On this page
Before you start
A minute of context so the order of the steps makes sense.
Haven sets your organization up before you sign in for the first time. Your organization, your owner account and your email domain are already in place, so this guide starts from your first sign in and takes you to a team that is protected and reporting.
The order below is deliberate. Get your people in, then decide what Haven protects, and only then switch enforcement on. Doing it the other way around is how you end up blocking something your team needed on a Monday morning.
What you can do yourself
- Invite people, set their roles, and remove them
- Choose which sites and categories Haven protects, and lock those choices
- Control which other browser extensions may run alongside Haven
- Switch between watching and enforcing, whenever you want
- Group your team and give each group its own policy
What to ask Haven for
- Adding or verifying another email domain for your organization
- Turning on automatic joining for people on your domain
- Turning on Gmail link scanning
- Changing how many seats your plan includes
Find your console
Confirm you are set up correctly before you change anything.
-
Go to account.starthaven.com and sign in with the email address your Haven contact set up.
-
Look for the Organization section in the menu on the left. You should see:
Overview › Members and Seats › Policy › Groups › Directory › Risk Report -
If that section is not there, do not change anything yet. Go to Troubleshooting below, which covers the usual cause.
Owners and admins can do everything in this guide, with one exception: only an owner can reach billing. If you are an admin and need a seat count or plan changed, ask your owner or email us.
Add your team
Three ways in. Most teams start with invites.
Invite people directly
-
Open Members and Seats, then choose Invite.
-
Enter their work email address and pick a role. Most people should be member. Give admin only to the people who will manage policy.
-
They get an email with a join link. Until they accept, the invite holds a seat, so a pending invite counts against your seat total the same way a joined member does.
Let people on your domain join automatically
If your team uses Google Workspace, Haven can add people to your organization the first time they sign in, with no invite at all. This needs a verified domain on your account, so ask us to switch it on.
It is off unless you ask, and that is deliberate. Turning it on means anyone your Workspace can sign in joins your Haven organization automatically.
Let people ask to join
The middle option. Someone on your domain asks to join and you approve or decline it in the console. This is what happens to a domain match when automatic joining is off.
Install Haven everywhere
Haven only protects a browser that has the extension.
People can install Haven themselves from the Chrome Web Store, which is fine for a small team. For anything larger, push it out centrally so nobody has to do anything and nobody can remove it.
We have a full step by step guide for this: Deploy Haven with Google Workspace. It covers installing Haven on every machine, pinning the icon so it stays visible, and piloting with one team first.
Two things worth knowing before you roll out.
- Installing Haven and joining your Haven organization are separate. Pushing the extension out does not put anyone in your organization by itself.
- Haven can sign people in automatically on a managed device, so nobody has to type anything. It needs a little setup on both sides, so tell us if you want it and we will walk you through it.
Haven is Chrome only today. Microsoft Edge is not supported yet.
Choose what Haven protects
Do this before you switch enforcement on.
Everything here lives on the Policy page, and each setting can apply to your whole organization or to a single group.
-
Protected sites and categories. Choose which sites get Haven's full treatment: the verified banner, link checking, and Haven Shield, which switches off other extensions while the site is open. Banking and payroll are the usual starting points.
-
Lock the ones that matter. A locked category or site cannot be switched off by the person using it. This is the difference between a suggestion and a policy.
-
Deny anything that should never be on. A denied site or category cannot be switched on, even by the person using it.
-
Set your extension allow list. Decide which other browser extensions may keep running while someone is on a protected site. Password managers are allowed by default.
Denied always beats locked, and locked always beats an individual's own choice. Where an organization setting and a group setting disagree, Haven applies the more protective of the two.
Turn on enforcement
The one switch that changes what your team experiences.
New organizations start in Monitor only. Haven watches, records what it would have done, and changes nothing for anyone. Your Overview and Risk Report fill up exactly as they would under enforcement, so you can see the effect of your policy before anyone feels it.
We suggest leaving it there for a normal working week. Look at what Haven would have blocked, adjust your policy, and then switch over.
Your own browser applies the change straight away. Everyone else picks it up within five minutes, because each browser checks for policy changes on a timer. If your machine starts enforcing before your colleagues' machines do, that is expected and not a fault.
Groups and Google Workspace
Optional. Useful once one policy stops fitting everyone.
Groups let one organization run more than one policy. Contractors can be held to something stricter than permanent staff, or a finance team can have a longer protected site list than everyone else.
- A group can carry its own enforcement mode, protected sites, extension allow list and settings.
- Where someone belongs to several groups, they get the most senior role and the most protective policy of any of them.
If you use Google Workspace, connect it on the Directory page and Haven can map your existing Workspace groups onto Haven groups. Membership then keeps itself up to date instead of being maintained by hand. You can disconnect from the same page at any time.
Two smaller things worth setting up
- Email aliases. If someone sends mail from a second address, add it to their member row so Haven recognises them as a colleague rather than flagging them as someone impersonating your team. The address is confirmed by email before Haven trusts it.
- Gmail link scanning. Haven can check links inside Gmail as well as on the web. Ask us to turn it on for your organization.
Troubleshooting
The questions we are asked most while a team is getting set up.
I am an owner but I cannot see the Organization section
Three things have to be true at once for the console to appear: you hold an owner or admin role, your account is an organization account rather than a personal one, and your subscription is active.
The most common cause by far is the third. If your subscription has lapsed, the console is hidden until it is renewed, and Haven will tell you so on your home page and name your organization.
Your team's protection is not affected by this. Only the console is.
I switched on enforcement and nothing happened
Wait five minutes. Every browser checks for policy changes on a timer, so a change is not instant for anyone except you.
If it still has not applied after that, check that the person is signed in to the Haven extension, that they are actually on one of your protected sites, and that no group they belong to is set to monitor only.
Someone has Haven installed but they are not in our organization
Installing the extension and joining your organization are two separate things. Pushing Haven out to a fleet places the extension, but it does not put anyone in your organization.
Invite them from Members and Seats, or ask us about automatic joining so that everyone on your domain is added when they first sign in.
The number of extensions shown for someone looks wrong
The number on the member list is what that person's browser last reported. Opening their row shows the actual list, and where the two disagree the list is the accurate one.
"Not reported yet" means their browser has not sent a list in. It does not mean they have no extensions.
Our subscription lapsed. Have we lost protection?
No. Your policy keeps applying on every member's browser, because protection is a security control rather than a paid feature.
What you lose is the console: admins cannot reach the organization pages until it is renewed. An owner can reactivate from Settings, under Billing.
Can we try Haven with one team before rolling it out to everyone?
Yes, and we recommend it. Invite one team, deploy the extension to just their organizational unit, and leave enforcement in monitor only while you watch what Haven reports.
When you are happy, widen the deployment and switch enforcement on.
Still stuck?
Tell us what you are trying to set up and where it went wrong, and someone from the Haven team will help you finish it.
Contact Haven support