Single Sign-On

View as Markdown

Single sign-on connects AIvis to the enterprise identity system. It reduces local account management and keeps onboarding, offboarding, and permission changes under centralized governance.

Management Boundary

AreaGuidance
Identity SourceUse an approved identity provider and domain.
MappingDefine user, group, role, and workspace mapping.
FallbackDefine emergency admin login and recovery behavior.
AuditRecord login, failure, configuration, and mapping events.

Before Configuration

  • Confirm provider metadata, callback URLs, and certificates are valid.
  • Plan admin accounts, test accounts, and fallback access.
  • Validate with security, user-group, and localization settings.

Verification

  • Log in, log out, and log in again with a test user.
  • Test an unauthorized domain or unmapped user and confirm denial.
  • Confirm login events and user mapping are auditable.