Administration
The Administration area is where account admins manage account-wide settings for your Knock AI workspace. It covers your company profile, who can access the account, security controls, lead restrictions, connected integrations, and website tracking.
To open it, click on Your domain → Settings. Administration settings are available to account admins.
General
The General page holds your company profile. These details appear across your Knock account.
- Company logo - click the pencil icon to upload or replace your logo.
- Company name - the display name for your account. Click the field to edit it.
- Company domain - your primary website domain, used to identify your account.
People
The People page lists everyone with access to your Knock dashboard and lets admins invite new users.
How to invite a user
- Click Invite user.
- Enter the person's email address.
- Send the invite. The invited user receives an email to join your account.
The people table
Each user in the table shows:
- Name
- Created Date - when the user was added to the account.
- Last Active - the user's most recent activity. This shows as
—if the user has not signed in yet.
Use the search box to find a person by name or email. Use the Created Date and Last Active column headers to sort the list.
Security
The Security section controls how users authenticate and which networks can reach your account. It contains two pages: IP Restrictions and SSO Provider.
IP restrictions
IP restrictions let you limit access to the Knock dashboard and API to specific IP addresses. Use this when your security policy requires access only from your corporate network or VPN.
How IP restrictions work
- When Restricted access is off, any authenticated user can reach the dashboard and API from any network. This is the default.
- When Restricted access is on, only the IP addresses on your allowlist can reach the dashboard and API. All other addresses are blocked.
How to turn on restricted access
- Toggle Restricted access on.
- Knock automatically adds the IP you are currently using, labeled My IP, so you cannot lock yourself out.
How to manage allowed IP addresses
- Click Add IP address to open the panel. Choose IP Match to allow one address, or IP Range to allow a CIDR range. Both IPv4 and IPv6 are supported.
- Enter the address in the IP address field (for example,
192.168.1.1or192.168.0.1/24), add an optional Label (for example,HQ Tel AvivorOffice VPN), then click Add IP to save it. - Toggle any entry on or off. A disabled entry stays in the list but does not grant access.
- Delete an entry from its menu. You cannot remove the last remaining entry while restricted access is on, which prevents you from locking everyone out.
What IP restrictions do and do not affect
- Applies to: the Knock dashboard, personal rep hub and the Knock API.
- Leads are never restricted: visitors chatting through Slack, WhatsApp, or LinkedIn, or booking through scheduling links, are never IP-restricted.
💡 Add your office and VPN ranges before you rely on restricted access, so your whole team keeps access.
Single sign-on (SSO)
Single sign-on lets your team sign in to Knock through your identity provider (IdP), such as Okta, Microsoft Entra ID, Google Workspace, or Ping Identity. Knock supports both OIDC and SAML.
How to connect an identity provider
- Go to Security → SSO Provider.
- Choose your provider and protocol (for example, Okta OIDC or Google SAML) and click Connect.
- In the setup wizard, enter the required configuration from your IdP.
- Add any optional settings, such as attribute mappings.
- Choose an enforcement mode: Optional or Required.
Enforcement modes
- Optional - users can sign in with SSO or with email.
- Required - users must sign in with SSO. You can add specific email addresses to a skip list; those users can still sign in with email, which is useful for break-glass or external admin accounts.
How to test and activate
- Click Test Connection. Knock runs a real sign-in round-trip through your IdP using your own credentials.
- You can only Activate after a successful test. If the test fails, activation stays disabled and the error is shown inline.
How to manage an active connection
- Edit configuration - any change requires you to test again before you can re-activate.
- Update the skip list - you can change exempt emails without re-testing.
- Disconnect - returns you to provider selection. Your configuration is saved so you can reconnect later.
What SSO applies to
- SSO is enforced for dashboard sign-in and Knock API use once the connection is active.
- Reps opening the Rep Hub from Slack are not routed through SSO.
- Users on the skip list can continue to sign in with email.
Access and user creation
When SSO is connected, anyone your identity provider grants access to the Knock app can sign in to the dashboard, even if an admin has not invited them from the People page.
The first time such a person signs in, Knock automatically creates a user for them and adds them to your People list. No manual invite is required.
Access is controlled in your identity provider. To grant or remove someone's dashboard access, change their assignment to the Knock app in your IdP.
Sessions and recovery
- Activating SSO does not sign out users who are already logged in. Enforcement applies at their next sign-in.
