Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Connect your own domain. Use connect.companydomain.com for production, dev.connect.companydomain.com for clean Dev and qa.connect.companydomain.com for a sanitized QA replica. Current availability: Owner-assisted setup. Before you start. DNS administrator access and an isolated deployment assigned by TLS. A unique production hostname; never point two customers at the same data store. Step 1. In Companies > company > Settings, add the company subdomain. Only a subdomain under that company's primary domain is accepted. Copy the displayed _laststop TXT verification name and value to the authoritative DNS provider. Step 2. Choose Verify ownership after DNS propagation. This verifies ownership only; it does not activate hosting or HTTPS. Step 3. In Billing > Company environments, request connect.companydomain.com, dev.connect.companydomain.com or qa.connect.companydomain.com. Replace companydomain.com with your registered company domain. TLS assigns the isolated deployment and registers its custom domain; each receives its own hosting CNAME and TXT verification values. Step 4. Add the exact deployment-specific CNAME and TXT records. Do not change MX or unrelated root/www records. Existing conflicting records at the requested hostname require review before replacement. Step 5. Wait for active domain routing and HTTPS. Configure customer-specific identity callbacks, webhook URLs, sender identity and native app links in that deployment. Remaining TLS-specific identity and sender assumptions must be removed before independent activation. Step 6. Check HTTPS, correct-company login, logout, cookies, deep links, notification URLs and two-company negative access. A DNS ownership check alone is not an accepted portal. Now verify the result. Hostname opens the correct company and HTTPS is active. Wrong-host cookies and unapproved OAuth callback URLs fail. Outbound notifications link to the same customer domain. Open the ready production, Dev and QA links in separate tabs. Refreshing one tab leaves the others open; every tab still enforces its own session and company permissions. If you get stuck. Pending DNS: check the exact hostname, record value and propagation at the authoritative DNS provider. Login returning to TLS production means the provider callback/source configuration is still TLS-specific; do not activate the customer domain. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.