Skip to content
  • There are no suggestions because the search field is empty.

Configuring SSO

You're setting up single sign-on for your organization and you need to know what attributes Valid8 requires, or where in the product to configure the connection.

There is no customer-facing SSO configuration screen

If you need to set up or modify your organization's SSO configuration, contact Valid8 support. Include your organization name, the identity provider you're using (for example, Okta, Azure AD, or another SAML provider), and let them know you're configuring SSO. The configuration happens outside the Valid8 product, coordinated between your identity team and Valid8's support or implementation team.

 

What happens when a user logs in through SSO for the first time

When someone from your organization logs in through SSO and Valid8 recognizes the connection identifier, the system automatically provisions a new user record if one doesn't already exist. That new user is granted:

  • Customer User status at the organization level (not Customer Admin)
  • Zero engagement assignments

This means a newly provisioned SSO user lands on an empty engagement list with no visible way to proceed. They are fully authenticated, but they belong to no engagements yet. A Customer Admin or an Engagement Owner needs to explicitly add them to the engagements they should access.

Manual user creation is blocked after enabling SSO

Once your organization is configured for enterprise SSO, manual user creation inside Valid8 is disabled. If a Customer Admin tries to add a user directly through the Create Customer User dialog, they'll see a generic Error Creating the Customer User toast. The full message behind that error reads: Manual user creation disallowed. Users must be created through the IDP.

This is expected behavior, not a defect. Users must be provisioned through your identity provider (your IDP) — Valid8 will auto-provision them on first login as described above. You can still manage their engagement assignments and customer-level role inside Valid8 after they've logged in at least once, but the initial account creation must come through SSO.

Getting SSO setup wrong can lock users out

SSO and SAML configuration sit at the boundary between your identity provider, your organization's security policies, and Valid8's authentication layer. Getting the attribute mapping, connection identifier, or certificate wrong can prevent your users from logging in at all, often with error messages that don't clearly identify the problem.

Because of this, Valid8 reviews and approves all SSO configuration guidance before it's published. If you're working from unofficial documentation or instructions that aren't directly from Valid8 support, double-check them before putting the configuration into production. A misconfigured connection can lock out your entire organization until it's corrected.