User Guide

SSO & group sync

Centralize authentication with your identity provider and automatically manage data scopes through group mappings.

Supported providers#

🔵

Azure AD / Entra ID

Full integration with Microsoft identity. Automatic group fetching via Microsoft Graph API for scope sync.
🔴

Google Workspace

OAuth2 with Google identity. Group mappings via free-text input for Google Workspace group names.
🟢

Generic OIDC

Any OpenID Connect provider — Okta, Auth0, Keycloak, PingFederate. Uses standard discovery URL.

Setting up SSO#

  1. Go to Settings → SSO (Owner only)
  2. Enter Client ID, Client Secret, and discovery URL (or tenant ID for Azure)
  3. Click Test Connection to validate credentials before saving
  4. Save — SSO buttons appear on the login page immediately
Tip
The Test Connection button validates credentials via a client_credentials grant without saving. Fix any issues before committing the configuration.

Auto-provisioning#

Auto-provision OFF (default)
  • ✗Only pre-invited users can log in via SSO
  • ✗Admin/Owner must send invitation first
  • ✗Full control over who accesses the platform
  • ✗Recommended for most deployments
Auto-provision ON
  • ✓Any user in your IdP tenant gets an account on first login
  • ✓New accounts get the default role from SSO config
  • ✓Useful for large orgs where everyone needs access
  • ✓Owner toggles this per provider
Note
Enabling auto-provision means any authenticated user in your IdP tenant can create an account. Combine with allowed domain restrictions (set via your license) for an extra layer of control.

Group sync#

Group sync maps IdP groups to CCO internal groups, automatically assigning data scopes when users log in via SSO:

  • ✓Enable per provider (AD Sync toggle + default group)
  • ✓Map IdP groups to CCO groups (many-to-many)
  • ✓Azure AD: 'Fetch Groups' button pulls groups from Microsoft Graph
  • ✓Google/OIDC: free-text input for group IDs
  • ✓Users in multiple IdP groups get the union of all matched scopes
  • ✓Default group fallback for unmatched users

Sync behavior#

On every SSO login:

  1. Check if AD Sync is enabled for the provider → skip if disabled
  2. Check user's manual override flag → skip if set
  3. Match IdP group claims against active mappings
  4. Replace user's CCO group membership with matched groups
  5. User's effective data scope updates immediately
Manual override
The per-user manual override flag prevents SSO sync from changing a user's scope. Useful for consultants or exceptions that don't match any IdP group. Toggle it from the user's context menu on the Users tab.

Break-glass access#

Password-based login is never disabled, even when SSO is configured. If your IdP goes down, users with passwords can still sign in. The Owner account always has a password.