as [local streaming](/verkada-cameras/video-streaming-and-sharing/live-streaming/local-streaming-on-verkada-cameras) require communication between the computer and the Verkada device.
{% endhint %}


# Network Port Speeds

Learn more about the Verkada product NIC port speeds

Use this reference for network interface card speeds for Verkada devices.

{% hint style="warning" %}
All devices negotiate at full-duplex.
{% endhint %}

|                    |                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **NIC Port Speed** | **Device Model**                                                                                                                                                                                                                                                                                                                                                                                                |
| 10/100 Mbps        | <p><a href="https://docs.verkada.com/docs/video-security-dome-series-overview.pdf">Dome</a> series</p><p>CF81-E</p><p>CM41</p><p>CM41-E</p><p>CM41-S</p><p>CH52-E</p><p><a href="https://www.verkada.com/docs/?search=bullet&#x26;product=videoSecurity&#x26;contentType=datasheet">Bullet</a> series (1st and 2nd generation)</p><p>AC42</p><p>TD52</p><p>BP41</p><p>BH51</p><p>BK21</p><p>BK11</p><p>BC82</p> |
| 10/100/1000 Mbps   | <p>CB63-E</p><p>CB53-E</p><p>CD63</p><p>CD63-E</p><p>CD53</p><p>CD53-E</p><p>CD43</p><p>CD43-E</p><p>CF83-E</p><p>CM22</p><p>CM42</p><p>CM42-S</p><p>CY53-E</p><p><a href="https://docs.verkada.com/docs/video-security-ptz-series-overview.pdf">Pan-Tilt-Zoom</a> series</p><p>SV11</p><p>SV20 series</p><p>AC41</p>                                                                                           |
| 100/1000 Mbps      | <p>AX11</p><p>AC62</p><p>BZ11</p>                                                                                                                                                                                                                                                                                                                                                                               |
| 1000 Mbps          | VX52                                                                                                                                                                                                                                                                                                                                                                                                            |


# Clear Your Browser Cache

Learn how to clear your browser’s cache

If you encounter isolated, unusual behaviors while using Verkada Command, it can sometimes be due to a particular browser, and you can fix it by clearing your browser cache.

***

## Chrome

{% stepper %}
{% step %}
**Go to** [**https://command.verkada.com**](https://command.verkada.com)**.**
{% endstep %}

{% step %}
**On the left of the URL bar, click the Site Controls icon.**
{% endstep %}

{% step %}
**Click the dropdown and select Site settings > Delete data.**
{% endstep %}

{% step %}
**Click Delete.**
{% endstep %}
{% endstepper %}

## Firefox

{% stepper %}
{% step %}
**Go to** [**https://command.verkada.com**](https://command.verkada.com)**.**
{% endstep %}

{% step %}
**On the left of the URL bar, click the lock icon.**
{% endstep %}

{% step %}
**Click Clear Cookies and Site data > command.verkada.com.**
{% endstep %}

{% step %}
**Click Remove.**
{% endstep %}
{% endstepper %}

## Safari

{% stepper %}
{% step %}
**Click Safari > Preferences > Privacy.**
{% endstep %}

{% step %}
**Click Manage Website Data.**
{% endstep %}

{% step %}
**Scroll down and select verkada.com.**
{% endstep %}

{% step %}
**Click Remove.**
{% endstep %}
{% endstepper %}

## Edge

{% hint style="warning" %}
Please make sure you’re running the [latest version](https://www.microsoft.com/en-us/edge).
{% endhint %}

{% stepper %}
{% step %}
**Go to** [**https://command.verkada.com**](https://command.verkada.com)**.**
{% endstep %}

{% step %}
**On the left of the URL bar, click the lock icon.**
{% endstep %}

{% step %}
**Click Cookies.**
{% endstep %}

{% step %}
**Click Remove until all cookies have been deleted.**
{% endstep %}
{% endstepper %}


# Verkada Command Account FAQ

Learn about the common questions asked for your Verkada Command account

## Command user accounts

<details>

<summary>Can an Org Amin unlock user accounts?</summary>

Org Admins do not have the ability to unlock users who have been locked out.

</details>

<details>

<summary>Can Verkada Support unlock user accounts?</summary>

Verkada Support does not have the ability to unlock user accounts. Users must wait the full 15 minutes before they can attempt to log in again.

</details>

<details>

<summary>How can I access a user’s Command account who is no longer with the company or organization?</summary>

You need access to that user’s mailbox or add their email address as an alias to your mailbox. Once you have access to their mailbox, request to reset the password to get a password reset link via email. With the password reset link, you can reset the password to their account and log in.

</details>

<details>

<summary>How many failed login attempts does Command allow before a user gets locked out?</summary>

User accounts are locked out after 7 failed attempts.

</details>

<details>

<summary>How long is the lockout period?</summary>

The lockout period is 15 minutes.

</details>

***

## Emails

<details>

<summary>How long does the Verkada new account activation link email last before it expires?</summary>

The Verkada new account activation link expires 30 days after the email invite is sent and can only be clicked once.

</details>

<details>

<summary>How long does a Verkada password reset link email last before it expires?</summary>

The password reset link email expires after 24 hours.

</details>

***

## 2-Factor Authentication (2FA)

<details>

<summary>Is 2FA required for Org Admins?</summary>

Yes. Two-Factor Authentication (2FA) is required for all Org Admins in Command. If not already configured, Org Admins will be prompted to set it up at their next login. This requirement cannot be bypassed.

</details>

<details>

<summary>Can an Org Admin disable 2FA for another user’s account?</summary>

Yes, they can. Follow the steps outlined in [Activate 2FA for Your Command Account.](https://github.com/verkada/Verkada-Support-Docs/blob/main/en/command/users-and-permissions/enable-2fa-for-your-command-account.md)

</details>

<details>

<summary>Can Verkada Support disable 2FA for a user account?</summary>

Verkada Support does not have the ability to disable 2FA for a user.

</details>

***

## Passwords

<details>

<summary>How do I change or reset my password?</summary>

In Verkada Command, at the bottom left, click the organization where you want to change your password.On the slide-out page, click My Account.Under Security > Password, click Change.a. Enter your current password.\
b. Enter your new password twice.\
c. Click Change to confirm.Alternatively, use the password reset link, enter your email address, and click Reset via Email.

