
Enterprise headshots your procurement team can approve
Everything the team plan does, plus procurement's checklist: enterprise headshots with enforced SSO, SCIM, and invoicing on your terms.

What Enterprise Headshots Add
The product is the same. What changes is how it is bought, governed, and connected to the systems you already run.
SAML SSO with enforced domains
Verify your domain and every employee on it must authenticate through your identity provider. Verification is required first - without it, claiming a domain would be an account-takeover primitive rather than a control.
SCIM 2.0 provisioning
Okta, Entra ID, and Google Workspace push directory changes directly. A leaver is deprovisioned by HR, not by someone remembering to click something here.
Net-30 invoicing
Agreed payment terms drive the invoice due date programmatically, alongside a contracted seat commitment and your negotiated per-seat rate.
Signed MSA and DPA
A master services agreement and data processing agreement your legal team reviews once, with the signature date recorded against your organization.

Where enterprise headshots require procurement review
If a purchase needs security review, a contract, and a PO number, this is the path.
Regulated industries
Finance, healthcare, and legal, where a vendor questionnaire arrives before any pilot does.
Large distributed workforces
Thousands of employees across regions, where a studio day was never a realistic plan.
Companies with an IdP mandate
Where every SaaS tool must sit behind SSO and be provisioned from the directory.
High-turnover organisations
Where automatic deprovisioning matters more than any feature on the product page.
How Enterprise Controls Actually Work
Each of these is enforced state read by the code path it governs, not a note in a sales spreadsheet.

How a Rollout Runs
Typically two calls and a week, not a quarter.

Security review and contract
We send the security overview, subprocessor list, and DPA up front. Your questionnaire gets answered against documented controls rather than aspirations.
Connect your identity provider
Verify your domain, enable SSO enforcement, and issue a SCIM token so your directory becomes the source of truth for seats.
Lock the brand look
Choose the backdrop and outfit pool, upload custom branded backdrops, and set per-department overrides where teams differ.
Roll out in waves
Provisioned employees are reminded on a bounded cadence that stops once their headshots exist. New hires match from their first day.
One Capture Standard Every Employee Can Follow
At four figures of headcount, output quality is mostly a function of what you wrote in the intranet article. These are the four lines worth writing.

Publish one sentence about light
Across a large population, variance in results is very largely variance in lighting. "Stand facing a window" is the single instruction worth putting in the announcement - it shifts more of the distribution than any guidance about phones or megapixels.
Specify a floor, not a spec
Do not mandate camera models or resolutions; people read that as a reason to defer. Ask for head and shoulders at arm’s length, which anyone can follow on any handset, and let the pre-flight check reject the few that still fall short before credits are spent.
State that wardrobe is irrelevant
Without this line a meaningful share of employees postpone indefinitely, waiting for a day they are dressed for it. The team wardrobe you locked replaces whatever is in the upload - saying so explicitly is what unblocks them.
Decide the opt-out before you launch
Some employees will decline to upload a photograph of their face, and under most biometric privacy regimes that is a legitimate position rather than an obstruction. Agree in advance what the directory shows for them, so the rollout does not stall on the first refusal.
Enterprise headshots capabilities
What is included beyond the team plan.

SAML 2.0 SSO
Enforced per verified domain, with just-in-time account creation on first sign-in.
SCIM 2.0 endpoints
Standards-compliant Users provisioning with filtering, pagination, PATCH deactivation, and a service provider config document.
Net-30 invoicing
Agreed terms drive due dates; pay by invoice or bank transfer rather than card.
Custom rate and seat commitment
A negotiated per-seat price with a contracted floor, applied automatically at billing time.
Contracted data residency
Your processing region is recorded on the agreement and surfaced on the trust page.
Audit trail
Sensitive administrative actions are recorded in an append-only audit log.
Biometric Handling Your Legal Team Can Review
Face photos are biometric data under BIPA, GDPR and CCPA. These are the controls your DPA references, implemented in the product and auditable.

Procurement Questions
Security, legal and procurement
Talk to Us About a Rollout
Send the security questionnaire. We will come back with the DPA, the subprocessor list, and an enterprise headshot rollout plan sized to your headcount.