Administration
SSO and SAML Setup
Learn how to connect a SAML identity provider, map IdP groups to Rivolq roles, verify your domain, and enforce SSO safely.
Updated September 15, 2026
SSO replaces per-user passwords with your identity provider, handles MFA centrally, and revokes access from one place when employees leave. It is worth the setup for any org over about 20 users.
Supported providers
Rivolq's customer SSO setup is SAML-based and works with common identity providers: Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, OneLogin, Auth0, and generic SAML 2.0.
Setup at a glance
- 01Go to Settings, then SSO, then New connection and pick your provider type, or Generic SAML.
- 02Rivolq generates an SP metadata URL and ACS URL. Give these to your IdP admin.
- 03Your IdP admin configures Rivolq as a SAML application and returns an IdP metadata URL or XML.
- 04Paste the IdP metadata into Rivolq.
- 05Configure attribute mapping.
- 06Test with a single user before rolling out.
Provider-specific guides are under Settings, then SSO, then Setup guides.
Attribute and group mapping
Map email to the IdP email or mail attribute, full name to displayName or cn, and role from group membership. Map IdP groups to Rivolq roles: rivolq-admins to Admin, rivolq-supervisors to Supervisor / Planner, rivolq-technicians to Technician, rivolq-inventory to Inventory Manager, rivolq-viewers to Viewer, and rivolq-contractors to Contractor. Roles are set automatically at sign-in from group membership, so role management happens in your IdP. Review Roles and permissions before mapping groups.
Domain verification and enforcement
Before enabling enforcement, verify your domain under Settings, then SSO, then Domain verification by adding a DNS TXT record. Once verified, only users with emails on that domain can sign in through this connection. Enforcement has three levels: Optional (SSO or password), Required for SSO domain, and Required for all. Do not enable Required for all until you have a backup admin who is not on SSO. Locking yourself out is the most common SSO mishap.
SCIM provisioning and tips
Enable SCIM under Settings, then SSO, then SCIM provisioning. Rivolq generates a SCIM endpoint URL and bearer token for your IdP admin, and your IdP can then create, update, and deactivate Rivolq accounts as users move in and out of SSO groups.
Test with a non-admin first. Keep one non-SSO emergency admin with a strong password and MFA. Roll out in phases: optional for a week, then required. Common mistakes are enforcing before testing, group mappings that make everyone a Viewer, and skipping domain verification.
Still need help?
Reach out for broken behavior, account-specific help, or billing questions.