</details>

<details>

<summary>Can Org Admins reset a user’s password?</summary>

Yes, Org Admins can reset Command users’ passwords.

In Verkada Command, go to All Products > Admin.Under Org Settings > Users, select the user whose password you wish to reset.Click on the three dots next to the user’s name and click on Control Login.Click Reset Password. This will log the user out of all existing Command sessions and send them a link via email to reset their password.

</details>

<details>

<summary>What is the URL to reset a password?</summary>

The password reset URL is <https://command.verkada.com/reset-password>.

</details>

<details>

<summary>Can Verkada Support set a user’s password?</summary>

Verkada Support does not have the ability to set user passwords.

</details>

<details>

<summary>What is the Verkada password complexity requirement?</summary>

The password must be at least 8 characters, contain one number (0 to 9) and at least one special character; for example, !@#$%&.

</details>

<details>

<summary>What email address do password resets and user invites come from?</summary>

The email address is <no-reply@command.verkada.com>.

</details>

<details>

<summary>What is the password reuse policy for Command users?</summary>

Users cannot reuse any of the last 30 passwords that have been used.

</details>

<details>

<summary>Does Verkada enforce a maximum password age?</summary>

By default, Verkada does not enforce a maximum password age. To enforce this policy, integrate Verkada with SSO or Active Directory through SAML, where password age requirements can be configured.

</details>

<details>

<summary>What does it mean if a password was detected in a "data leak"</summary>

Credential stuffing is when attackers use passwords leaked in other data breaches to try to access your account.

To keep you safe, Verkada checks every new password against [Have I Been Pwned (HIBP)](https://haveibeenpwned.com/Passwords) — a trusted database of exposed passwords.

If your chosen password appears in this database, Verkada will block it and prompt you to select a stronger one. For best security, use a randomly generated password.

**How it works**

Your actual password never leaves Verkada.We create a SHA-1 hash of your password and send only the first 5 characters of that hash to HIBP.HIBP returns a list of possible matches.Verkada checks locally to see if your password is compromised without revealing your password or email address to anyone.

This process keeps your account secure while ensuring your password stays private.

</details>


# Site Planner

View all your projects in one place

The Site Planner homepage provides a centralized view of all your projects. At the top left you will see the following options:

* **My Projects**: shows all projects you have created
* **All Projects**:
  * For Org Admins: shows all projects in your partner organization
  * For other users: shows all projects you created and the ones shared with you
* **Shared with me**: show all projects shared with you by other people in your partner organization
* **Archive**: shows all deleted projects (you can restore projects if needed)

At the top right, you can:

* Search through your projects
* Manage user preferences
* Create a [new project](/command/need-help/site-planner-homepage-overview/create-site-plan-project)


# Create Site Plan Project

Learn how to Create Projects in Site Planner

{% hint style="danger" %}
You need Org Admin permissions to manage a site plan.
{% endhint %}

***

## Configuration

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**In the top right, click New Project.**
{% endstep %}

{% step %}
**On Create a project:**

a. Enter the project name (e.g., customer name)\
b. (Optional) Upload a logo or image that represents the Project\
c. Click **Create.**
{% endstep %}

{% step %}
**On Create a Location:**

a. Enter the project location.\
b. Enter the street address.\
c. Click **Create.**\
d. Click **Create a Plan.**
{% endstep %}

{% step %}
**On Create a plan:**

a. Enter a plan name.\
b. (Optional) [Upload an image of your site plan.](#h_2a141a7482)\
c. (Optional) [Set the scale of your site plan.](#h_557082cd58)\
d. (Optional) [Align your plan on the map.](#h_8174ac3e63)\
e. Click **Create.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}

* Site plans support PDF, PNG, and JPG files with a maximum size of 15MB.
* Site planner does not support multi-page PDFs. Split PDFs into single-page files before uploading.
  {% endhint %}

{% hint style="info" %}
Do not upload a site plan if you want to plot Verkada products directly on the map. The map will load at the specified location to allow you to plot products.
{% endhint %}

***

## Crop a site plan

After you upload a site plan, you can crop the file to only display the relevant portion in the plan editor.

{% stepper %}
{% step %}
**Click and drag one of the four corners to change the shape of the site plan.**
{% endstep %}

{% step %}
**Click and drag one of the four sides to change the dimensions of the site plan.**
{% endstep %}

{% step %}
**Click Done to save the changes.**
{% endstep %}
{% endstepper %}

***

## Set the site plan scale

Set the scale of your site plan to ensure accurate Verkada device ranges on the map.

{% stepper %}
{% step %}
**Select two points on the site plan.**
{% endstep %}

{% step %}
**Enter the distance between the two points. Both feet and meters are supported.**

<div align="left" data-with-frame="true"><img src="/files/lnLfCKyvMQUDgvS9MYqN" alt=""></div>
{% endstep %}

{% step %}
**Click to save.**
{% endstep %}
{% endstepper %}

{% hint style="info" %}
In the U.S., the standard door width is 3 feet. Use this as the scale by selecting two points on a door on your site plan.
{% endhint %}

***

## Align a site plan

Set the orientation of your site plan to accurately align with the map.

{% stepper %}
{% step %}
**Click and drag one of the four corners to change the size of the site plan.**
{% endstep %}

{% step %}
**Click and drag the handle at the top center of the image to change the orientation.**

<div align="left" data-with-frame="true"><img src="/files/lIbqzxZTmuLgRUJwoIIO" alt="" width="563"></div>
{% endstep %}

{% step %}
Click **Done** to save.
{% endstep %}
{% endstepper %}


# Add Locations and Sites

Add locations, site plans, and manage your project in one place

You can add additional locations and plans from the Bill of Materials page. Locations are the physical addresses of your sites. Plans are used to separate your locations into smaller sections such as floors.

