jump to content

Identity and access

Understand how members, roles, SAML SSO and SCIM provisioning work together across the platform to authenticate members and automate their life cycle.

Show as Markdown

Invite and manage members’ roles in your organization, use SAML single sign-on (SSO) to authenticate them through your identity provider, and use SCIM to create, update and disable their access.

SSO checks a member’s identity when logging in, but does not create or remove organization members. SCIM manages these members and user records but does not authenticate users. Organizations typically configure both against the same identity provider so that assignment controls access and SSO protects authentication.

flowchart TB
  idp["Identity provider"]
  sso["SAML SSO<br/>authenticates"]
  scim["SCIM<br/>provisions and deactivates"]
  profile["Profile and membership"]
  signin["Sign-in allowed"]
  permitted["What the person can do"]

  idp --> sso
  idp --> scim
  scim --> profile
  sso --> signin
  profile --> signin
  profile --> permitted
SSO authenticates, SCIM provisions, and the membership role decides what is allowed.
  1. Invite initial owners and administrators under Roles and permissions.
  2. Check the email domain used by the members of your organization.
  3. Configure SSO as optional and test both authentication initiated by the service provider and identity provider.
  4. Configure SCIM with a limited group and confirm provisioning, updates, and deprovisioning.
  5. Expand the SCIM assignment to the desired population.
  6. Request SSO only after confirmation that expected members can connect and that there is a recovery path available.

The platform provides configuration guides for Google Workspace, Microsoft Entra ID or Microsoft 365 and Okta in the SSO and SCIM sections.

Role management choices

Role management choices

Keep membership roles in People, or map them from your identity provider with SAML Role AttributeSCIM creates and deactivates people and usually starts them as Employeeto take on the role of platform in People afterwards. Where to Manage Platform Roles.

Ultima actualizare: