How to Set Up SSO and SCIM for AI Tools and Agents

Last updated ·Read as Markdown
Answer

Single sign-on (SSO) decides who can sign in, and System for Cross-domain Identity Management (SCIM) decides which accounts and groups exist in the downstream tool. For AI tools, connect your identity provider for sign-in, map its groups to tool access, and have provisioning disable accounts when people leave. Metorial documents SSO for portals, with groups that can match SSO group IDs. Its public documentation does not describe SCIM provisioning, so confirm that before planning around it.

An AI tool with its own usernames and its own group list is a second directory to keep in step with the first. SSO and SCIM are how you avoid that, and the setup is mostly deciding what your identity provider is the source of truth for.

If you need
Use
People to sign in with company credentials
SSO, through your identity provider
Accounts created and disabled automatically
SCIM provisioning, where the tool supports it
Access that follows team membership
Groups mapped from your identity provider
A leaver's agents to stop working
Disable the person, then remove their groups

What do SSO and SCIM each do?

Single sign-on (SSO) handles sign-in. With SAML (Security Assertion Markup Language) 2.0, an identity provider authenticates the person and sends the tool a signed assertion. The assertion can carry attributes such as email and group membership. OpenID Connect (OIDC) plays the same role with a different protocol.

System for Cross-domain Identity Management (SCIM) handles accounts. It is an HTTP and JSON protocol, defined in RFC 7644, with standard Users and Groups resources and operations to create, read, replace, patch, and delete them. Its core schema includes an active attribute, where false typically means the account is suspended.

The difference matters at offboarding. SSO decides whether someone can sign in. SCIM decides whether the account and its group memberships still exist.

What does Metorial document today?

Metorial documents SSO for portals. Portal authentication covers SSO tenants, email or domain allowlists, and session expiry. Access groups can apply to every account by default or match SSO group IDs, and the product pages describe SAML sign-in with group import.

Accounts are created by invitation. In Workforce, under Identity, Accounts, select Invite User. Metorial's public documentation does not describe SCIM provisioning or deprovisioning. If you need it, ask in a demo before you plan around it. The rest of this page describes what the standards expect, so you can check any tool against it.

How do you set up SSO for AI tools?

1. Pick the groups first. List the identity provider groups that should map to AI tool access, such as engineering, support, and finance. Reuse existing groups where you can.

2. Configure sign-in. In Metorial, open Workforce, then Portals, open the portal, and go to its authentication settings. Add the SSO tenant, set any email or domain allowlist, and choose a session expiry.

3. Create matching access groups. Under Access, Groups, create a group for each team and match it to the SSO group ID. Turn on default assignment only for a group every new account should join.

4. Allow groups on resources. Open each integration or skill, select Add Group in its Access section, set Allow or Deny, and save. How to control which AI tools each team can use covers this in more depth.

5. Test the real path. Open the portal as a person in each group, using the same sign-in route your users will, and confirm they see the right integrations and skills.

What should provisioning do?

Whether through SCIM or a manual process, provisioning has four jobs:

  1. Create the account when someone is assigned to the application in the identity provider.
  2. Keep group membership current as people change teams.
  3. Suspend the account when someone leaves, which SCIM expresses as active set to false.
  4. Keep the record of what the person did, even after the account is gone.

Without SCIM, jobs one to three become manual steps. Follow How to onboard and offboard employees' AI tool access: remove group assignments and direct grants on the account's Access view, and offboard the person in the identity provider. Their past calls stay in Tracing.

What should you check in a security review?

  • Who owns the mapping between identity provider groups and tool groups, and who is told when it changes.
  • How long a session lasts after a person is disabled. A short session expiry limits the gap.
  • Whether agents act under the person's identity or a shared credential. The tokenless approach ties them to the person.
  • Whether automated agents use service accounts with named owners.
  • Whether logs show the person for every call.

How do you test offboarding?

Do not assume the chain works. Each quarter, create a test account in a test group, connect an integration, and run one tool call. Then disable the account in the identity provider, remove its groups, and try again. Check the Tool Calls table for the result, and write down how long the gap lasted. That number, not the vendor's feature list, is what your security team needs.

Frequently asked questions

What is the difference between SSO and SCIM?

SSO is how a person proves who they are at sign-in, using your identity provider. SCIM is a standard for creating, updating, and disabling user accounts and groups in another system. SSO stops new sign-ins for someone who left, while SCIM removes or suspends the account itself.

Does Metorial support SSO?

Metorial documents SSO for portals: administrators configure SSO tenants, email or domain allowlists, and session expiry, and its product pages describe SAML sign-in with group import. Test the same sign-in path your users will take before rollout.

Does Metorial support SCIM provisioning?

Metorial's public documentation does not describe SCIM provisioning today. Accounts are created by invitation or on sign-in, and access groups can match SSO group IDs. If automatic provisioning and deprovisioning are a requirement, ask Metorial directly.

How do groups from the identity provider reach AI tool access?

In Metorial, access groups can apply to every account by default or match SSO group IDs. Allowing a group on an integration or skill then gives everyone in the matching identity provider group that access.

What happens to an AI agent when its owner leaves?

It should lose access with the person. Agents that act for a person use that person's access, so removing their groups removes it. Automated jobs should run on a service account with its own owner so they do not break or linger.

Sources

  1. Metorial documentation: Portals
  2. IETF RFC 7644: System for Cross-domain Identity Management Protocol
  3. OASIS: Security Assertion Markup Language (SAML) V2.0 Technical Overview

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.