Org SSO
Org SSO is the sign-on tab on the organization surface at /settings/organization/sso. It shows how this org authenticates: whether single sign-on is configured, which identity provider backs it, and what a member without SSO does at sign-in. The directory mechanics behind it (SSO / IDP setup, directory sync, group-to-role mapping) live under Security.
Two setup cards start the flow. Single sign-on (SSO) configures SAML or OIDC with the identity provider. Directory sync (SCIM) auto-provisions and deprovisions members from the directory. Each card opens its guided setup from the portal.
- Directory group to role mapping binds identity-provider groups to elevated roles, or ignores groups that should stay unbound. The rows shown include account services, agents (mapped to standard), and exec leadership.
- Unmapped groups are informational no-ops: directory users still receive the default standard role. Only an explicit mapping to a missing role counts as a warning.
- Membership still runs through People: SSO decides how members prove who they are, not who belongs.
- If sign-in breaks, check the provider status and the verified email domains on Org before changing config. Most SSO outages are identity mismatches, not product bugs.


