User Guide
SSO & group sync
Centralize authentication with your identity provider and automatically manage data scopes through group mappings.
Supported providers#
🔵
Azure AD / Entra ID
Full integration with Microsoft identity. Automatic group fetching via Microsoft Graph API for scope sync.
🔴
Google Workspace
OAuth2 with Google identity. Group mappings via free-text input for Google Workspace group names.
🟢
Generic OIDC
Any OpenID Connect provider — Okta, Auth0, Keycloak, PingFederate. Uses standard discovery URL.
Setting up SSO#
- Go to Settings → SSO (Owner only)
- Enter Client ID, Client Secret, and discovery URL (or tenant ID for Azure)
- Click Test Connection to validate credentials before saving
- Save — SSO buttons appear on the login page immediately
Tip
The Test Connection button validates credentials via a client_credentials grant without saving. Fix any issues before committing the configuration.
Auto-provisioning#
Auto-provision OFF (default)
- ✗Only pre-invited users can log in via SSO
- ✗Admin/Owner must send invitation first
- ✗Full control over who accesses the platform
- ✗Recommended for most deployments
Auto-provision ON
- ✓Any user in your IdP tenant gets an account on first login
- ✓New accounts get the default role from SSO config
- ✓Useful for large orgs where everyone needs access
- ✓Owner toggles this per provider
Note
Enabling auto-provision means any authenticated user in your IdP tenant can create an account. Combine with allowed domain restrictions (set via your license) for an extra layer of control.
Group sync#
Group sync maps IdP groups to CCO internal groups, automatically assigning data scopes when users log in via SSO:
- ✓Enable per provider (AD Sync toggle + default group)
- ✓Map IdP groups to CCO groups (many-to-many)
- ✓Azure AD: 'Fetch Groups' button pulls groups from Microsoft Graph
- ✓Google/OIDC: free-text input for group IDs
- ✓Users in multiple IdP groups get the union of all matched scopes
- ✓Default group fallback for unmatched users
Sync behavior#
On every SSO login:
- Check if AD Sync is enabled for the provider → skip if disabled
- Check user's manual override flag → skip if set
- Match IdP group claims against active mappings
- Replace user's CCO group membership with matched groups
- User's effective data scope updates immediately
Manual override
The per-user manual override flag prevents SSO sync from changing a user's scope. Useful for consultants or exceptions that don't match any IdP group. Toggle it from the user's context menu on the Users tab.
Break-glass access#
Password-based login is never disabled, even when SSO is configured. If your IdP goes down, users with passwords can still sign in. The Owner account always has a password.