Single-Sign On and User Management

How SSO makes controlling access to Operating easy

Written By Matti Parviainen

Last updated About 2 months ago

SSO basics

In order to get SSO activated for your Operating organization, reach out to support@operating.app and we’ll get it done. If you’re using Microsoft Entra, have a look at the step-by-step instructions here.

Creating users in Operating

Operating Users are created when the user accesses Operating for the first time. Before your colleagues have logged in using SSO for the first time, you won’t see them in the Settings → Users list.

Upon first login, they will:

  • get a User with the default permission set

    • the User is identified by their SSO ID

    • most SSO systems also provide an email address, which is saved in Operating

  • be matched to a Person with their email address – if no match is found, no User-Person mapping is made

Known issues / FAQ

Question

Answer

What happens to users that we created before we turned SSO on?

They will remain duplicates, and will be able to access Operating using the email+password authentication unless specified otherwise. Let us know if you’d like to get rid of them.

What happens when a SSO user changes their email address?

Not a problem, we identify them based on the SSO ID. If you’d like us to edit their user’s email address in Operating, email us.

Do you support SCIM?

Not yet.

Is it possible to assign groups, sites, and other metadata to the Person related to a new SSO User?

Yes, the Person API is your friend.