ColleagueOne documentation

SSO & SCIM

Plan organisational sign-in and member lifecycle management with supported identity providers.

ColleagueOne supports Google and Microsoft Entra sign-in, SAML and OIDC single sign-on, and SCIM provisioning. Exact setup values are provided during private-beta organisation onboarding.

Choose an identity approach

Use an organisation-controlled identity provider when possible. Decide which domains and user groups should have access, who retains emergency ownership responsibility and how access will be removed when a person leaves.

SSO planning

Before configuration, gather:

  • the identity provider and protocol (SAML or OIDC);
  • authorised domains or groups;
  • the organisation administrators responsible for both systems;
  • sign-in and recovery requirements;
  • a small test group.

Configure and test the connection with the values supplied for your ColleagueOne organisation. Verify successful sign-in, rejected access and role expectations before broad rollout.

SCIM planning

SCIM allows the identity system to provision and deprovision members. Map groups and roles deliberately. Test the lifecycle of a non-production member: create, update and remove access, then inspect the resulting member state in ColleagueOne.

Safe rollout

  1. Preserve a documented administrative recovery path.
  2. Test with a small group before enforcing organisation-wide sign-in.
  3. Confirm that deprovisioning removes access as expected.
  4. Review colleagues, automations and approvals owned by a departing member.
  5. Record the organisation’s access-review cadence.

Troubleshooting

Check identity-provider logs and ColleagueOne audit information for the same attempt. Confirm identifiers, certificate or client configuration, redirect values, group mapping and clock settings. Do not weaken access policy broadly to resolve one user’s issue.

Contact the private-beta support channel for organisation-specific endpoints and credentials.