Skip to main content

Single Sign-On (SSO)

Single Sign-On (SSO) lets your team sign in to the Gallium Console with your existing identity provider instead of a separate Gallium password. Your people use the credentials they already have, and you manage access centrally from your directory.

Gallium's SSO is built on WorkOS and supports Microsoft Entra ID (Azure AD). It uses SAML for sign-in and SCIM for automatic user provisioning, so members are kept in step with your directory without manual invitations.

How SSO Works at Gallium

When SSO is enabled, your organization becomes identity-provider managed. Rather than inviting members one by one, you control who has access from your directory, and the Gallium Console reflects that.

There are two parts to how this works day to day:

  • Provisioning: members are provisioned automatically from your directory over SCIM. As you add or remove people in your identity provider, they appear or disappear in the Console. Provisioned members are listed under SSO Users instead of being invited individually.
  • Sign-in: people sign in by entering their email address. The Console uses the email domain to route them to your identity provider, where they authenticate over SAML.

Because membership flows from your directory, the way you manage users changes once SSO is in place. See What You Can Manage in the Console below for the details.

Setting Up SSO

SSO is not self-service: it must be activated for your organization by the Gallium support team. Once they have turned it on and established the connection to your identity provider, you manage it day to day from the Console.

To get SSO enabled:

  1. Contact Gallium support to request SSO for your organization.
  2. Provide your identity provider connection details (for example, an Entra ID SAML connection) and the email domain(s) your organization uses so members can be routed to your identity provider when they sign in.
  3. Gallium activates SSO and completes the connection, after which your organization becomes identity-provider managed.
info

SSO is set up in partnership with Gallium. To enable it for your organization, contact Gallium support. See Getting Help.

Availability

SSO is included for Enterprise Flex customers. On all other license programs it requires an SSO entitlement, which is available as an add-on. Ask Gallium support or your partner to add it to your organization.

What You Can Manage in the Console

Once SSO is active, you administer it from Settings > Single Sign-On in the Console. Day-to-day management comes down to three things:

  • View Domains: review the email domain(s) tied to your organization, each shown with its verification status. Selecting a domain shows its verification details.
  • View Users: the SSO Users page lists the members provisioned from your directory, so you can confirm who currently has access. Adding and removing members happens in your identity provider, not here.
  • Update Configuration: change your SSO connection or domains. This opens WorkOS, where the underlying SAML connection and SCIM directory are managed.

Your SAML connection and SCIM directory are each shown with their current status, so you can confirm at a glance that sign-in and user provisioning are healthy.

Signing In with SSO

Signing in with SSO starts the same way as any other sign-in: with your email address. The Console takes it from there and sends you to your identity provider.

  1. Go to the Gallium Console sign-in page.
  2. Enter your email address.
  3. If your domain is set up for SSO, you're redirected to your identity provider to authenticate.
  4. Once you've authenticated, you're returned to the Console and signed in.
note

For SSO organizations, the standard Users page is replaced by a read-only SSO Users list. Adding, removing, and assigning roles to members is done in your identity provider, not in the Console.