SSO, Federation & Provisioning

Tenant- and organization-aware identity providers. Configurations are scoped, versioned, tested and approved before activation. Accounts are never linked by email alone, and just-in-time provisioning is off unless explicitly enabled.

0
Providers
0
Active
0
Pending approval
0
Recovery grants

Identity providers

Loading providers...

Emergency recovery grants (break-glass)

No active recovery grants. If an organization's IdP fails, an approved admin can issue a time-boxed fallback grant.

Every inbound assertion is validated for issuer, audience, signature, nonce, state, redirect URI and lifetime. Group-to-role mapping is bounded by an approved permission ceiling. Activation requires a passing test and a separate approver (maker is never the checker).