{% hint style="warning" %}
Multiple Org Admins can edit and collaborate in real time on a site plan.
{% endhint %}

***

## Add location

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**Next to your project, click** <i class="fa-plus">:plus:</i>**.**

a. Enter a unique name.\
b. Enter the street address.\
c. Click **Create.**
{% endstep %}
{% endstepper %}

## Add plan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**Next to a location, click** <i class="fa-plus">:plus:</i>**.**

a. Enter a plan name.\
b. (Optional) [Upload an image of your site plan.](/command/need-help/site-planner-homepage-overview/create-site-plan-project)\
c. (Optional) [Set the scale of your site plan.](/command/need-help/site-planner-homepage-overview/create-site-plan-project)\
d. (Optional) [Align your plan on the map.](/command/need-help/site-planner-homepage-overview/create-site-plan-project)\
e. Click **Create.**
{% endstep %}
{% endstepper %}


# Add Products

This guide gives you a comprehensive overview of using the Plan Editor

Site Planner supports the entire Verkada product suite and all product lines. Add devices to your site plan to create a site mockup and generate a bill of materials.

***

## Add products

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan.**
{% endstep %}

{% step %}
**Click Add Device, under the product you want to add.**
{% endstep %}

{% step %}
**In the left navigation, select the dropdown next to a product line and select a model.**
{% endstep %}

{% step %}
**Click a spot on the map to place the device.**
{% endstep %}

{% step %}
**If the device has a field of view setting, click and drag the field of view to the correct angle.**
{% endstep %}

{% step %}
**On the right panel, at the top, name your device.**

**Note:** This name will appear in your Bill of Materials and Exports.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Quickly add additional devices by selecting a device on the plan and copy with **CTRL+C** (or **⌘+C** on Mac) and paste with **CTRL+V** (or **⌘+V** on Mac) on the plan.
{% endhint %}

***

## Product options

The product options menu on the right side of the plan editor has the following information:

* **Capabilities:** Shows details about the device (for select models)
* **Details:** Shows the device model, license, and retention (depending on product type)
* **Specs:** Shows details about the device’s hardware capabilities. Options displayed depend on product family, line, and model.

***

## Product add ons

You can select add-ons for a device, such as accessories or additional cloud data storage licensing.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan.**
{% endstep %}

{% step %}
**Click a device on the plan. The product options menu will open on the right.**

a. In the top left, click .\
b. The supported accessories are shown. Select an accessory to add it to the device.
{% endstep %}
{% endstepper %}

***

## Bulk edit

{% hint style="danger" %}
You need to enable Click to Drag to bulk edit. See [Configure Site Planner User Preferences](/command/need-help/site-planner-homepage-overview/configure-site-planner-user-preferences) for more information.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan.**
{% endstep %}

{% step %}
**Click and drag on the map to select a set of devices.**
{% endstep %}

{% step %}
**(Optionally) hold SHIFT and click on specific devices to select.**
{% endstep %}

{% step %}
**In the right panel, edit the device options as needed.**

{% hint style="warning" %}
You only see attributes you can modify across all selected devices.
{% endhint %}

<div align="left" data-with-frame="true"><img src="/files/B6H3Scx1iFi6XYz5z9b1" alt=""></div>
{% endstep %}
{% endstepper %}


# Create Walls & Barriers

Add walls and barriers to your Site Plan to show real-world field of view

You can add walls or barriers to your Site Plan to visualize the actual field of view for accurate device planning.

***

## Configuration

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan > Edit Plan.**
{% endstep %}

{% step %}
**At the top, click** <i class="fa-draw-square">:draw-square:</i>**.**

a. Click points on the site plan to add walls.\
b. (Optional) To change the shape, click on a wall to add a point and drag it in or out.\
c. Press **ESC** on your keyboard to exit.

<div align="left" data-with-frame="true"><img src="/files/eMGPk4OMCceaU3V6MJeM" alt="" width="1437"></div>
{% endstep %}
{% endstepper %}


# Visibility Options

Show and hide various elements to make it easier to manage a Site Plan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan > Edit Plan.**
{% endstep %}

{% step %}
**At the bottom, click** <i class="fa-object-intersect">:object-intersect:</i>**.**

* Deselect a product to hide it from view.

  **Note:** Hiding products **will not** remove them from the plan.
* Switch between **Satellite** and **Roadmap** to change the map view.
* Use the slider to change the size of the icons (25%-500%).

  <div align="left" data-with-frame="true"><img src="/files/yY5WL7vOqVeaqcMlVSXw" alt="" width="378"></div>

{% endstep %}
{% endstepper %}


# User Preferences

Set user preferences for pricing, Plan Editor interactions, and measurement units

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**In the top right, click** <i class="fa-gear">:gear:</i>**.**
{% endstep %}

{% step %}
**You can toggle your preference for the following settings:**

a. Under **Editor:**

* Click to Drag
* Scroll to Zoom
* Measurement Unit

e. Under **Bill of Materials:**

* Show Pricing
  {% endstep %}

{% step %}
**(Optional) In the bottom left, click Reset to defaults to revert the changes.**
{% endstep %}

{% step %}
**Click Done.**

<div align="left" data-with-frame="true"><img src="/files/Nxo80aNawRW3VTdhuWdV" alt="" width="385"></div>
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Hiding pricing allows you to present products to customers without MSRP, giving you control over cost discussions in final quotes. This removes all pricing from the editor and bill of materials.
{% endhint %}


# Keyboard Shortcuts

Use these hotkeys to make using the Plan Editor fast and easy

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner .**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan > Edit Plan.**
{% endstep %}

{% step %}
**At the top right, click** <i class="fa-circle-question">:circle-question:</i> **to see the list of available shortcuts.**

<div align="left" data-with-frame="true"><img src="/files/u9kvHH7mwjiv1qET4Fzo" alt="" width="563"></div>
{% endstep %}
{% endstepper %}


# Image Snapshot

Take a quick snapshot of your Site Plan and export as an image file

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan > Edit Plan.**
{% endstep %}

{% step %}
**At the top, click** <i class="fa-camera">:camera:</i> **> Take Snapshot.**

{% hint style="warning" %}
The file will be saved to your designated web downloads folder on your desktop.
{% endhint %}

<div align="left" data-with-frame="true"><img src="/files/SnqSPfslhsrdJU8FxLjh" alt="" width="1435"></div>
{% endstep %}
{% endstepper %}


# Export Bill of Materials

Export your Bill of Materials at the Project, Location, or Site Plan level

You can export your Site Plan to share directly with vStore or external parties, ensuring a seamless experience within our environment.

