> ## Documentation Index
> Fetch the complete documentation index at: https://help.cryptolens.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Company SSO and SCIM

> Set up company sign-in, provision operator accounts, and manage dashboard access through your identity provider.

Devolens (formerly Cryptolens) supports single sign-on (SSO) for your team's dashboard access through Scalekit. You can connect existing operator accounts, create operators on first sign-in with just-in-time (JIT) provisioning, or synchronize users and permissions from your identity provider with SCIM.

Operators can also accept customer association links to view the licenses assigned to those customers. This lets employees access internally licensed software without needing permission to manage products or customers. See [employee access to internal licenses](#employee-access-to-internal-licenses).

<Warning>
  **Enabling SCIM changes access for existing users.** Operators who are absent from SCIM provisioning lose company access and their operator association with the company. For provisioned operators, directory role mappings replace existing local permissions, including permissions restricted to a specific product or customer. The company owner is retained. Review the users and role mappings before enabling SCIM.
</Warning>

## Connect company SSO

Contact [help@devolens.com](mailto:help@devolens.com) to enable SSO for your company and arrange approval of your SSO organization. Setup requires the **company owner account**. Work with your identity provider administrator to configure and test the connection.

1. Sign in as the company owner, open [Security](https://app.cryptolens.io/Security), and select **Manage SSO**.
2. Complete **Verify your identity** when prompted. Use your Devolens username and password and complete two-factor authentication if enabled. If the account has no password and no two-factor authentication, use **Verify account by email**.
3. Select **Connect SSO** to connect the company to its approved SSO organization and open the administration portal. If you see a message asking you to contact support, email [help@devolens.com](mailto:help@devolens.com): our team needs to finish setup or approve the organization before you can continue. Once connected, configure and test your identity provider connection in the portal. You can reopen it later with **Configure SSO / SCIM**.
4. Return to [Company SSO](https://app.cryptolens.io/Security/Sso), select **Connect my SSO identity**, and complete company sign-in with the email address on the owner account.
5. Choose a **User provisioning** mode below and select **Save**. Review the confirmation when switching to JIT or SCIM.

New connections start with **Existing users** and optional SSO. Once sign-in works and operator onboarding is ready, select **Require SSO** under **Require Company SSO** to require company authentication before accessing company data. The owner must connect their SSO identity before enabling this setting. SCIM automatically makes company SSO required.

Devolens may ask you to verify your account again when managing SSO settings. If verification returns you to the settings page, repeat the action you were taking.

## Choose How Users Are Provisioned

JIT and SCIM are **user provisioning modes**: they determine how operator accounts are created or connected to your company. SSO is how those users sign in.

| Mode | How operators join | Permissions |
| - | - | - |
| **Existing users** | Operators must already have a Devolens account associated with your company. Their account email must match their company sign-in email. | Existing permissions are retained and managed in Devolens. |
| **Just-in-time** | Connects an existing company operator, or creates a new operator on the first verified company SSO sign-in. To reuse an account, associate it with the company first, as described below. | Existing operator permissions are retained. Automatically created operators start without resource permissions. |
| **SCIM** | Synchronizes accounts and their active status from your company directory. To reuse an account, associate it with the company before it is first provisioned. Users must be provisioned and active before signing in. | Directory roles determine access through configured role mappings. |

See [Restricted accounts](/feature/web-ui/restricted-accounts) for operator permissions. In Existing users and JIT modes, grant dashboard permissions on the [Operators page](https://app.cryptolens.io/Operator) when needed. Employees who only view licenses through customer associations do not need these additional permissions.

### Reuse an Existing Operator Account

Associating an existing operator account means adding it to your company's list on the [Operators page](https://app.cryptolens.io/Operator). Dashboard permissions and customer associations are managed separately.

To associate an existing account, share the invitation link from the **Operators** page. The employee signs in to their existing Devolens operator account, opens the invitation link, and accepts it. Check that they appear on your Operators page and that their account email matches their company sign-in email.

