Documentation / Account and billing

Enterprise SSO

Connecting Okta, Entra ID, Google Workspace or any SAML 2.0 provider, and how sign-in changes.

Agency plan and above

SAML single sign-on lets your team sign in with company credentials instead of separate Rivarise passwords. It is available on the Agency plan.

Supported providers

Any SAML 2.0 identity provider works. Commonly connected:

  • Okta
  • Microsoft Entra ID, formerly Azure AD
  • Google Workspace
  • Any other SAML 2.0 compliant IdP

Setting it up

Setup is white-glove rather than self-serve, because a misconfigured SAML connection locks people out of their own workspace.

  1. Email support@rivarise.com from an address on the domain you want to connect.
  2. Include your IdP SAML metadata URL. Every provider exposes one; in Okta and Entra ID it is on the application configuration screen.
  3. Include the email domain or domains that should authenticate through this connection, for example yourcompany.com.
  4. We configure and confirm. Connections are normally live within one business day.

How your team signs in afterwards

Once connected, your team signs in at app.rivarise.com/login/sso and enters your company email domain. They are redirected to your identity provider, authenticate there, and return signed in. No Rivarise password is involved.

Bookmark the SSO URL and share it internally. The standard login page expects an email and password, which SSO users will not have.

Roles and provisioning

Users arriving through SSO are placed in your workspace and assigned a role in Rivarise. Role assignment is managed on the Team Members screen rather than mapped from IdP groups, so review roles after the first few people sign in.

Removing someone in your identity provider prevents them from authenticating. Remove them from the Team screen as well to free the seat and revoke workspace access completely.

Practical notes

  • Keep one Owner with a password. If your IdP has an outage, a password-based Owner can still reach billing. This is standard practice for any SSO deployment.
  • Seats still apply. SSO does not bypass seat counting, though the Agency plan has no seat cap.
  • Send the metadata URL, not a downloaded XML file, so the connection picks up certificate rotations automatically.