Identity · SSO and SCIM. Keep team access in sync with your directory.
Sync members and groups into StackOne, then use those groups to assign access to business systems.
Lena Ortiz
Daniel Okafor
Hannah WeissMembership managed in your directory
Lena Ortiz
Daniel Okafor
Hannah WeissSAML single sign-on. Choose how members sign in to StackOne.
Configure SSO and select the sign-in methods permitted for your organization.
Connect Okta, Microsoft Entra or Google Workspace through guided SAML setup. Use just-in-time provisioning to create members on their first sign-in, with the default project and role you configure.
Sign-in enforcement is an Enterprise control. Review the setup for members who belong to multiple organizations.
Sign-in methods for your organization
Enforced methods
Just-in-time and SCIM provisioning. Add members through SSO or from your directory.
Just-in-time provisioning runs on your SSO connection. SCIM also keeps groups and deactivations in sync.
Joins
Gets
Default project and role
Leaves
Stays a member
Joins
Gets
Default project and role, plus group grants
Leaves
Suspended and signed out
Groups and access. Assign access to business systems through your groups.
Manage membership in your directory and assign each group's access in StackOne.
-
In your directory
Operations group
Ravi MenonMember
Sam RiveraAdded to the groupNew -
In StackOne
- Operations documentsGoogle Drive · connector profile
- IT requestsServiceNow · shared connection
From Operations' existing grants
-
-
In Sam's agent
Claude
- List Files
- Get File
- Create Incident
Sync groups from Okta or Microsoft Entra through SCIM. As people join a group, they receive the connector profile and account access you've assigned to it.
Explore Connector AccessOAuth sign-in for AI agents. Agents act as the person using them.
Members connect Claude, ChatGPT, Cursor or Copilot by signing in through your SSO. Every call their agent makes carries their identity.
StackOne applies that member's account access and Permission Policies to each call, and the logs show it under their name. When your directory deactivates them, their agent's next call is refused.
-
Priya signs in
-
Claude calls as Priya
Claude
Priya Shah List SuppliersSAP S/4HANA · Procurement- Account accessMember
- Permission PoliciesAllowed
-
Logged under her name
09:38List SuppliersSAP S/4HANA200 OK
Priya Shahvia Claude09:31Get FileGoogle Drive200 OK
Noah Patelvia ChatGPT
SCIM deprovisioning. Revoke access when someone leaves.
Deactivate someone in your directory and StackOne suspends their membership and ends their sessions. Calls their agent makes for them are refused.
-
Your directory
Sam Rivera is deactivated
-
Membership suspended and sessions ended
- MembershipSuspended
- SessionsEnded
- Group grantsKept for reactivation
-
Sam's agent, next call
Get FileGoogle Drive · Operations documentsAccess revoked
FAQ. Questions about SSO and SCIM
Connect your directory.
Talk through SSO, SCIM and how your groups will get access.