Skip to main content Announcing Tool Gateway MCP: the universal MCPRead the announcement

Identity · SSO and SCIM. Keep team access in sync with your directory.

Sync members and groups into StackOne, then use those groups to assign access to business systems.

Your directoryOkta or Microsoft Entra ID
Finance
Lena Ortiz
Daniel Okafor
Hannah Weiss

Membership managed in your directory

SCIM sync
StackOneIn sync
Finance3 members
Lena Ortiz
Daniel Okafor
Hannah Weiss
Access assigned in StackOne
Finance accountNetSuite · use the shared connection
Member
Finance documents profileGoogle Drive · connect own accounts
Member
Finance projectProject Member

SAML single sign-on. Choose how members sign in to StackOne.

Configure SSO and select the sign-in methods permitted for your organization.

Connect Okta, Microsoft Entra or Google Workspace through guided SAML setup. Use just-in-time provisioning to create members on their first sign-in, with the default project and role you configure.

Sign-in enforcement is an Enterprise control. Review the setup for members who belong to multiple organizations.

Just-in-time and SCIM provisioning. Add members through SSO or from your directory.

Just-in-time provisioning runs on your SSO connection. SCIM also keeps groups and deactivations in sync.

First sign-in
Just-in-time provisioning

Joins

Maya ChenCreated when she first signs in with SSO

Gets

Default project and role

ProductionMember

Leaves

Stays a member

Until an admin disables her in StackOneActive
Directory change
SCIM provisioning

Joins

Lena OrtizCreated when your directory assigns her, before she signs in

Gets

Default project and role, plus group grants

ProductionMemberFinanceSynced group

Leaves

Suspended and signed out

When your directory deactivates herSuspended

Groups and access. Assign access to business systems through your groups.

Manage membership in your directory and assign each group's access in StackOne.

  1. In your directory

    Operations group
    Ravi MenonMember
    Sam RiveraAdded to the group
    New
  2. In StackOne

    • Operations documentsGoogle Drive · connector profile
    • IT requestsServiceNow · shared connection

    From Operations' existing grants

  3. In Sam's agent

    Claude
    • List Files
    • Get File
    • Create Incident

Sync groups from Okta or Microsoft Entra through SCIM. As people join a group, they receive the connector profile and account access you've assigned to it.

Explore Connector Access

OAuth sign-in for AI agents. Agents act as the person using them.

Members connect Claude, ChatGPT, Cursor or Copilot by signing in through your SSO. Every call their agent makes carries their identity.

StackOne applies that member's account access and Permission Policies to each call, and the logs show it under their name. When your directory deactivates them, their agent's next call is refused.

  1. Claude calls as Priya

    Claude Priya Shah
    List SuppliersSAP S/4HANA · Procurement
    • Account accessMember
    • Permission PoliciesAllowed
  2. Logged under her name

    Northwind Logs Action logs
    09:38
    List SuppliersSAP S/4HANA
    Priya Shahvia Claude
    200 OK
    09:31
    Get FileGoogle Drive
    Noah Patelvia ChatGPT
    200 OK

SCIM deprovisioning. Revoke access when someone leaves.

Deactivate someone in your directory and StackOne suspends their membership and ends their sessions. Calls their agent makes for them are refused.

  1. Your directory

    Sam Rivera is deactivated

  2. Membership suspended and sessions ended

    • MembershipSuspended
    • SessionsEnded
    • Group grantsKept for reactivation
  3. Sam's agent, next call

    Get FileGoogle Drive · Operations documents
    Access revoked
See sign-ins in the audit logs

FAQ. Questions about SSO and SCIM

Connect your directory.

Talk through SSO, SCIM and how your groups will get access.