SSO, JIT, group mapping and SCIM
What EID-1.0 implements, what depends on external configuration and how enterprise identity connects to role and scope.
How to interpret this document
This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.
Authentication foundation
The session is established by Base44 authentication. EID-1.0 adds Enterprise policy, verified domains, provider status, JIT and group mappings.
SSO required
Mandatory SSO should not be enabled just because the control plane exists. It requires a configured provider, verified domain and tested recovery access to avoid organizational lockout.
JIT
Just-in-time provisioning can create or associate identity on the first authorized login according to tenant policy.
Group mapping
External groups can map to role, workspace and department. Mapping should follow least privilege and have an explicit fallback.
SCIM
The SCIM lifecycle depends on runtime token and organization configuration. Endpoint availability does not mean provisioning is active.
Offboarding
Deprovisioning should remove access without deleting historical audit, billing or ownership evidence already recorded.