Skip to content

Org SSO

Org SSO is the sign-on tab on the organization surface at /settings/organization/sso. It shows how this org authenticates: whether single sign-on is configured, which identity provider backs it, and what a member without SSO does at sign-in. The directory mechanics behind it (SSO / IDP setup, directory sync, group-to-role mapping) live under Security.

Two setup cards start the flow. Single sign-on (SSO) configures SAML or OIDC with the identity provider. Directory sync (SCIM) auto-provisions and deprovisions members from the directory. Each card opens its guided setup from the portal.

  • Directory group to role mapping binds identity-provider groups to elevated roles, or ignores groups that should stay unbound. The rows shown include account services, agents (mapped to standard), and exec leadership.
  • Unmapped groups are informational no-ops: directory users still receive the default standard role. Only an explicit mapping to a missing role counts as a warning.
  • Membership still runs through People: SSO decides how members prove who they are, not who belongs.
  • If sign-in breaks, check the provider status and the verified email domains on Org before changing config. Most SSO outages are identity mismatches, not product bugs.
SSO and SCIM surface with Single sign-on and Directory sync setup cards and directory group to role mapping table
  • Security: SSO / IDP setup, directory sync, and group-to-role mapping.
  • People: who belongs to the tenant this sign-in protects.
  • Org: the identity (name, hostname, domains) SSO keys off.