Configure SSO

Enterprise SSO is an admin-owned, plan-gated WorkOS workflow under Configuration -> Tenant Management -> SSO. ITLedger can request setup, create or reuse the tenant's WorkOS organization, open the hosted WorkOS configuration portal, refresh connection and domain-verification state, and apply a default role plus optional group-to-role mappings. Richard should guide this UI flow; SSO secrets and provider configuration do not belong in chat.

Steps

  1. Go to Configuration -> Tenant Management -> SSO and review subscription eligibility and current connection state.
  2. Choose the identity provider, enter the tenant domain and identity-admin email, then request setup.
  3. Open the generated WorkOS portal link and complete provider configuration outside Richard chat.
  4. Return to ITLedger and refresh the connection state until the expected domain and connection are verified.
  5. Choose the default fallback role and configure only deliberate identity-provider group-to-role mappings.
  6. Enable role synchronization only after validating mappings and password-fallback policy.
  7. Test sign-in and effective permissions with a non-admin pilot account before rollout.

Notes

Browse all documentation