* With **JIT user provisioning**, complete this before their first SSO sign-in.
* With **SCIM user provisioning**, complete this before the directory first provisions them, including the initial synchronization when you enable SCIM.

<Warning>
  A matching email address alone is not enough. If the existing account is not associated with your company, JIT or SCIM can create a separate operator account. The normal sign-in process does not merge these accounts or move the connection to the original account. Contact support if a separate account has already been created.
</Warning>

### Just-in-Time Provisioning

JIT supports two onboarding paths:

* **Reuse an existing account:** follow the [association steps above](#reuse-an-existing-operator-account) before the first SSO sign-in. On first use, follow the account-verification prompts to connect the SSO identity. Existing operator permissions are retained.
* **Create an account through SSO:** a new user can complete company SSO sign-in and have an operator account created automatically. The new operator starts without dashboard resource permissions.

For invitation-based onboarding, share the sign-up link from the **Operators** page and have the employee complete registration before their first SSO attempt. In JIT mode, manual invitations are available only while company SSO is optional. Complete this onboarding before selecting **Require SSO**. When manual invitations are unavailable in JIT mode, the Operators page provides an **SSO Sign-In Link** for automatic account creation.

JIT does not itself make company SSO mandatory; use **Require SSO** to enforce it.

## Enable and manage SCIM

### Before enabling SCIM

1. Review your existing operators and record any local permissions you may need to recreate later. If an employee already has an operator account you want to reuse, complete the [company association steps](#reuse-an-existing-operator-account) before the first synchronization.
2. In **Configure SSO / SCIM**, configure and enable the company directory. Include every operator who must retain access in SCIM provisioning, and check their email addresses and active status. Being able to authenticate with SSO alone is not enough in SCIM mode.
3. When selecting SCIM for the first time, leave only one directory enabled.
4. Review the [directory role mappings](#directory-role-mappings) below and confirm that each operator has the intended role. Existing local permissions, including resource-specific rules, will be replaced.

Return to **Company SSO**, select **SCIM** under **User provisioning**, select **Save**, and review the access-change confirmation. Devolens performs an initial directory synchronization; SCIM is enabled only if that synchronization succeeds.

<Warning>
  The initial synchronization applies these access changes immediately. Existing operators missing from provisioning are removed from active company access. Enabling SCIM also makes company SSO required. Switching SCIM off later does not restore the previous permissions or automatically reactivate removed users.
</Warning>

### Directory Role Mappings

The following directory roles grant permissions in Devolens:

| Directory Role | Products | Customers | Analytics | Billing |
| - | - | - | - | - |
| `viewer` | View | View | View | No access |
| `manager` | Edit | Edit | View | No access |
| `company_admin` | Owner | Owner | Owner | Owner |

These permissions apply to **all resources of each listed type**. See [operator permissions](/feature/web-ui/restricted-accounts#permissions) for what View, Edit and Owner allow. Analytics currently provides read-only access at all three permission levels.

If a user has several mapped roles, the highest permission for each resource type applies. Roles without a matching mapping grant no dashboard resource permissions. The `company_admin` role does not change who owns the company account; SSO setup still requires the company owner account.

### Manage directory users

While SCIM is enabled:

* Manage operator permissions, suspension, removal, and restoration through your identity provider. The Operators page shows these accounts as **Directory managed**; manual operator invitations and local permission changes are unavailable.
* Once suspension or deletion updates are processed, the operator loses company access and their company SSO sessions are revoked.
* Check the active user count, last synchronization time, and synchronization notices on **Company SSO**. Select **Synchronize now** to refresh the directory manually.

If a deleted user is recreated with a different directory identity, the old account is not automatically restored based on its email address. Under **Deleted directory accounts**, select **Reconnect directory user**, verify that the replacement belongs to the original person, and select **Confirm reconnection**. Access follows the replacement's current status and roles; previous sessions remain revoked.