{% hint style="info" %}
The Bill of Materials can be exported at different levels—Project, Location, or Site Plan. Use the left navigation to select the desired level, ensuring the correct aggregation. When you click export, the appropriate data set will be included.
{% endhint %}

***

## Export a Site Plan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select the level you want to export (project, location, site plan)**
{% endstep %}

{% step %}
**On the right, click** <i class="fa-ellipsis">:ellipsis:</i> **> Export.**
{% endstep %}

{% step %}
**Select a file format.**

* [Verkada Store](#h_6694a4a029)
* CSV - a CSV file will be saved to your designated web downloads folder on your desktop.
  {% endstep %}
  {% endstepper %}

### Export to Verkada Store (vStore)

{% stepper %}
{% step %}
**Click Log in to vStore.**
{% endstep %}

{% step %}
**In the pop-up window, click Log In With Partner Portal.**

a. Enter your credentials.\
b. Click **Log In.**
{% endstep %}

{% step %}
**Your products will now populate on the export page.**

<div align="left" data-with-frame="true"><img src="/files/JA4V9Q4kAESkKMarhnXb" alt=""></div>
{% endstep %}

{% step %}
**Click New Draft.**

a. Enter a unique name.\
b. Click **Export.**
{% endstep %}

{% step %}
**Your draft order will populate in the vStore web portal.**

<div align="left" data-with-frame="true"><img src="/files/fqgwb5nqcL5QT6l1nNgG" alt=""></div>
{% endstep %}

{% step %}
**Click Submit Order.**
{% endstep %}
{% endstepper %}


# Duplicate a Site Plan

Make a copy of your Site Plan with previously added products

You can duplicate a site plan to easily create a new plan with all the added products and options.

***

### Duplicate a Site Plan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner .**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan.**
{% endstep %}

{% step %}
**On the right, click** <i class="fa-ellipsis">:ellipsis:</i> **> Duplicate.**
{% endstep %}

{% step %}
**Your new plan will appear in the left navigation. The default name for the new Site Plan is** `[Site Plan Name] (1)`**.**
{% endstep %}
{% endstepper %}


# Share Projects

Share your Site Plans with users, contacts, and externally

You can share your Site Plan projects with:

* Other Command users
* Command contacts
* External users emails
* Public link (share a general link anyone can access)

{% hint style="warning" %}
Sharing a project does not grant external users access to log in to Command.
{% endhint %}

***

## Share a Site Plan

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner.**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan.**
{% endstep %}

{% step %}
**On the right, click** <i class="fa-ellipsis">:ellipsis:</i> **> Share.**
{% endstep %}
{% endstepper %}

#### Command users and contact

{% stepper %}
{% step %}
**Enter the name of the recipient.**
{% endstep %}

{% step %}
**Click Save.**
{% endstep %}

{% step %}
**Click Done.**
{% endstep %}
{% endstepper %}

#### External users

{% stepper %}
{% step %}
**Enter the email address of the recipient.**
{% endstep %}

{% step %}
**Click Save.**
{% endstep %}

{% step %}
**Click Done.**
{% endstep %}
{% endstepper %}

#### Links

{% stepper %}
{% step %}
**Set the Link access.**

* **Restricted:** Only people with access can open the link
* **Public:** Anyone on the internet with the link can view
  {% endstep %}

{% step %}
**If the link access is set to restricted:**

a. Enter the name or email address of the recipient.\
b. Click **Save.**\
c. Click **Done.**
{% endstep %}

{% step %}
**Click Copy Link.**
{% endstep %}

{% step %}
**Share the link as needed.**
{% endstep %}
{% endstepper %}

***

## Reassign ownership

Org Admins can reassign the ownership of any project. Organization members can reassign ownership from themselves to another Command user.

{% hint style="danger" %}
A project can only have one owner at a time.
{% endhint %}

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Site Planner .**
{% endstep %}

{% step %}
**Under My Projects, select your project.**
{% endstep %}

{% step %}
**In the left navigation, select your plan.**
{% endstep %}

{% step %}
**On the right, click** <i class="fa-ellipsis">:ellipsis:</i> **> Share.**
{% endstep %}

{% step %}
**Next to a user, click the Viewer dropdown.**
{% endstep %}

{% step %}
**Select Make Owner.**
{% endstep %}

{% step %}
**Click Done.**
{% endstep %}
{% endstepper %}


# Partner Installation Guide

{% hint style="success" %}
End of Life Notice: Partner Tools within Verkada Command will reach end of life (EoL) on August 1, 2026. To maintain uninterrupted service and access to enhanced renewal insights, transition to the new [Partner Management Tool](https://partners.verkada.com/login) within Verkada's Partner Portal. The updated interface allows customers to control data sharing in detail and gives partners direct visibility into relevant renewal timelines.
{% endhint %}

This document offers best practice recommendations for partners setting up organizations for their customers. It should be considered a guide rather than an all-inclusive list, as each organization’s needs differ.

***

## **Create a partner organization**

Verkada suggests partners create their own Command organization to access Partner Tools and manage their devices. This allows partners to track renewals, monitor support cases, and view the contact information for the Verkada representatives assigned to each customer.

{% stepper %}
{% step %}
**Navigate to the** [**Command**](https://command.verkada.com/) **home page.**
{% endstep %}

{% step %}
[**Create a new organization.**](/command/getting-started/create-a-command-organization)
{% endstep %}

{% step %}
[**Contact Verkada Support**](/command/need-help/contact-verkada-support) **and provide your** [**organization’s short name**](/command/organization-settings/personalized-subdomain-urls-for-your-verkada-organization) **and an Org Admin email to enable the account as a Partner organization.**
{% endstep %}
{% endstepper %}

#### Things to consider

* All users in the organization should [verify their email address and phone number.](/command/security/authentication-overview/verify-your-verkada-command-account)
* [2FA](/command/security/authentication-overview/two-factor-authentication) should be enabled for users with Org Admins permissions.
* Add at least two Org Admins to your partner organization.
* Avoid using shared accounts.

