Skip to main content
StackOne gives your organization three tools for governing access, and they build on each other:
  • Single Sign-On (SSO) lets members sign in through your identity provider (Okta, Microsoft Entra ID, or any SAML 2.0 IdP) instead of a StackOne password.
  • SCIM Provisioning creates and deactivates members automatically from that same identity provider, so joiners and leavers are handled for you.
  • Groups grant many members the same project or account access at once, so you can manage least-privilege access as a team rather than one person at a time.
A typical rollout runs in that order: connect SSO so people can sign in, add SCIM Provisioning so membership stays in step with your directory, then use Groups to grant the right access.

Set up identity and access

Manage Team

Invite members, change their roles, and remove people who leave.

Authentication

Set up Single Sign-On, or sign in with a password and MFA.

Provisioning

Add members by invitation, at their first SSO sign-in, or from your directory over SCIM.

Groups

Grant a whole team the same project or account access, and change it in one place.

How they fit together

  • SSO authenticates. A verified SSO connection lets a member sign in, but it does not, on its own, place them in your organization.
  • SCIM Provisioning manages membership. It creates and deactivates organization members from your IdP, and adds them to the projects you choose. Without it, membership comes from an invitation.
  • Groups grant access. Once members exist, assign Groups to projects and accounts to give everyone in the group the same role, the strongest role a member holds always wins.

Audit and logs

Review sign-in and provisioning events under Security > Logs.

Back to Secure

IP restrictions, MFA, connector scoping, and the rest of your security settings.