- Single Sign-On (SSO) lets members sign in through your identity provider (Okta, Microsoft Entra ID, or any SAML 2.0 IdP) instead of a StackOne password.
- SCIM Provisioning creates and deactivates members automatically from that same identity provider, so joiners and leavers are handled for you.
- Groups grant many members the same project or account access at once, so you can manage least-privilege access as a team rather than one person at a time.
Set up identity and access
Manage Team
Invite members, change their roles, and remove people who leave.
Authentication
Set up Single Sign-On, or sign in with a password and MFA.
Provisioning
Add members by invitation, at their first SSO sign-in, or from your directory over SCIM.
Groups
Grant a whole team the same project or account access, and change it in one place.
How they fit together
- SSO authenticates. A verified SSO connection lets a member sign in, but it does not, on its own, place them in your organization.
- SCIM Provisioning manages membership. It creates and deactivates organization members from your IdP, and adds them to the projects you choose. Without it, membership comes from an invitation.
- Groups grant access. Once members exist, assign Groups to projects and accounts to give everyone in the group the same role, the strongest role a member holds always wins.
Audit and logs
Review sign-in and provisioning events under Security > Logs.
Back to Secure
IP restrictions, MFA, connector scoping, and the rest of your security settings.