Register an identity provider
Registering a provider needs an organization Owner or Admin: a provider decides who can become a member, which is the same class of authority as inviting people.1
Add identity provider
Choose Add identity provider. Pick the Protocol and enter the Email domain (for example
bigcorp.com). One provider covers exactly one domain.2
Enter what the IdP administrator provides
- OpenID Connect — the Issuer URL, Client ID, and Client secret. Endpoints are discovered from the issuer; nothing else has to be retyped.
- SAML 2.0 — the Sign-on URL, and optionally the IdP metadata XML. The IdP administrator in turn needs the SAML metadata address, shown at the bottom of the page once a SAML provider exists — append the provider’s domain as
providerId.
3
Verify the domain
The new row shows Domain unverified. Choose Get DNS record: the page shows a TXT record — host is the domain, value is a token. Publish it in the domain’s DNS, then choose Verify domain. On success the row shows Enabled.
How members sign in
On the sign-in page, below the password form, is Sign in with your company account. The person enters their work email. If its domain has an enabled provider, they are sent there and come back signed in. If not, the page says the domain has no single sign-on configured and offers the way back to password sign-in. Nobody needs to be created or invited beforehand. The first successful sign-in through a provider makes the person a member of the organization that registered it, with the Viewer role.What SSO decides — and what it does not
- The IdP proves who someone is. It does not decide how much authority they hold. Everyone arriving through SSO joins as Viewer. Raising them is the organization’s decision, made on Members & roles — as an organization role, or per Business Unit.
- Deactivating a person at the IdP stops their SSO sign-in. Their membership on orriven stays until it is removed on Members. There is no automatic deprovisioning.
- Password sign-in stays available. SSO cannot be made mandatory for an organization.
- Sign-in always starts on orriven’s page. Sign-in started from the IdP’s own portal is not supported.
- Attendees are not affected. Attendees never sign in; they reach their own pages through the links the platform emails them. See Hosted pages.
Rules to know
- One provider, one domain. A group with five email domains registers five providers. An organization can register up to ten.
- Unverified means inert. A provider whose domain has not been verified is listed, but no one can sign in through it.
- Removing a provider removes only the sign-in route. Choose Remove on its row. People who joined through it stay members until removed on Members.
- Owner or Admin only — for adding, verifying, and removing providers alike.
Related
Members & roles
Where SSO-provisioned Viewers are raised to the role they need.
Roles
What a Viewer — and every other role — may do.