Set it up
An owner sets up SSO in the dashboard, under Settings → Single sign-on. Every member can see what is set up; only owners change it, since it decides who can sign in.- Set up SSO opens the Admin Portal, where you pick your identity provider and follow its steps: an app to create on your side, and its metadata or client details to paste back. The portal says what your provider needs.
- Verify a domain opens the portal to verify the domain your people’s email addresses are on, such as
acme.com, with a DNS record. - When you’re done, the portal returns you to Settings, which lists the connection and the domain with their status. Once the connection is
activeand the domainverified, people from that domain sign in through your provider.
org.sso.
Who can sign in, and with what role
- Someone from your verified domain who signs in through your provider and isn’t a member yet joins your organization as read_only, the least privileged role: they can see everything and change nothing. An owner gives them another role on the Members page. The join is in your audit log as
member.put, bysystem:sso. - A member keeps the role an owner gave them.
- Removing someone starts in your identity provider: once it stops letting them in, they can’t sign in through it. Remove them on the Members page as well, which ends their membership.
After a downgrade
SSO is a Scale feature. A downgrade takes effect on the 1st of a month at least 30 days after you ask (changing plan); until then nothing changes. From its date:- The connection stays. Your members keep signing in through your provider.
- Nobody new joins through it, and owners can’t open the Admin Portal to change it.
- Upgrading again restores all of it at once. Nothing has to be set up again.