Security guide
Prepare SSO and SCIM
Connect enterprise identity only after tenant metadata and ownership are verified.
Last updated September 24, 2026
What to know
Enterprise identity is fail-closed until the organization, verified domains, WorkOS connection, directory, and operator launch flag are configured. Test login, just-in-time access, provisioning, suspension, and deprovisioning with non-production identities first.
Do this
- 1. Verify the organization and domains.
- 2. Configure the WorkOS connection and directory.
- 3. Run test-user SSO and SCIM lifecycle acceptance.
- 4. Enable production only after evidence is captured.