Varcio FinOps Copilot

Identity & SSO

Enterprise identity federation — OIDC and SAML 2.0 single sign-on, and SCIM 2.0 automated user and group provisioning.

At a glance

Route/organization/identity
GroupAdmin
Page permissionidentity
AvailabilityEnterprise

What it is

Enterprise identity federation: OIDC and SAML 2.0 single sign-on, and SCIM 2.0 automated user and group provisioning.

Who it is for

IT and security teams at enterprises that require federated identity and automated de-provisioning as a condition of adoption.

How it works

SSO supports both OIDC and SAML 2.0, with SAML assertions validated using signed XML verification. Identity provider discovery by email domain routes a user to the correct IdP automatically, and a status endpoint reports configuration health.

SCIM 2.0 provides automated provisioning and de-provisioning with a rotatable bearer token and group-to-role mapping — so platform access follows the directory rather than requiring parallel administration.

Features

  • OIDC single sign-on
  • SAML 2.0 with signed assertion validation
  • Identity provider discovery by email domain
  • SSO configuration status and health reporting
  • SCIM 2.0 user and group provisioning and de-provisioning
  • SCIM group-to-role mapping
  • Rotatable SCIM bearer token
  • Compatible with Okta, Microsoft Entra ID, and other standard providers

How to use it

Confirm your plan includes SSO and SCIM

Both are Enterprise features.

Configure the identity provider

Using the platform's published metadata, choosing OIDC or SAML per your organisation's standard.

Verify with a test user before enabling for everyone

Keep a break-glass local administrator until federation is proven. A misconfigured SSO integration can lock every administrator out simultaneously.

Configure SCIM and map directory groups to platform roles

So permissions follow group membership rather than being maintained twice.

Verify de-provisioning explicitly

Remove a test user from the directory and confirm platform access is actually revoked. Do not assume it works.

Why it matters

SSO and SCIM are usually procurement gates rather than preferences — an enterprise security review will block adoption without them.

Beyond compliance, automated de-provisioning closes the most common real access-control failure: accounts that remain active after someone leaves.

That matters more here than in most tools, because platform access can reach cloud infrastructure.

Connects to

On this page