Connect company SSO
Contact [email protected] to enable SSO for your company and arrange approval of your SSO organization. Setup requires the company owner account. Work with your identity provider administrator to configure and test the connection.- Sign in as the company owner, open Security, and select Manage SSO.
- Complete Verify your identity when prompted. Use your Devolens username and password and complete two-factor authentication if enabled. If the account has no password and no two-factor authentication, use Verify account by email.
- Select Connect SSO to connect the company to its approved SSO organization and open the administration portal. If you see a message asking you to contact support, email [email protected]: our team needs to finish setup or approve the organization before you can continue. Once connected, configure and test your identity provider connection in the portal. You can reopen it later with Configure SSO / SCIM.
- Return to Company SSO, select Connect my SSO identity, and complete company sign-in with the email address on the owner account.
- Choose a User provisioning mode below and select Save. Review the confirmation when switching to JIT or SCIM.
Choose How Users Are Provisioned
JIT and SCIM are user provisioning modes: they determine how operator accounts are created or connected to your company. SSO is how those users sign in.
See Restricted accounts for operator permissions. In Existing users and JIT modes, grant dashboard permissions on the Operators page when needed. Employees who only view licenses through customer associations do not need these additional permissions.
Reuse an Existing Operator Account
Associating an existing operator account means adding it to your company’s list on the Operators page. Dashboard permissions and customer associations are managed separately. To associate an existing account, share the invitation link from the Operators page. The employee signs in to their existing Devolens operator account, opens the invitation link, and accepts it. Check that they appear on your Operators page and that their account email matches their company sign-in email.- With JIT user provisioning, complete this before their first SSO sign-in.
- With SCIM user provisioning, complete this before the directory first provisions them, including the initial synchronization when you enable SCIM.
Just-in-Time Provisioning
JIT supports two onboarding paths:- Reuse an existing account: follow the association steps above before the first SSO sign-in. On first use, follow the account-verification prompts to connect the SSO identity. Existing operator permissions are retained.
- Create an account through SSO: a new user can complete company SSO sign-in and have an operator account created automatically. The new operator starts without dashboard resource permissions.
Enable and manage SCIM
Before enabling SCIM
- Review your existing operators and record any local permissions you may need to recreate later. If an employee already has an operator account you want to reuse, complete the company association steps before the first synchronization.
- In Configure SSO / SCIM, configure and enable the company directory. Include every operator who must retain access in SCIM provisioning, and check their email addresses and active status. Being able to authenticate with SSO alone is not enough in SCIM mode.
- When selecting SCIM for the first time, leave only one directory enabled.
- Review the directory role mappings below and confirm that each operator has the intended role. Existing local permissions, including resource-specific rules, will be replaced.
Directory Role Mappings
The following directory roles grant permissions in Devolens:
These permissions apply to all resources of each listed type. See operator permissions for what View, Edit and Owner allow. Analytics currently provides read-only access at all three permission levels.
If a user has several mapped roles, the highest permission for each resource type applies. Roles without a matching mapping grant no dashboard resource permissions. The
company_admin role does not change who owns the company account; SSO setup still requires the company owner account.
Manage directory users
While SCIM is enabled:- Manage operator permissions, suspension, removal, and restoration through your identity provider. The Operators page shows these accounts as Directory managed; manual operator invitations and local permission changes are unavailable.
- Once suspension or deletion updates are processed, the operator loses company access and their company SSO sessions are revoked.
- Check the active user count, last synchronization time, and synchronization notices on Company SSO. Select Synchronize now to refresh the directory manually.
Employee access to internal licenses
An operator can also accept a customer invitation, called a customer association link. This is useful when your organization licenses software for its own employees: each employee signs in with their operator account and views the licenses linked to the customer records they are associated with. The company operator invitation and the customer association link serve different purposes. The first associates an operator with your company; the second gives that account access to a customer’s licenses.- Onboard the employee as an operator. Share the company operator sign-up link from the Operators page. Have the employee register with their company email, or sign in to their existing operator account and accept the invitation. When reusing an account with JIT or SCIM user provisioning, follow the association steps before the first JIT sign-in or SCIM provisioning. An operator already created through JIT or SCIM can also accept customer association links.
- Prepare the customer record and licenses. On the Customers page, create or select a customer record containing the licenses the employee is permitted to use. Turn on Enable Customer Association. If several employees should access the same customer’s licenses, also enable Allow Multiple User Association.
- Share the customer invitation. Copy Customer Link from the customer record and share it with the intended employees. Each employee opens it while signed in with their operator account and accepts any configured terms of use. If prompted to sign in, they should return to the association link afterward.
- View the licenses in the customer portal. The employee can see licenses belonging to their associated customer records. Associate the operator with additional customer records when they need access to those licenses too.
No extra operator permissions are needed to view these licenses. For employees who only need this access, leave operator permissions unset. Customer associations determine which licenses they can view; product or customer management permissions are unnecessary for this workflow.
Sign in and troubleshoot
On the login page, select Sign in with company SSO, enter your company email, and choose Continue with SSO. Use that same email at your identity provider. If you are signed in to a different Devolens account, sign out first. When connecting an existing account for the first time, Devolens asks you to verify that account. Enter its Devolens username and password, complete two-factor authentication if enabled, and follow the prompts to complete company sign-in. Accounts without a password and without two-factor authentication can use Verify account by email. Connecting SSO does not grant additional operator permissions.- Wrong account selected: sign out of the identity provider or choose the account matching the email you entered, then restart sign-in.
- Existing operator account was not connected: check that it was associated with the company before the first JIT sign-in or SCIM provisioning, and that its email matches company sign-in. If a separate account was created, contact support before continuing account setup; signing in with the original account does not merge the two.
- Cannot sign in with SCIM: confirm that the user has been provisioned and is active. For a recreated directory identity, check whether the owner needs to reconnect the directory user.
- Signed in but cannot see dashboard resources: check local operator permissions for Existing users or JIT; for SCIM, check active directory membership and mapped roles.
- Employee cannot see an internal license: check that the employee accepted the correct customer association link and that the license belongs to that customer record. Viewing these licenses does not require additional operator permissions.
- Setup or synchronization failed: review the error and Debug Information on Company SSO. If Manage SSO or SCIM is unavailable, or no approved SSO organization is found, contact support. Debug entries are temporary, so include the error and time when requesting help.