Fowlguard

Home  /  Resources  /  Organization

Organization

Everything that identifies your organization, and the rules that decide who may join it.

Names and identifiers

Two names and two identifiers, kept apart on purpose. The Organization Name is your company; the FGMesh Name is the private network your systems and devices sit on. One organization can hold several FGMeshes, which is why they are separate fields.

Both names are free to change. Nothing durable refers to them, every record keys on the Organization ID and FGMesh ID, which are generated once and never edited. Renaming moves no records and breaks no access. Two organizations may both be called Acme and neither is wrong.

Quote the Organization ID when you contact support; it is the value that identifies you unambiguously.

To change a name, press Change on its row, edit, and press Save. An FGMesh name must be a single word.

FgDNS zone

Your FGMesh is given its own DNS zone, shown as the FgDNS Zone. Every enrolled system and device is reachable by name inside the mesh under that zone, and nowhere outside it. The zone is generated and globally unique; it is not editable.

Verified domains

Proving that your organization controls a domain is done by publishing a DNS TXT record we give you. Add the record at your DNS provider, then press Verify; the check can take a few minutes to see a newly published record.

A verified domain does two things. Other organizations can agree to receive shared devices from you by that name, so the person approving sees "acme.com" rather than an identifier they cannot check. And a custom identity provider is tied to it, which is what stops anyone else claiming to sign in as your company.

Verifying a domain does not by itself let anyone in. It establishes who you are; join rules below decide who joins.

Join rules

Someone signing up with an email on a listed domain - or on a verified admin's own domain - joins this organization as a member. Without a rule they would get an FGMesh of their own, which is rarely what you want for a colleague.

Public mailbox domains are refused: gmail.com, outlook.com and the rest. A rule on one of those would hand your mesh to anyone in the world with that provider, so the server rejects it rather than trusting the list to be curated.

When SAML is enabled its settings decide who joins instead, and these rules stop applying. That is deliberate: two systems deciding membership independently is how someone ends up in a mesh nobody meant to admit them to.

Turning on Require admin approval holds a newly joined person until an admin accepts them. Admins are emailed when someone is waiting.

Internal base domains

Claiming a base domain makes FgDNS authoritative for every name beneath it. A lookup for anything under a claimed domain is answered from your mesh zone and never reaches the machine's own DNS.

That is the point, and it is also the risk: do not claim a domain that also resolves publicly and is needed publicly. If you claim example.com and your staff also need the public www.example.com, they will stop being able to reach it - your mesh will answer first, and it does not know about the public record.

Claim the domain your internal systems actually live under, usually something that resolves nowhere else, such as corp.example.com or an internal-only name.

DNS routing

Split DNS sends one domain's lookups to the resolvers that own it. A rule names a domain and the resolvers to ask; global nameservers catch everything no rule claims.

A resolver listed here that cannot be reached means slow lookups, never broken ones. Devices always fall back to their own resolvers when a configured one does not answer, so a mistyped or decommissioned address costs time rather than access. It is still worth correcting: every lookup that falls back waits for the timeout first.

Leave the global nameservers empty and devices use whatever their own network gave them, which is usually what you want for anything not internal.

FGMesh switching

Lets your users choose which FGMesh the Fowlguard Connect client connects to. They start on your primary FGMesh. On by default.

This replaced client account switching. A person has one identity with you and more than one mesh, so choosing between meshes is an in-session, same-identity choice; switching account was asking someone to be somebody else. Turn it off if a device should only ever reach one mesh.

Join rules

List the email domains whose users join this organization when they sign up or sign in for the first time, rather than creating an organization of their own. Public mailbox domains are refused.

Require admin approval holds a newly-joined user until an administrator approves them. Admins are emailed when someone is waiting; the queue is on the Access Requests page.

If you have configured SAML, its settings decide who joins and these rules do not apply.

Verified domains

Proof that your organization controls a domain. Claim the domain, publish the TXT record shown, then press Verify. Claiming asserts nothing on its own. Only verification establishes control.

A verified domain is what another organization sees when it decides whether to accept devices shared from you, and it is what a custom identity provider is tied to.

DNS records

The names your devices can reach across the mesh, generated automatically from device hostnames and registered systems. Rename an entry if its automatic name is not the one you want to resolve by.

Internal base domains

Claim a domain here and Fowlguard answers every name beneath it from the mesh, the request never reaches the device's own DNS. The claim is total, so do not claim a domain that also resolves publicly and is needed publicly.

DNS routing

Split DNS sends a domain's lookups to the resolvers that own it. Global nameservers catch everything no rule claims. Devices always fall back to their own resolver when a configured one does not answer, so an unreachable resolver here costs you slow lookups, not broken ones.

FgDNS names

The names your devices reach each other by across the mesh. They are generated for you, from device hostnames and from the systems you register, so there is no zone to author and nothing to forget. Rename any entry whose auto-derived name is not the one you want to resolve by.

Each name maps to a mesh address, and the count above the table is how many of your subnet's addresses are in use. An address is held by the record that owns it until that record is deleted, so a machine you have revoked still holds its name and its address, and neither is handed to anything else.

© 2026 Fowlguard Platform Pricing Resources Company hello@fowlguard.com