- If your IdP becomes unavailable, Knock provides a recovery path. Contact Knock support to restore email sign-in, so a broken IdP never locks you out permanently.
Step-by-step provider guides
Lead restrictions
Lead restrictions control who can engage with Knock on your website and how visitors are handled.
Country restrictions
Country restrictions prevent visitors from selected countries from seeing or starting a chat with Knock or booking a meeting.
- Click Add Country.
- Search for a country by name and select it. Flags help you confirm the right country.
- The country is added to the blocked list.
To manage the list:
- Toggle any country on or off.
- Delete a country from its menu. Knock asks you to confirm before removing it.
Each entry shows the date it was added.
Integrations
The Integrations page connects Knock to the tools your team already uses, so every lead, conversation, and booked meeting moves through your existing stack. Integrations are grouped into tabs: Messaging, Scheduling, Outreach, CRM, Advertisements, and Developer tools.
Each app card shows its status: a Connect action, a Connected label, or a way to manage existing connections. Where an app supports multiple reps, a manage view lists who connected, when, and (where relevant) meetings booked.
Messaging
Give leads more ways to reach your team.
- Slack - receive and reply to lead messages in Slack. Installing Slack requires a Slack admin.
- WhatsApp - let leads message you on WhatsApp.
- Telegram - let leads message you on Telegram.
- LinkedIn - let leads message you on LinkedIn. Connect your own account or invite teammates to connect theirs. Once connected, open the LinkedIn connections view to manage connected reps. See Connect LinkedIn Accounts to Knock.
Scheduling
- Google Calendar - connect your calendar for automated meeting scheduling, or manage reps who have connected. See How to Connect Sales Calendars in Knock.
- Zoom - generate Zoom links for booked meetings. Zoom requires an active Google Calendar connection, so the Zoom option stays disabled until Google Calendar is connected. See How to Use Zoom with Knock AI Scheduling.
Outreach
Automated LinkedIn outreach sends a personalized LinkedIn message to a lead after the lead interacts with a Knock AI meeting link.
- LinkedIn - uses the same connection as the Messaging tab.
- Email - Knock AI email is always connected. No action is required.
CRM
Connect your CRM so Knock can read and write lead and meeting data.
HubSpot, Salesforce, and Marketo are supported.
Setup guides: HubSpot · Salesforce · Marketo.
Advertisements
Connect your ad platforms so Knock can send real buyer engagement and conversion events straight into your ad tools.
- LinkedIn Ads - connect the LinkedIn Campaign card and authenticate your LinkedIn Ads account. Knock then sends engagement and conversion events into LinkedIn Campaign Manager automatically, with no tracking code or engineering work. See Connect Knock AI Events to LinkedIn Ads.
- Google Ads - connect the Google Ads card and authenticate your account. Knock then sends the same engagement and conversion events into Google Ads automatically.
Developer tools
Developer tools link out to Knock's developer resources and downloads.
- Webflow - the Knock Buttons Library gives you ready-made Slack, WhatsApp, and LinkedIn contact buttons. Pick a platform, choose the style (corners, colors, and icon or icon-plus-text), copy the element, and paste it onto your Webflow canvas.
Tracking Codes
The Tracking Codes page provides the Knock tag for your website. Adding the tag lets Knock capture visitor data and intent and identify high-intent visitors.
Under Add Knock Tag to your Marketing Site, use Copy code to copy the script, or Send to IT to email it to whoever manages your site. Add the script to your site's HTML, ideally in the <head> section. The card shows a connected status once Knock detects the tag on your site.
For full instructions, see How Do I Add the Knock AI Tag to My Website?
FAQ
On this page
- Administration
- General
- People
- How to invite a user
- The people table
- Security
- IP restrictions
- How IP restrictions work
- How to turn on restricted access
- How to manage allowed IP addresses
- What IP restrictions do and do not affect
- Single sign-on (SSO)
- How to connect an identity provider
- Enforcement modes
- How to test and activate
- How to manage an active connection
- What SSO applies to
- Access and user creation
- Sessions and recovery
- Step-by-step provider guides
- Lead restrictions
- Country restrictions
- Integrations
- Messaging
- Scheduling
- Outreach
- CRM
- Advertisements
- Developer tools
- Tracking Codes
- FAQ