Feature

SSO + SCIM

Enterprise identity controls: SSO for access and SCIM for automated provisioning and deprovisioning.

Enterprise platforms need identity governance that matches their security requirements.

Manual onboarding and offboarding creates drift: people keep access they no longer need, approvals get assigned inconsistently, and audit trails become harder to validate.

SSO for governed access

Single sign-on connects OrchesTerra access to your existing identity provider, so authentication follows your established security posture.

SCIM provisioning

SCIM automates user and group lifecycle:

  • create accounts from IdP groups,
  • update membership changes automatically,
  • remove access when users or group memberships are revoked.

Why it matters for governance

Governance depends on predictable access control. When identity changes are automated, approval workflows stay aligned with your org structure.

Related: enterprise identity controls use case.

FAQ

Does SCIM reduce audit effort?

Yes. When membership changes are automated and recorded, auditors can trace how access decisions were sourced.

Platform evaluation

See OrchesTerra on your infrastructure

Request access to generate architecture from a repository, review the plan, and run governed reconciliation across AWS, Azure, GCP, and OCI.