Configure SSO
Enterprise SSO is an admin-owned, plan-gated WorkOS workflow under Configuration -> Tenant Management -> SSO. ITLedger can request setup, create or reuse the tenant's WorkOS organization, open the hosted WorkOS configuration portal, refresh connection and domain-verification state, and apply a default role plus optional group-to-role mappings. Richard should guide this UI flow; SSO secrets and provider configuration do not belong in chat.
Steps
- Go to Configuration -> Tenant Management -> SSO and review subscription eligibility and current connection state.
- Choose the identity provider, enter the tenant domain and identity-admin email, then request setup.
- Open the generated WorkOS portal link and complete provider configuration outside Richard chat.
- Return to ITLedger and refresh the connection state until the expected domain and connection are verified.
- Choose the default fallback role and configure only deliberate identity-provider group-to-role mappings.
- Enable role synchronization only after validating mappings and password-fallback policy.
- Test sign-in and effective permissions with a non-admin pilot account before rollout.
Notes
- SSO setup is subscription-gated; the API reports both setup eligibility and paid SSO eligibility for the current tier.
- Supported provider values are microsoft_entra_id, okta, google_workspace, and other.
- Use the hosted WorkOS portal link for provider configuration; never ask an admin to paste credentials, certificates, or secrets into Richard chat.
- The default role and every group mapping must resolve to a valid built-in or tenant permission role.