I don't really like having to use <company>.sso.meraki.com. This is just another URL for staff to remember. Most of the SAML Idps out there have some kind of portal function already - and do you give your staff one special URL to be used for just the Meraki portal, or the one URL for your Idp portal which is used to access everything in your company's world?
You know what the answer is.
We need to take the work you have done a step further. There needs to be a way to validate a company owns a domain (DNS record verification seems a good choice, or you could send an email to that domain with a magic link to click on that expires in 60 minutes, ...), such as company.com, and then make all login requests at the Meraki main login page use SAML for that domain, for every org.