Identity & SSO
Enterprise identity federation — OIDC and SAML 2.0 single sign-on, and SCIM 2.0 automated user and group provisioning.
At a glance
| Route | /organization/identity |
| Group | Admin |
| Page permission | identity |
| Availability | Enterprise |
What it is
Enterprise identity federation: OIDC and SAML 2.0 single sign-on, and SCIM 2.0 automated user and group provisioning.
Who it is for
IT and security teams at enterprises that require federated identity and automated de-provisioning as a condition of adoption.
How it works
SSO supports both OIDC and SAML 2.0, with SAML assertions validated using signed XML verification. Identity provider discovery by email domain routes a user to the correct IdP automatically, and a status endpoint reports configuration health.
SCIM 2.0 provides automated provisioning and de-provisioning with a rotatable bearer token and group-to-role mapping — so platform access follows the directory rather than requiring parallel administration.
Features
- OIDC single sign-on
- SAML 2.0 with signed assertion validation
- Identity provider discovery by email domain
- SSO configuration status and health reporting
- SCIM 2.0 user and group provisioning and de-provisioning
- SCIM group-to-role mapping
- Rotatable SCIM bearer token
- Compatible with Okta, Microsoft Entra ID, and other standard providers
How to use it
Confirm your plan includes SSO and SCIM
Both are Enterprise features.
Configure the identity provider
Using the platform's published metadata, choosing OIDC or SAML per your organisation's standard.
Verify with a test user before enabling for everyone
Keep a break-glass local administrator until federation is proven. A misconfigured SSO integration can lock every administrator out simultaneously.
Configure SCIM and map directory groups to platform roles
So permissions follow group membership rather than being maintained twice.
Verify de-provisioning explicitly
Remove a test user from the directory and confirm platform access is actually revoked. Do not assume it works.
Why it matters
SSO and SCIM are usually procurement gates rather than preferences — an enterprise security review will block adoption without them.
Beyond compliance, automated de-provisioning closes the most common real access-control failure: accounts that remain active after someone leaves.
That matters more here than in most tools, because platform access can reach cloud infrastructure.
Connects to
- Complements manual user management in Organization
- Gated by Membership
- Authentication events recorded in Audit Logs
- All authentication methods are compared in Access Control