***

## **Create a customer organization**

{% stepper %}
{% step %}
**Login to Command with an Org Admin account.**
{% endstep %}

{% step %}
**In the bottom left, select the icon with the initials of the organization’s name.**
{% endstep %}

{% step %}
**Click Create a new organization and follow the setup flow.**
{% endstep %}

{% step %}
**Add at least two Org Admins from the customer side for full access.**
{% endstep %}

{% step %}
**(Optional) Add at least two Org Admins from the partner side if providing managed services.**
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
**Note:** You can also create a Command organization from the Verkada Command homepage. See [Create a Command Organization](/command/getting-started/create-a-command-organization) for more information.
{% endhint %}

### **Link a customer organization to a partner organization**

Customers can manage partner access through the **Manage Verkada Partners** section of Command. This access can be granted or revoked at any time.

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin .**
{% endstep %}

{% step %}
**In the left navigation, select Org Settings > Manage Verkada Partners.**
{% endstep %}

{% step %}
**Click Add Partner.**
{% endstep %}

{% step %}
**Enter the partner** [**organization’s short name**](/command/organization-settings/personalized-subdomain-urls-for-your-verkada-organization) **and click Next.**
{% endstep %}

{% step %}
**Enter the partner’s name and toggle on which data you want to share.**
{% endstep %}

{% step %}
**Click Add Partner to complete.**
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
We do not recommend Partners enable this option without explicit written permission from the customer.
{% endhint %}

***

## Access Partner Tools <a href="#h_2d17cccbf4" id="h_2d17cccbf4"></a>

{% hint style="danger" %}
You need to be an Org Admin in the partner organization to access Partner Tools.
{% endhint %}

Partner Tools will appear in the All Products menu after your partner organization is added to a customer organization. You can see all customers who have enabled partner access on this page.

{% stepper %}
{% step %}
In Verkada Command, go to **All Products > Partner Tools** <img src="https://downloads.intercomcdn.com/i/o/q5re5q6g/1391325304/56817cf31bf3ada0d2efb1784c62/Screenshot+2025-02-21+at+12_02_43%E2%80%AFPM.png?expires=1766178000&#x26;signature=07b58f20634b26222474767df6f06b7ec25726cd53a7427e92211041605fc89c&#x26;req=dSMuF8p8mIJfXfMW3Hu4gZOBr4cHgGC1sYYQM%2FuEmHmguU749NPVL0UD5R2V%0A%2Bg%3D%3D%0A" alt="" data-size="line">.
{% endstep %}

{% step %}
The overview page displays information:

1. Licensing:
   * Detailed product breakdown of licensing for that customer's organization, including any specific licenses that may be missing
   * When a customer’s license is set to expire, enabling them to proactively reach out about renewals
2. Support cases:
   * Active support cases for that organization
   * History of cases closed over the past six months
   * Support cases and insight into the types of issues and support assistance commonly required by the customer
3. Sales Representative:
   * Name and contact information
     {% endstep %}
     {% endstepper %}

{% hint style="warning" %}
Only support cases initiated through Command live chat are shown.
{% endhint %}

***

## Best practice considerations

### Stage devices and sites

* You can [add devices](/command/organization-settings/add-a-device-to-your-command-organization) to an organization before they are physically on-site once you have the order number. This stages all devices from the order in the unassigned sites section for setup and configuration.
* If you have the floorplans and information planned out, you do have the ability to create sites and subsites and assign the devices to the sites so the installer only has to physically install and wire up the device [Manage Your Sites and Subsites | Verkada Help Center](/verkada-cameras/configuration/manage-sites-and-subsites)

### Access for installers

* You should add the installer to the customer Command organization before they go onsite to install the devices. We recommend adding installers as [temporary users](/command/users-and-permissions/manage-users-in-your-organization/manage-temporary-users) and setting an expiration date for their account access.
* Installers should plug-in devices in a staging environment before final installation to verify they come online, register, and check for firmware updates. This ensures quick installation in cases involving ladders, lifts, or other challenging scenarios.
* Installers should download the Command mobile app to assist with viewing cameras during installation. The app eliminates the need for a laptop or repeatedly climbing a ladder to check the camera angle on a desktop.

### Post-installation considerations

* Confirm with the customer if they want to keep the partner accounts as admins, reduce access permissions, or remove the accounts altogether. See [Manage Users in Your Organization](/command/users-and-permissions/manage-users-in-your-organization) for more information.
* Verkada uses [API keys](https://apidocs.verkada.com/reference/introduction) to allow customers to extract data for further analysis. Discuss with the customer if there are any managed services for alerting or reporting they would like integrated with Command.


# End-of-Sale Products

Learn the guidelines for the support availability throughout the life of a Verkada product

The Verkada Lifecycle Policy covers products and services across the portfolio that require ongoing support to remain functional and secure.

To keep pace with changing market demands, Verkada will continuously introduce functionally superior products to replace mature product lines in service.

Our life cycle policy is designed to support you as you transition from one product to the next. We are committed to keeping you informed by communicating key milestones.

