SSO user provisioning
When users authenticate via SSO for the first time, their user account is automatically created based on the information provided by your identity provider.Automatic account creation: New users are automatically added to your organization when they successfully authenticate via SSO, provided their email domain is configured for SSO.
Does Ravenna support SCIM?
Ravenna does not offer a SCIM endpoint for provisioning users and groups into Ravenna. User accounts in Ravenna are created just-in-time on first SSO sign-in, and deactivation happens automatically when the user can no longer authenticate through the identity provider. For syncing users and groups from an identity provider, use one of the Okta, Google Workspace, Microsoft Entra ID, or JumpCloud integrations. These keep group membership in sync so access policies and group provisioning work against the same directory you already manage. For provisioning access to downstream applications, Ravenna does not act as a SCIM client either. Access requests provision through the connected identity provider using group or direct application assignment, or through a workflow. See provisioning methods for the options that are available, including manual provisioning for tools that are not connected to an identity provider.User roles and permissions
SSO users are automatically added to your organization with default member permissions. However, there are important considerations for workspace access:Organization-level permissions
New SSO users default to Member role at the organization level. To modify their organization role:- Navigate to Organization Settings → Members
- Find the SSO user in the organization member list
- Update their organization role (Member, Admin, etc.) as needed
Workspace access
After SSO authentication, users need workspace access:- Navigate to the specific workspace
- Go to Members within that workspace
- Add the SSO user to the workspace
- Set their workspace role and permissions as needed
Deactivating SSO users
When employees leave your organization:- Remove from IdP: Deactivate or remove the user from your identity provider
- Automatic deactivation: The user will no longer be able to authenticate via SSO
- Manual cleanup: Optionally remove the user from organization settings
Custom attribute mapping
For complex organizational structures, you may need custom attribute mapping:Configuring attribute mapping
Work with your identity provider administrator to ensure these attributes are included in the authentication response and properly mapped to your organizational structure.Best practices
User access reviews
- Regular audits: Periodically review SSO user access and remove inactive accounts
- Role validation: Ensure users have appropriate permissions for their current role
- Workspace membership: Verify users are in the correct workspaces