Kalokoby

All guides › Set up for the team

Set up for the team

Company sign-in: SAML or OIDC, SCIM and the controls around them

On Enterprise, people from your domains sign in through your identity provider, SCIM adds and removes them, and the IP allowlist and audit streaming cover the rest.

Someone leaves the company on Friday. Their laptop is wiped, their directory account disabled, and on Monday they can still open the client's acceptance runs because the review tool had its own login. With company sign-in and SCIM, disabling the account in your directory ends their access to Kaloko too.

The problem

Every tool with its own sign-in is one more list of people to keep in step with the directory. Security reviews ask how access is granted, how it is removed and where it is logged, and the honest answer is "by hand".

What changes with Kaloko

On the Enterprise plan an organization admin connects your identity provider under Settings → Security. People from your verified domains then sign in through it, SCIM creates and removes their accounts, and every change lands in the audit log, which can stream to your SIEM. Guests from other companies keep signing in as before.

How it works

  1. Verify your domain

    under Settings → Domains. Company sign-in and SCIM act only on addresses from your verified domains.

  2. Connect the provider

    SAML (Okta, Entra ID, Google Workspace and others) with your provider's metadata, or OIDC with the issuer, client ID and secret. Test connection shows what the provider sent and whether Kaloko would accept it; nobody is signed in by the test.

  3. Enforce it

    after a successful test, people from those domains sign in only through your provider. Admins with a passkey or an authenticator app keep a way in for the day the provider is down.

  4. Provision with SCIM

    paste the SCIM base URL and token into Okta or Entra ID. Assigned people join with their domain's default role, pushed groups map to projects and roles, and deprovisioning ends sessions, revokes tokens and removes them from projects. SCIM never makes anyone an admin.

  5. Close the rest

    allowed IP ranges for the app and for the API, CLI and MCP; audit entries streamed to a signed webhook, Splunk HTTP Event Collector or a Datadog-compatible endpoint.

What you get

FAQ

Which plans have company sign-in?

Enterprise. Every plan has sign-in by e-mail link, Google, Microsoft and GitHub, and personal MFA with passkeys or an authenticator app. Business adds an MFA requirement for the organization, session limits and the audit log page with its export.

Do client reviewers need accounts in our directory?

No. Company sign-in covers your verified domains only. Clients and other guests sign in as before and stay limited to the projects you invite them to.

Is there a step-by-step setup guide?

Yes, for Okta, Entra ID and Google Workspace. Enterprise customers get it with onboarding; write to support@sinfin.cz. Where your data lives and who processes it is on the trust page.

More guides

Jira, Linear, Slack and Teams: returned steps where the team worksAccepting a task with an AI agent, in the pull requestRegression before a release: compare the run with the accepted baseline

Install once, then work through your agent

Kaloko runs where your code and your agent are. The service stores and versions the results, shows the canvas and collects approvals.

  1. Add the CLI to the project
    npm install --save-dev kaloko

    Needs Node 20 or newer. Update later with npm update kaloko.

  2. Create the config and install the skill
    npx kaloko init --agent claude --org <your-org>

    The skill is copied to .claude/skills/kaloko. npx kaloko doctor checks Chrome, the config and the token.

  3. Create your organization and a token

    Create an organization; you become its admin. The start page offers a tester token in one click, later under Settings → API tokens. Put it into the project .env:

    KALOKO_TOKEN=qwk_…
    TYPESAFE_API_KEY=…   # optional: semantic evaluator

Then just ask your agent

The skill teaches your agent the whole loop: it writes the acceptance plan and the scenario from the task, walks the screens, evaluates, shares the canvas, reads what reviewers said and fixes it. You don’t type the commands; you look at the canvas.

What the agent runs (or run it yourself, e.g. in CI)

The same loop by hand:

npx kaloko start --scenario docs/tasks/TASK-123/qa/scenario.yml --env local
npx kaloko walk        # playwright steps; agent/manual steps: kaloko capture
npx kaloko evaluate
npx kaloko share --pr
npx kaloko feedback    # what reviewers said, with ids to answer