Single sign-on & team access

Configure enterprise SSO and manage who on your team can sign in and with what role.

Getting started

Under Settings, you manage how your team authenticates. SSO lets you federate login to your identity provider over OpenID Connect or SAML 2.0, with optional just-in-time provisioning, role mapping, and MFA pass-through. Team manages users and their roles (admin, auditor, viewer) directly.

How to use it

  1. Open Settings → SSO to configure an enterprise login connection.

  2. Create a connection, choose OIDC or SAML, and follow the provider-specific guide for the exact IdP steps.

  3. Set the email domains the connection applies to, choose whether to auto-provision new users (JIT) and their default role, and optionally map IdP groups to ComplianceScout roles.

  4. Test sign-in before rolling the connection out to your team.

  5. Use Settings → Team to invite users directly and manage roles when you're not using SSO provisioning.

Tips

  • Enterprise SSO is a tier-gated feature. Role mapping lets your IdP groups drive ComplianceScout admin/auditor/viewer roles automatically.

Open Single sign-on & team access in the app

Jump straight to the feature, or browse the rest of the guides.