SSO and SCIM
16 min
ashby supports single sign on (sso) via security assertion markup language (saml) and openid connect (oidc) connections, along with directory system for cross domain identity management (scim) through workos sso can be configured on the foundations, legacy plus, plus, and enterprise plans foundations legacy plus plus enterprise ✅ ✅ ✅ ✅ scim can be configured for accounts on the legacy plus, plus, and enterprise plans foundations legacy plus plus enterprise ❌ ✅ ✅ ✅ sso and scim overview sso and scim are essential tools for modern businesses ashby integrates with workos to provide seamless sso and scim capabilities, ensuring secure access and efficient user management for your organization getting started how do i set up sso/scim for my organization? reach out to our support team at support\@ashbyhq com mailto\ support\@ashbyhq com with the following details the email address where you'd like any error messages or notifications directed (it service account recommended) whether you'd like to set up sso, or both sso and scim support will follow up, providing you with a setup link once you receive the link, follow the on screen instructions to integrate your identity provider with ashby via workos the steps are tailored to your identity provider okta provisioning settings when configuring the ashby app's provisioning settings in okta, set the application username format to email , not custom this setting ensures okta correctly matches existing ashby accounts if you unassign and later reassign a user if you leave this setting as a custom expression, such as one that references the okta internal user id, reassigning a previously removed user can fail with a user already exists error because okta cannot find the existing account to reactivate test the integration to ensure everything is working correctly confirm with support once you've completed the setup process for sso, you can connect multiple domains, with different identity providers if needed you can also set up multiple workos connections for scim and users from the connected systems will flow into ashby what attributes are pulled via scim? once you've configured scim on your company's account, you can determine the attributes that are synced over by navigating to admin > integrations > scim in the fields to sync section, use the toggles to confirm the information that syncs from workos screenshot of the fields to sync section in ashby's scim integration settings the following fields can be synced job title name updates cost center department division groups manager job title, name, and manager are immediately useful for storing up to date information on all your employees without having to manually maintain it in ashby cost center, department, and division can be useful for further reporting on or grouping employees these fields are pulled over as employee custom fields in ashby and information synced to these fields appears in the employment info section of the employee's profile in admin > organization setup > employees screenshot of synced employee fields displayed on the employee profile page in ashby troubleshooting "user already exists" error when reassigning a user in okta if you unassign a user from the ashby app in okta and later reassign them, you may see a user already exists error, and the user remains deactivated in ashby this happens when okta's application username format for the ashby app does not match the identifier used to provision users okta cannot find the existing deactivated record, so it attempts to create a new one instead of reactivating it to fix this, open your okta admin console, open the ashby app's provisioning settings, and confirm that application username format is set to email once the identifiers align, unassigning and reassigning a user correctly reactivates their existing ashby account if you already see this error and have deactivated users stuck in a conflict, contact ashby support mailto\ support\@ashbyhq com for help clearing the affected records pricing how much does the sso/scim service cost? sso is included for plus and enterprise plans for those on the foundations plan, sso is a paid add on it costs $100 per month, billed monthly or annually, depending on your plan faqs what is sso? sso (single sign on) allows users to access multiple applications with a single set of credentials this means you don't have to remember multiple passwords for different services what is scim? scim (system for cross domain identity management) is a standard that automates the exchange of user identity information between identity domains or it systems which identity providers do you support? through our integration with workos, we support a wide range of identity providers, including but not limited to google workspace, microsoft azure ad, and okta see workos integrations https //workos com/docs/integrations for a full list of identity providers do you support just in time (jit) provisioning? we don't currently support just in time (jit) provisioning submit a feature request to support\@ashbyhq com mailto\ support\@ashbyhq com if you're interested in this option i have users in ashby that are not in my directory if i set up scim, will those users still be active when the directory sync is enabled? no, any users that are in ashby but not in your directory are deactivated in ashby once the sync is enabled before directory sync is enabled, confirm that the list of users in your directory is the full list of users that need to access ashby do you support log streams or domain verification? we do not support log streams or domain verification how do i get the setup link for sso/scim integration? contact your customer success manager or our support team at support\@ashbyhq com mailto\ support\@ashbyhq com is the sso/scim integration secure? absolutely! our integration with workos ensures that all data is encrypted and securely transmitted we adhere to industry best practices to ensure the safety and privacy of your data learn more about ashby's security practices https //www ashbyhq com/resources/security i'm facing issues with the sso/scim setup what should i do? if you encounter any issues during the setup or have questions about the integration, reach out to support\@ashbyhq com mailto\ support\@ashbyhq com we're here to help! can i use both sso and scim together? yes, you can use both sso and scim together while sso streamlines the login process, scim ensures efficient user management across platforms can permissions be mapped with scim? at this time, we only support provisioning users, not mapping permissions or access roles via scim users are added, via directory sync, as limited access users you can change their permission level in their employee profile once the user account has been created within ashby via the sync for more on permission levels, see user permissions docid\ i5jhibmkqhyobnnvrl8rk once configured, how often do scim syncs happen? scim syncs happen hourly we also respond to webhooks