Skip to content
Headshots for Enterprise

Enterprise headshots your procurement team can approve

Everything the team plan does, plus procurement's checklist: enterprise headshots with enforced SSO, SCIM, and invoicing on your terms.

Headshots for Enterprise workflow

What Enterprise Headshots Add

The product is the same. What changes is how it is bought, governed, and connected to the systems you already run.

SAML SSO with enforced domains

Verify your domain and every employee on it must authenticate through your identity provider. Verification is required first - without it, claiming a domain would be an account-takeover primitive rather than a control.

SCIM 2.0 provisioning

Okta, Entra ID, and Google Workspace push directory changes directly. A leaver is deprovisioned by HR, not by someone remembering to click something here.

Net-30 invoicing

Agreed payment terms drive the invoice due date programmatically, alongside a contracted seat commitment and your negotiated per-seat rate.

Signed MSA and DPA

A master services agreement and data processing agreement your legal team reviews once, with the signature date recorded against your organization.

Headshots for Enterprise use cases

Where enterprise headshots require procurement review

If a purchase needs security review, a contract, and a PO number, this is the path.

Regulated industries

Finance, healthcare, and legal, where a vendor questionnaire arrives before any pilot does.

Large distributed workforces

Thousands of employees across regions, where a studio day was never a realistic plan.

Companies with an IdP mandate

Where every SaaS tool must sit behind SSO and be provisioned from the directory.

High-turnover organisations

Where automatic deprovisioning matters more than any feature on the product page.

How Enterprise Controls Actually Work

Each of these is enforced state read by the code path it governs, not a note in a sales spreadsheet.

You claim a domain, prove control of it with a DNS record, and only then can SSO be required for its users. The unverified state deliberately does nothing.

Domain verification gates SSO enforcement

How a Rollout Runs

Typically two calls and a week, not a quarter.

Headshots for Enterprise steps

Security review and contract

We send the security overview, subprocessor list, and DPA up front. Your questionnaire gets answered against documented controls rather than aspirations.

Connect your identity provider

Verify your domain, enable SSO enforcement, and issue a SCIM token so your directory becomes the source of truth for seats.

Lock the brand look

Choose the backdrop and outfit pool, upload custom branded backdrops, and set per-department overrides where teams differ.

Roll out in waves

Provisioned employees are reminded on a bounded cadence that stops once their headshots exist. New hires match from their first day.

One Capture Standard Every Employee Can Follow

At four figures of headcount, output quality is mostly a function of what you wrote in the intranet article. These are the four lines worth writing.

A consistent portrait capture standard for an enterprise headshot rollout

Publish one sentence about light

Across a large population, variance in results is very largely variance in lighting. "Stand facing a window" is the single instruction worth putting in the announcement - it shifts more of the distribution than any guidance about phones or megapixels.

Specify a floor, not a spec

Do not mandate camera models or resolutions; people read that as a reason to defer. Ask for head and shoulders at arm’s length, which anyone can follow on any handset, and let the pre-flight check reject the few that still fall short before credits are spent.

State that wardrobe is irrelevant

Without this line a meaningful share of employees postpone indefinitely, waiting for a day they are dressed for it. The team wardrobe you locked replaces whatever is in the upload - saying so explicitly is what unblocks them.

Decide the opt-out before you launch

Some employees will decline to upload a photograph of their face, and under most biometric privacy regimes that is a legitimate position rather than an obstruction. Agree in advance what the directory shows for them, so the rollout does not stall on the first refusal.

Enterprise headshots capabilities

What is included beyond the team plan.

Headshots for Enterprise features

SAML 2.0 SSO

Enforced per verified domain, with just-in-time account creation on first sign-in.

SCIM 2.0 endpoints

Standards-compliant Users provisioning with filtering, pagination, PATCH deactivation, and a service provider config document.

Net-30 invoicing

Agreed terms drive due dates; pay by invoice or bank transfer rather than card.

Custom rate and seat commitment

A negotiated per-seat price with a contracted floor, applied automatically at billing time.

Contracted data residency

Your processing region is recorded on the agreement and surfaced on the trust page.

Audit trail

Sensitive administrative actions are recorded in an append-only audit log.

Biometric Handling Your Legal Team Can Review

Face photos are biometric data under BIPA, GDPR and CCPA. These are the controls your DPA references, implemented in the product and auditable.

Uploads are used once to generate your headshots and are never used to train, fine-tune, or improve a model. No exceptions, and every provider we route to is contractually bound to the same rule.

No AI training

Procurement Questions

Security, legal and procurement











Talk to Us About a Rollout

Send the security questionnaire. We will come back with the DPA, the subprocessor list, and an enterprise headshot rollout plan sized to your headcount.