***

## End-of-Sale product announcements

| Product                                                                                                                            | Announcement      | End-of-Sale Date           | End-of-Support Date |
| ---------------------------------------------------------------------------------------------------------------------------------- | ----------------- | -------------------------- | ------------------- |
| [AC42](/command/need-help/end-of-sale-products-policy-overview/ac42)                                                               | May 8, 2026       | August 6, 2026             | August 6, 2036      |
| [CB62](/command/need-help/end-of-sale-products-policy-overview/cb62)                                                               | May 7, 2026       | August 5, 2026             | August 5, 2036      |
| [CB52](/command/need-help/end-of-sale-products-policy-overview/cb52)                                                               | May 7, 2026       | August 5, 2026             | August 5, 2036      |
| [Classic Alarms (Canada)](/command/need-help/end-of-sale-products-policy-overview/classic-alarms-canada)                           | February 12, 2026 | March 15, 2026             |                     |
| [BR31 (US/CA)](/command/need-help/end-of-sale-products-policy-overview/br31-and-br32-us-ca)                                        | February 12, 2026 | March 15, 2026             |                     |
| [BR32 (US/CA)](/command/need-help/end-of-sale-products-policy-overview/br31-and-br32-us-ca)                                        | February 12, 2026 | March 15, 2026             |                     |
| [CH52-E](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-ch52-e)                              | November 4, 2025  | February 1, 2026           | February 1, 2036    |
| [CD42-F](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd42-f-cd52-f)                       | August 15, 2025   | August 15, 2025            | August 15, 2035     |
| [CD52-F](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd42-f-cd52-f)                       | August 15, 2025   | August 15, 2025            | August 15, 2035     |
| [ACCX-TBL-2](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-accx-tbl-2)                      | June 24, 2025     | September 22, 2025         |                     |
| [CD42](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd42-cd52)                             | May 1, 2025       | July 31, 2025              | August 1, 2035      |
| [CD52](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd42-cd52)                             | May 1, 2025       | July 31, 2025              | August 1, 2035      |
| [CF81-E](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cf81-e)                              | May 1, 2025       | July 31, 2025              | August 1, 2035      |
| [AD33](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-ad33)                                  | May 1, 2025       | July 31, 2025              | August 1, 2035      |
| [CD62](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd62)                                  | February 5, 2025  | May 1, 2025                | May 1, 2035         |
| [TD52](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-td52)                                  | November 11, 2024 | February 1, 2025           | February 1, 2035    |
| [ACCX-TBL-1](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-accx-tbl-1)                      | November 11, 2024 | February 9, 2025           |                     |
| [BR34](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-br34-wireless-glass-break-sensor)      | November 7, 2024  | February 7, 2025           |                     |
| [Classic Alarms (US)](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-classic-alarms-us-only) | November 7, 2024  | February 7, 2025 (US only) |                     |
| [CM41-S](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cm41-s)                              | November 6, 2024  | February 1, 2025           | February 1, 2035    |
| [AC41](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-ac41)                                  | June 4, 2024      | July 31, 2024              | July 31, 2034       |
| [CM41](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cm41)                                  | June 8, 2023      | August 31, 2023            | August 31, 2033     |
| [BC51](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-bc51)                                  | June 8, 2023      | August 31, 2023            | August 31, 2033     |
| [AD32](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-ad32)                                  | May 4, 2023       | May 5, 2023                | May 5, 2033         |
| [CB51](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cb51-cb61)                             | February 16, 2023 | May 20, 2023               | May 20, 2033        |
| [CB61](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cb51-cb61)                             | February 16, 2023 | May 20, 2023               | May 20, 2033        |
| [SV11](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-sv11)                                  | December 14, 2022 | March 1, 2023              | March 1, 2033       |
| [CM61](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-d30-cm61)                              | March 31, 2022    | June 30, 2022              | June 30, 2032       |
| [D30](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-d30-cm61)                               | March 31, 2022    | June 30, 2022              | June 30, 2032       |
| [AD31](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-ad31)                                  | March 21, 2022    | April 30, 2022             | April 30, 2032      |
| [CD41](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd41)                                  | January 25, 2022  | February 25, 2022          | February 25, 2032   |
| [D80](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-d40-d80)                                | December 31, 2021 | January 31, 2022           | January 31, 2032    |
| [D40](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-d40-d80)                                | December 31, 2021 | January 31, 2022           | January 31, 2032    |
| [CD51](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd51-and-cd61)                         | December 30, 2021 | January 30, 2022           | January 30, 2032    |
| [CD61](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-cd51-and-cd61)                         | August 30, 2021   | September 30, 2021         | September 30, 2031  |
| [D50](/command/need-help/end-of-sale-products-policy-overview/end-of-sale-announcement-for-d50)                                    | April 1, 2020     | May 1, 2020                | May 1, 2030         |

***

## Key milestones

{% hint style="info" %}
**Key definitions**

* [**End-of-Sale announcement**](#h_91f1fc51eb) **(this article)**: Official End-of-Sales notice.
* [**End-of-Sale date**](#h_68a382d03d): The last date to order the product through Verkada.
* [**End-of-Support date**](#h_6516b0503b): The last date a product will be supported by Verkada.
  {% endhint %}

### End-of-Sale announcement

Date of official end-of-sale notice, typically one (1) month prior to the last order date. Products being discontinued will be announced as end-of-sale and identified on the [Verkada Updates](https://www.verkada.com/updates/) webpage.

### End-of-Sale date

The last date to order the product through a Verkada-authorized reseller. Discontinued products are removed from the [Pricing](https://www.verkada.com/pricing/) webpage and are no longer available for purchase. Device-specific licenses corresponding to discontinued hardware products will remain available after the end-of-sale date unless otherwise specified in the announcement. After the end-of-sale date, Verkada will continue to support the discontinued product until the end-of-support date. Verkada typically provides support for a given product for a period of ten (10) years after the end-of-sale date.

### End-of-Support date

The last date a product will be supported by Verkada, generally up to ten (10) years after the end-of-sale date. After the end-of-support date, Verkada will no longer:

* Guarantee the legacy product will be able to connect or remain indefinitely compatible with the management platform, Verkada Command
* Provide Technical Support for troubleshooting
* Issue firmware updates or automatic patches for the hardware
* Ensure new software features available through the management platform, Command, are compatible with the hardware or the firmware running on it

{% hint style="warning" %}
**\*** If these situations occur, [Verkada Support](/command/need-help/contact-verkada-support) will do its best to provide a workable solution.
{% endhint %}

***

## FAQ

<details>

<summary>Can customers return a discontinued product that they purchased prior to the end-of-sale date?</summary>

Customers may return any product *within 30 days of purchase*.

</details>

<details>

<summary>What happens if a discontinued product under warranty needs to be replaced?</summary>

Verkada will replace return merchandise authorization (RMA) units with the same discontinued product. If the discontinued product is no longer available for replacement, Verkada will replace the discontinued product with functionally equivalent hardware, and transfer the remaining license term to the replacement hardware.

</details>

<details>

<summary>What if a customer upgrades their legacy hardware to newer hardware?</summary>

Verkada will transfer the remaining value of any licenses attributable to the legacy hardware for use with the new updated hardware the customer purchased.

