SSO & Identity Integration
SAML 2.0, OIDC, and SCIM integration with every major identity provider. Setup in under 30 minutes with our guided configuration wizard.
Enterprise identity protocols
SAML 2.0
Industry-standard Security Assertion Markup Language for enterprise SSO. Supports SP-initiated and IdP-initiated login flows with signed assertions and encrypted name IDs.
- ◆SP-initiated and IdP-initiated SSO
- ◆Signed assertions (RSA-SHA256)
- ◆Encrypted NameID support
- ◆Single Logout (SLO)
- ◆Metadata exchange (URL and XML)
- ◆Multiple certificate rotation
OpenID Connect
Modern OAuth 2.0 based identity protocol. Supports Authorization Code flow with PKCE for maximum security. Compatible with any OIDC-compliant identity provider.
- ◆Authorization Code + PKCE flow
- ◆ID Token validation (RS256)
- ◆UserInfo endpoint integration
- ◆Custom scope mapping
- ◆Token refresh and revocation
- ◆Dynamic client registration
SCIM 2.0
System for Cross-domain Identity Management for automated user lifecycle management. Automatically provision, update, and deprovision users as changes occur in your identity provider.
- ◆User create, update, delete
- ◆Group membership sync
- ◆Schema extension support
- ◆Bulk operations
- ◆Change detection via ETags
- ◆Filter and pagination support
Identity provider setup walkthrough
Okta
Azure Active Directory
Google Workspace
OneLogin
PingIdentity
Role-based access control (RBAC)
Organization Admin
Full platform access including user management, SSO configuration, billing, and all data
FinOps Lead
Full access to cost data, recommendations, governance policies, and reporting across all accounts
Team Lead
Cost data access for assigned teams/accounts. Create budgets, dashboards, and reports within scope
Analyst
Read access to cost data and recommendations. Create personal dashboards and export data
Viewer
Read-only access to shared dashboards and reports. No data export or configuration access
API Service Account
Programmatic access with configurable scopes. Rate limits per service account with audit logging
Enterprise identity security
Multi-Factor Authentication
Enforce MFA for all users with support for TOTP authenticator apps, SMS, and hardware security keys (FIDO2/WebAuthn). Configurable per-role MFA requirements.
IP Allowlisting
Restrict platform access to approved IP ranges and CIDR blocks. Support for VPN and corporate network ranges with automatic violation alerting.
Session Management
Configurable session timeouts from 15 minutes to 24 hours. Concurrent session limits, forced logout, and active session monitoring.
Conditional Access Policies
Define access policies based on user location, device type, risk level, and time of day. Integrate with Azure AD Conditional Access and Okta policies.
Audit Logging
Complete audit trail of all authentication events, permission changes, and data access. Export to SIEM platforms via Splunk, Datadog, or syslog.
Password Policy
Configurable password complexity, rotation, and history requirements for local accounts. Integration with corporate password policies via SSO.
Need help with SSO setup?
Our implementation team will configure SSO for you as part of enterprise onboarding.
Contact Sales