All guides › Set up for the team
Set up for the teamCompany sign-in: SAML or OIDC, SCIM and the controls around them
On Enterprise, people from your domains sign in through your identity provider, SCIM adds and removes them, and the IP allowlist and audit streaming cover the rest.
Someone leaves the company on Friday. Their laptop is wiped, their directory account disabled, and on Monday they can still open the client's acceptance runs because the review tool had its own login. With company sign-in and SCIM, disabling the account in your directory ends their access to Kaloko too.
The problem
Every tool with its own sign-in is one more list of people to keep in step with the directory. Security reviews ask how access is granted, how it is removed and where it is logged, and the honest answer is "by hand".
What changes with Kaloko
On the Enterprise plan an organization admin connects your identity provider under Settings → Security. People from your verified domains then sign in through it, SCIM creates and removes their accounts, and every change lands in the audit log, which can stream to your SIEM. Guests from other companies keep signing in as before.
How it works
- Verify your domain
under Settings → Domains. Company sign-in and SCIM act only on addresses from your verified domains.
- Connect the provider
SAML (Okta, Entra ID, Google Workspace and others) with your provider's metadata, or OIDC with the issuer, client ID and secret. Test connection shows what the provider sent and whether Kaloko would accept it; nobody is signed in by the test.
- Enforce it
after a successful test, people from those domains sign in only through your provider. Admins with a passkey or an authenticator app keep a way in for the day the provider is down.
- Provision with SCIM
paste the SCIM base URL and token into Okta or Entra ID. Assigned people join with their domain's default role, pushed groups map to projects and roles, and deprovisioning ends sessions, revokes tokens and removes them from projects. SCIM never makes anyone an admin.
- Close the rest
allowed IP ranges for the app and for the API, CLI and MCP; audit entries streamed to a signed webhook, Splunk HTTP Event Collector or a Datadog-compatible endpoint.
What you get
- SAML with signed responses or assertions, encrypted assertions with the organization's own key pair, single logout in both directions, and sign-in from your provider's app tile when you turn it on.
- Your provider's second step counted as Kaloko's MFA when you allow it, for sign-ins through your own provider.
- Service accounts and admin tokens for automation that belongs to no person.
- An audit log of who changed what, for your auditors and your SIEM.
FAQ
Which plans have company sign-in?
Enterprise. Every plan has sign-in by e-mail link, Google, Microsoft and GitHub, and personal MFA with passkeys or an authenticator app. Business adds an MFA requirement for the organization, session limits and the audit log page with its export.
Do client reviewers need accounts in our directory?
No. Company sign-in covers your verified domains only. Clients and other guests sign in as before and stay limited to the projects you invite them to.
Is there a step-by-step setup guide?
Yes, for Okta, Entra ID and Google Workspace. Enterprise customers get it with onboarding; write to support@sinfin.cz. Where your data lives and who processes it is on the trust page.