Accounts and your organization
On Based Workstation and Based Poweruser your accounts live in GNOME Settings, under Online Accounts. Onboarding's Online Accounts page is a copy of it, so you can add them at the first login or any time after. Based adds four rows at the top:
| row | what it sets up |
|---|---|
| Work or School Account | everything your organization publishes, from one sign-in |
| VPN | NetBird, OpenVPN or WireGuard |
| Matrix | chat, in Fractal |
| Nextcloud | files, calendar and contacts, and Nextcloud Passwords in Zen if you want it |
Each row is complete on its own. A Nextcloud you add directly gets the desktop sync client, Thunderbird's calendar and contacts, and an app password made for this computer, the same as one your organization hands you. GNOME's other providers are there too, less Exchange, Fedora and Enterprise Authentication, since Thunderbird can't use them.
The Retro editions have no Work or School Account. On Retro WhiteSur the rows are KDE's own, and on Retro Chicago95 you sign in to Nextcloud from its desktop client.
Work or School Account
Type the address your organization gave you, your work email or its domain, and press Sign In. Based looks up what the organization publishes and lists each service with a switch, all on. A service this computer can't set up stays off and says why. Turn off the ones you don't want and press Sign In again.
Signing in happens once, in your browser, through your organization's sign-in page. The dialog opens the browser, and shows the address and a code to type in case it doesn't. Based never asks for your password: each service gets its own credential from the organization afterwards.
What it can set up, depending on what your organization runs:
- mail, calendar and contacts in Thunderbird
- Nextcloud files, through the Nextcloud client
- Matrix chat, in Fractal
- the NetBird VPN, signed in with the same account
- servers for your AI agents, see AI agents
The Nextcloud client, NetBird and Fractal aren't in the image. They install when you approve the service, which is why signing in needs a network.
Removing the Work or School Account in Online Accounts undoes everything it set up. Removing one of the entries it made, such as its mail, takes that service away alone and revokes its credential.
Joining an organization
A work computer can also belong to the organization, beyond your own accounts on it. On Workstation and Poweruser the first login shows the Organization page right after Welcome. Enter your work email or domain and Join signs you in, sets up the services above and asks for this computer's administrator password once, for the parts that change the machine. On your own computer, skip it. You can join later from Setup, then Organization in the Omarchy menu.
Joining can bring two things your own sign-in doesn't. If your organization runs Fleet, it can enroll this computer in device management, which lets it run scripts here as an administrator. It enrolls only with your yes, and you can always say no on a personal computer. To enroll later, open Setup, then Security, then Enroll in your organization's Fleet. And the organization's policy can have this computer install every update by itself instead of waiting for you; Updating has what that changes.
On a joined computer, Setup, then Organization says which organization it belongs to and offers Leave Organization. Leaving removes Fleet's agent, the organization's policy and the record of the join. Your account and what you installed stay.
A VPN on its own
The VPN row takes NetBird, OpenVPN or WireGuard without any organization. For NetBird, type your management server and sign in the way it asks.