Documentation

Enterprise SSO & SCIM

AdminUpdated Sep 11, 2026

Enterprise SSO & SCIM

Large customers expect to manage access to your product through their identity provider (Okta, Microsoft Entra ID, Google Workspace, OneLogin…). Atlas lets you offer that without building SAML plumbing yourself.

Enterprise SSO (SAML) and SCIM provisioning

The three pieces

  1. SSO connection (SAML / OIDC) — the customer's IdP signs their employees in to your app. See SAML SSO setup.

  2. Enforced SSO per domain — everyone with an @customer.com email must sign in through that IdP; no passwords or personal logins. See Enforced SSO & domains.

  3. SCIM provisioning — the IdP automatically creates, updates and deactivates user accounts as employees join, change teams or leave. See SCIM provisioning.

How it fits your organizations

Enterprise connections are scoped to an organization. A customer's IdP feeds people into their org, with roles mapped from IdP groups — so authorization keeps working exactly as it does for everyone else.

What your customer's admin does vs what you do

You (the app)

Your customer (the IdP admin)

Create the org, enable an enterprise connection

Register Atlas as an application in their IdP

Share the Atlas SP metadata / ACS URL

Provide IdP metadata / certificate

Map IdP groups to Atlas roles

Assign employees and groups

Enforce SSO for their domain

Manage the directory going forward

Availability

Enterprise SSO, enforced SSO and SCIM are part of the Enterprise plan, which also includes an uptime SLA, data residency and a DPA. See Plans & billing or talk to sales.

Next

Set up the SSO connection → SAML SSO setup.

Was this page helpful?