## Employee access to internal licenses

An operator can also accept a customer invitation, called a **customer association link**. This is useful when your organization licenses software for its own employees: each employee signs in with their operator account and views the licenses linked to the customer records they are associated with.

The company operator invitation and the customer association link serve different purposes. The first associates an operator with your company; the second gives that account access to a customer's licenses.

1. **Onboard the employee as an operator.** Share the company operator sign-up link from the [Operators page](https://app.cryptolens.io/Operator). Have the employee register with their company email, or sign in to their existing operator account and accept the invitation. When reusing an account with JIT or SCIM user provisioning, follow the [association steps](#reuse-an-existing-operator-account) before the first JIT sign-in or SCIM provisioning. An operator already created through JIT or SCIM can also accept customer association links.
2. **Prepare the customer record and licenses.** On the [Customers page](https://app.cryptolens.io/Customer), create or select a customer record containing the licenses the employee is permitted to use. Turn on **Enable Customer Association**. If several employees should access the same customer's licenses, also enable **Allow Multiple User Association**.
3. **Share the customer invitation.** Copy **Customer Link** from the customer record and share it with the intended employees. Each employee opens it while signed in with their operator account and accepts any configured terms of use. If prompted to sign in, they should return to the association link afterward.
4. **View the licenses in the customer portal.** The employee can see licenses belonging to their associated customer records. Associate the operator with additional customer records when they need access to those licenses too.

<Note>
  **No extra operator permissions are needed to view these licenses.** For employees who only need this access, leave operator permissions unset. Customer associations determine which licenses they can view; product or customer management permissions are unnecessary for this workflow.
</Note>

In SCIM mode, these employees must still be included and active in provisioning. Customer association does not replace the company SSO and provisioning requirements. For more on customer invitations, see the [Customer portal guide](/feature/customer-portal/index).

## Sign in and troubleshoot

On the [login page](https://app.cryptolens.io/Account/Login), select **Sign in with company SSO**, enter your company email, and choose **Continue with SSO**. Use that same email at your identity provider. If you are signed in to a different Devolens account, sign out first.

When connecting an existing account for the first time, Devolens asks you to verify that account. Enter its Devolens username and password, complete two-factor authentication if enabled, and follow the prompts to complete company sign-in. Accounts without a password and without two-factor authentication can use **Verify account by email**. Connecting SSO does not grant additional operator permissions.

* **Wrong account selected:** sign out of the identity provider or choose the account matching the email you entered, then restart sign-in.
* **Existing operator account was not connected:** check that it was associated with the company before the first JIT sign-in or SCIM provisioning, and that its email matches company sign-in. If a separate account was created, contact support before continuing account setup; signing in with the original account does not merge the two.
* **Cannot sign in with SCIM:** confirm that the user has been provisioned and is active. For a recreated directory identity, check whether the owner needs to reconnect the directory user.
* **Signed in but cannot see dashboard resources:** check local operator permissions for Existing users or JIT; for SCIM, check active directory membership and mapped roles.
* **Employee cannot see an internal license:** check that the employee accepted the correct customer association link and that the license belongs to that customer record. Viewing these licenses does not require additional operator permissions.
* **Setup or synchronization failed:** review the error and **Debug Information** on Company SSO. If **Manage SSO** or SCIM is unavailable, or no approved SSO organization is found, contact support. Debug entries are temporary, so include the error and time when requesting help.

## Turn off SCIM or disconnect SSO

To return to local user management, change provisioning to **Existing users** or **Just-in-time** and save. Active users retain their current permissions for local management; permissions removed or replaced by SCIM are not restored. Suspended and deleted members remain inactive. Company SSO stays required until you separately select **Make optional**.

To disconnect completely, first turn off SCIM, then make SSO optional, and select **Disconnect**. Review the account list in the confirmation. SSO cannot be made optional while SCIM is enabled.

<Warning>
  Disconnecting company SSO preserves the affected operator accounts, but removes their SSO connection, company operator association, and operator permissions for this company. Their company SSO sessions end. This has a different effect from only switching off SCIM.
</Warning>
