Skip to content
DocumentationEnterpriseSSO, JIT, group mapping and SCIM
EnterpriseCurrent contractVersion DOCS-2.0

SSO, JIT, group mapping and SCIM

What EID-1.0 implements, what depends on external configuration and how enterprise identity connects to role and scope.

How to interpret this document

This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.

Authentication foundation

The session is established by Base44 authentication. EID-1.0 adds Enterprise policy, verified domains, provider status, JIT and group mappings.

SSO required

Mandatory SSO should not be enabled just because the control plane exists. It requires a configured provider, verified domain and tested recovery access to avoid organizational lockout.

JIT

Just-in-time provisioning can create or associate identity on the first authorized login according to tenant policy.

Group mapping

External groups can map to role, workspace and department. Mapping should follow least privilege and have an explicit fallback.

SCIM

The SCIM lifecycle depends on runtime token and organization configuration. Endpoint availability does not mean provisioning is active.

Offboarding

Deprovisioning should remove access without deleting historical audit, billing or ownership evidence already recorded.