Domain allowlist
The trade-off: OAuth has no built-in domain restriction. Any Google account can attempt sign-in. For most orgs, that's not acceptable as-is. ZopNight applies a domain allowlist post-OAuth to bridge the gap. The check happens after the OAuth handshake: if the authenticated user's email is not in the allowlist, ZopNight rejects the session with an explicit message ("This Google account is not allowed for this org").
Read the term in context.
Each row is a lesson that uses this term. The lesson where it first appears is the canonical definition.