Identity and access
Understand how members, roles, SAML SSO and SCIM provisioning work together across the platform to authenticate members and automate their life cycle.
Invite and manage members’ roles in your organization, use SAML single sign-on (SSO) to authenticate them through your identity provider, and use SCIM to create, update and disable their access.
How Capacities Work Together
Section “How the capabilities work together”SSO checks a member’s identity when logging in, but does not create or remove organization members. SCIM manages these members and user records but does not authenticate users. Organizations typically configure both against the same identity provider so that assignment controls access and SSO protects authentication.
flowchart TB idp["Identity provider"] sso["SAML SSO<br/>authenticates"] scim["SCIM<br/>provisions and deactivates"] profile["Profile and membership"] signin["Sign-in allowed"] permitted["What the person can do"] idp --> sso idp --> scim scim --> profile sso --> signin profile --> signin profile --> permitted
Recommended rollout
Section entitled “Recommended rollout”- Invite initial owners and administrators under Roles and permissions.
- Check the email domain used by the members of your organization.
- Configure SSO as optional and test both authentication initiated by the service provider and identity provider.
- Configure SCIM with a limited group and confirm provisioning, updates, and deprovisioning.
- Expand the SCIM assignment to the desired population.
- Request SSO only after confirmation that expected members can connect and that there is a recovery path available.
The platform provides configuration guides for Google Workspace, Microsoft Entra ID or Microsoft 365 and Okta in the SSO and SCIM sections.
Role management choices
Role management choicesKeep membership roles in People, or map them from your identity provider with SAML Role AttributeSCIM creates and deactivates people and usually starts them as Employeeto take on the role of platform in People afterwards. Where to Manage Platform Roles.