</details>

<details>

<summary>What if Verkada no longer is able to offer the Cloud Service?</summary>

Under our End User Agreement, Verkada gives our customers a license to use Verkada’s software. Without the software, customers will have limited or no access to their data, Verkada’s product features and Verkada’s Software, and Verkada’s hardware will not function as designed. However, in the event of Verkada’s dissolution, winding up, or other inability to continue providing its software to its customers, upon written request from a customer, Verkada will update the firmware on the ***camera*** hardware that the customer purchased in order to support RTSP streaming on a commercially reasonable timeline.

</details>


# AC42

Learn details about the end-of-sale for the Verkada AC42 Four Door Access Controller

Verkada is announcing the end-of-sale for the following products:

| Product  | SKU     | Description               |
| -------- | ------- | ------------------------- |
| **AC42** | AC42–HW | AC42 Four–Door Controller |

The following products will replace the above products:

| Product    | SKU       | Description                                          |
| ---------- | --------- | ---------------------------------------------------- |
| **AC43**   | AC43-HW   | AC43 Four-Door Controller                            |
| **AC43-G** | AC43-HW-G | AC43 4 Door Controller for Government, FIPS 140, TAA |

{% hint style="danger" %}
Final orders for **AC42** must be received by **August 6, 2026**. End-of-Support date for these products is **August 6, 2036.**
{% endhint %}

***

## Key definitions <a href="#h_807747ae69" id="h_807747ae69"></a>

* End-of-Sale Announcement: Official End-of-Sales notice.
* End-of-Sale Date: The last date to order the product through Verkada.
* End-of-Support Date: The last date a product will be supported by Verkada.

## FAQ

<details>

<summary>What does this mean?</summary>

As of August 6, 2026, we will no longer sell AC42 SKUs. However, we will continue to provide support for the product through our 10-year warranty period.

</details>

<details>

<summary>Can customers return products that they purchased?</summary>

Customers can return products *within 30 days of purchase*.

</details>

<details>

<summary>What happens if a product under warranty needs to be replaced?</summary>

We will replace RMA units with the same model, if available. Otherwise, we will replace them with the next most similar product.

</details>

***


# CB62

Learn details about the end-of-sale information for the Verkada CB62

Verkada is announcing the end-of-sale for the following products:

| Product     | SKU           | Description                                                                                 |
| ----------- | ------------- | ------------------------------------------------------------------------------------------- |
| **CB62-E**  | CB62-512E-HW  | Verkada CB62-E Outdoor Bullet Camera, 4K, Zoom Lens, 512GB, 30 Days of Retention            |
|             | CB62-1TBE-HW  | Verkada CB62-E Outdoor Bullet Camera, 4K, Zoom Lens, 1TB, 60 Days of Retention              |
|             | CB62-2TBE-HW  | Verkada CB62-E Outdoor Bullet Camera, 4K, Zoom Lens, 2TB, 90 Days of Retention              |
| **CB62-TE** | CB62-512TE-HW | Verkada CB62-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 256GB, 30 Days of Retention |
|             | CB62-1TBTE-HW | Verkada CB62-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 512GB, 60 Days of Retention |
|             | CB62-2TBTE-HW | Verkada CB62-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 768GB, 90 Days of Retention |

The following products will replace the above products:

| Product     | SKU           | Description                                                                                 |
| ----------- | ------------- | ------------------------------------------------------------------------------------------- |
| **CB63-E**  | CB63-512E-HW  | Verkada CB63-E Outdoor Bullet Camera, 4K, Zoom Lens, 512GB, 30 Days of Retention            |
|             | CB63-1TBE-HW  | Verkada CB63-E Outdoor Bullet Camera, 4K, Zoom Lens, 1TB, 60 Days of Retention              |
|             | CB63-2TBE-HW  | Verkada CB63-E Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 2TB, 90 Days of Retention    |
|             | CB63-3TBE-HW  | Verkada CB63-E Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 3TB, 120 Days of Retention   |
| **CB63-TE** | CB63-512TE-HW | Verkada CB63-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 512GB, 30 Days of Retention |
|             | CB63-1TBTE-HW | Verkada CB63-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 1TB, 60 Days of Retention   |
|             | CB63-2TBTE-HW | Verkada CB63-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 2TB, 90 Days of Retention   |
|             | CB63-3TBTE-HW | Verkada CB63-TE Outdoor Bullet Camera, 4K, Telephoto Zoom Lens, 3TB, 120 Days of Retention  |

{% hint style="danger" %}
Final orders for **CB62 products** must be received by **August 5, 2026**. End-of-Support date for these products is **August 5, 2036.**
{% endhint %}

***

## Key definitions <a href="#h_807747ae69" id="h_807747ae69"></a>

* End-of-Sale Announcement: Official End-of-Sales notice.
* End-of-Sale Date: The last date to order the product through Verkada.
* End-of-Support Date: The last date a product will be supported by Verkada.

## FAQ

<details>

<summary>What does this mean?</summary>

As of August 5, 2026, we will no longer sell CB62 SKUs. However, we will continue to provide support for the product through our 10-year warranty period.

</details>

<details>

<summary>Can customers return products that they purchased?</summary>

Customers can return products *within 30 days of purchase*.

</details>

<details>

<summary>What happens if a product under warranty needs to be replaced?</summary>

We will replace RMA units with the same model, if available. Otherwise, we will replace them with the next most similar product.

</details>

***


# CB52

Learn details about the end-of-sale information for the Verkada CB52

Verkada is announcing the end-of-sale for the following products:

| Product     | SKU           | Description                                                                                  |
| ----------- | ------------- | -------------------------------------------------------------------------------------------- |
| **CB52-E**  | CB52-256E-HW  | Verkada CB52-E Outdoor Bullet Camera, 5MP, Zoom Lens, 256GB, 30 Days of Retention            |
|             | CB52-512E-HW  | Verkada CB52-E Outdoor Bullet Camera, 5MP, Zoom Lens, 512GB, 60 Days of Retention            |
|             | CB52-768E-HW  | Verkada CB52-E Outdoor Bullet Camera, 5MP, Zoom Lens, 768GB, 90 Days of Retention            |
|             | CB52-2TBE-HW  | Verkada CB52-E Outdoor Bullet Camera, 5MP, Zoom Lens, 2TB, 365 Days of Retention             |
| **CB52-TE** | CB52-256TE-HW | Verkada CB52-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 256GB, 30 Days of Retention |
|             | CB52-512TE-HW | Verkada CB52-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 512GB, 60 Days of Retention |
|             | CB52-768TE-HW | Verkada CB52-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 768GB, 90 Days of Retention |
|             | CB52-2TBTE-HW | Verkada CB52-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 2TB, 365 Days of Retention  |

The following products will replace the above products:

| Product     | SKU           | Description                                                                                  |
| ----------- | ------------- | -------------------------------------------------------------------------------------------- |
| **CB53-E**  | CB53-256E-HW  | Verkada CB53-E Outdoor Bullet Camera, 5MP, Zoom Lens, 256GB, 30 Days of Retention            |
|             | CB53-512E-HW  | Verkada CB53-E Outdoor Bullet Camera, 5MP, Zoom Lens, 512GB, 60 Days of Retention            |
|             | CB53-768E-HW  | Verkada CB53-E Outdoor Bullet Camera, 5MP, Zoom Lens, 768GB, 90 Days of Retention            |
|             | CB53-1TBE-HW  | Verkada CB53-E Outdoor Bullet Camera, 5MP, Zoom Lens, 1TB, 120 Days of Retention             |
|             | CB53-2TBE-HW  | Verkada CB53-E Outdoor Bullet Camera, 5MP, Zoom Lens, 2TB, 365 Days of Retention             |
| **CB53-TE** | CB53-256TE-HW | Verkada CB53-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 256GB, 30 Days of Retention |
|             | CB53-512TE-HW | Verkada CB53-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 512GB, 60 Days of Retention |
|             | CB53-768TE-HW | Verkada CB53-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 768GB, 90 Days of Retention |
|             | CB53-1TBTE-HW | Verkada CB53-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 1TB, 120 Days of Retention  |
|             | CB53-2TBTE-HW | Verkada CB53-TE Outdoor Bullet Camera, 5MP, Telephoto Zoom Lens, 2TB, 365 Days of Retention  |

{% hint style="danger" %}
Final orders for **CB52 products** must be received by **August 5, 2026**. End-of-Support date for these products is **August 5, 2036.**
{% endhint %}

***

## Key definitions <a href="#h_807747ae69" id="h_807747ae69"></a>

* End-of-Sale Announcement: Official End-of-Sales notice.
* End-of-Sale Date: The last date to order the product through Verkada.
* End-of-Support Date: The last date a product will be supported by Verkada.

## FAQ

<details>

<summary>What does this mean?</summary>

As of August 5, 2026, we will no longer sell CB52 SKUs. However, we will continue to provide support for the product through our 10-year warranty period.

</details>

<details>

<summary>Can customers return products that they purchased?</summary>

Customers can return products *within 30 days of purchase*.

</details>

<details>

<summary>What happens if a product under warranty needs to be replaced?</summary>

We will replace RMA units with the same model, if available. Otherwise, we will replace them with the next most similar product.

</details>

***


# Classic Alarms (Canada)

Learn details about the end-of-sale information for classic Alarms SKUs

Verkada is announcing the end-of-sale of classic Alarms in **Canada**, to be replaced by new Alarms.

***

Verkada will no longer sell the following SKUs in **Canada**:

{% hint style="danger" %}

* Final orders for the SKUs listed below must be received by **March 15, 2026**
* After March 15, 2026, only **renewals** of classic Alarms licenses will be allowed
* Verkada will continue to support classic Alarms going forward
  {% endhint %}

<table><thead><tr><th width="269.2734375"></th><th></th></tr></thead><tbody><tr><td><strong>SKU</strong></td><td><strong>Description</strong></td></tr><tr><td>LIC-BB-1Y-CAP</td><td>1-Year Basic Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BB-3Y-CAP</td><td>3-Year Basic Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BB-5Y-CAP</td><td>5-Year Basic Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BB-10Y-CAP</td><td>10-Year Basic Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BA-1Y-CAP</td><td>1-Year Standard Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BA-3Y-CAP</td><td>3-Year Standard Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BA-5Y-CAP</td><td>5-Year Standard Alarms License (Classic Alarms), Capacity Increase</td></tr><tr><td>LIC-BA-10Y-CAP</td><td>10-Year Standard Alarms License (Classic Alarms), Capacity Increase</td></tr></tbody></table>

We recommend our new Alarms SKUs going forward:

<table><thead><tr><th width="264.94140625"></th><th></th></tr></thead><tbody><tr><td><strong>SKU</strong></td><td><strong>Description</strong></td></tr><tr><td>LIC-BX-MB-1Y-CAP</td><td>1-Year Basic Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MB-3Y-CAP</td><td>3-Year Basic Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MB-5Y-CAP</td><td>5-Year Basic Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MB-10Y-CAP</td><td>10-Year Basic Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MA-1Y-CAP</td><td>1-Year Advanced Video Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MA-3Y-CAP</td><td>3-Year Advanced Video Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MA-5Y-CAP</td><td>5-Year Advanced Video Alarms License (New Alarms), Capacity Increase</td></tr><tr><td>LIC-BX-MA-10Y-CAP</td><td>10-Year Advanced Video Alarms License (New Alarms), Capacity Increase</td></tr></tbody></table>

***

### Key definitions <a href="#h_807747ae69" id="h_807747ae69"></a>

* End-of-Sale Announcement: Official End-of-Sales notice.
* End-of-Sale Date: The last date to order the product through Verkada.

### FAQ <a href="#faq" id="faq"></a>

<details open>

<summary>What does this mean?</summary>

Starting March 15, 2026, we will no longer sell classic Alarms capacity licenses in Canada. We will continue to provide support for classic Alarms and allow existing customers to renew their classic Alarms licenses.

</details>

<details open>

<summary>Can customers return any of the above products that they purchased?</summary>

Customers may return products *within **30 days of purchase.***

</details>

<details open>

<summary>What is the impact on regions outside the US and Canada?</summary>

Since new Alarms is not yet available outside the US and Canada, all classic Alarms licenses will continue to be available for purchase outside of those countries.

</details>




---

[Next Page](/llms-full.txt/1)

