Skip to main content

Enhanced SSO: Self-Service Configuration, Roles & Tenants, and SCIM Deprovisioning

You can now set up and manage your organization's Single Sign-On directly in Panorays. This feature must be enabled by your account team in Panorays. Currently supported for SAML protocol only. Support for OIDC (OAuth) is planned for a future release.

This release moves SSO into self-service, adds attribute-based access rules, and introduces automated de-provisioning.


What's New

  • Self-service SSO configuration page - Admins can now set up and manage SSO directly from Company Settings → Single Sign-On, without involving Panorays Support.

  • Roles & Tenants attribute rules - Define rules that automatically assign users to the correct roles and tenants based on attributes sent by your Identity Provider (IdP). For example: department = security → assign Observer role. Rules are re-evaluated on every login, so access stays current as IdP attributes change.

  • User de-provisioning via SCIM - When a user is deactivated in your IdP, they're automatically marked as inactive in Panorays - no manual off-boarding needed.


How to Use It

  1. Contact Panorays to enable it in your environment.

  2. Complete your SSO provider configuration directly on the settings page (provide your IdP metadata or required connection details for your SAML provider).

  3. Under Roles & Tenants, add attribute-based rules: select the IdP attribute, define the value condition, and assign the target role and/or tenant.

  4. Enable SCIM de-provisioning to automatically deactivate users in Panorays when they're removed in your IdP.

  5. Save your configuration. Rules take effect on the next user login.


Did this answer your question?