Identity management
Verified domains, single sign-on, and SCIM provisioning — how they fit together and the order to set them up in.
Identity management lets your organization control BriefCatch access from your own directory: people sign in with your identity provider, and joiners and leavers follow your directory rather than a separate invitation list.
These features are Enterprise capabilities, and you need the admin or owner role to configure them. See Plans and licenses and Roles and permissions.
Set them up in this order
The three features build on each other, and the screens tell you when you are ahead of yourself.
Verify your domains
Proof that your organization owns the email domain. Until one is verified, the SSO screen shows “Verify a domain before enabling SSO” above the form. Verified domains and automatic membership
Connect single sign-on
Point BriefCatch at your identity provider so people sign in through it. Set up single sign-on
Set up SCIM provisioning
Let your directory create, update, and deactivate BriefCatch accounts automatically. Until SSO is connected, the SCIM screen shows “Connect SSO before setting up SCIM” and its controls stay disabled. Set up SCIM provisioning
The two notices behave differently: the SSO one is guidance above a form you can still fill in, while the SCIM one actually disables the controls until a connection exists.
You can stop after any step. Verified domains alone are useful, and SSO without SCIM is a normal setup. SCIM without SSO is not offered.
What each one does
Verified domains
Proves you own the domain. Shared by automatic membership and SSO discovery.
Single sign-on
People sign in through Okta, Microsoft Entra ID, Google Workspace, or any SAML or OIDC provider.
SCIM provisioning
Your identity provider manages the user lifecycle. Provisioned groups map to BriefCatch roles.
Where to find these settings
All three live under Settings → Security, as separate entries:
| Menu entry | What it covers |
|---|---|
| Domain | Verified domains and automatic membership |
| SSO | The single sign-on connection and enforcement |
| SCIM | Provisioning tokens and group mappings |
If you do not see them, check in this order:
- Your role. Identity settings require admin or owner.
- Your plan. These are Enterprise capabilities and are absent on other plans.
- Your active organization. The picker in the header decides which membership applies.
Important: organization SSO is not the same as social login
The Continue with Google and Continue with Microsoft buttons on the sign-in screen are social login for individual accounts. They are separate from an organization-managed SSO connection, even when the provider is the same company.
Signing in with a social button when your organization expects SSO produces a different identity, and that is the most common cause of “I have an account but my organization’s plan is not applied.” See Identity troubleshooting.
Related
- Teams and organizations — invitations, membership, and shared credits
- Roles and permissions — which role can configure identity
- Plans and licenses — which plans include these capabilities
- Identity troubleshooting — sign-in failures and mismatches