Single Sign-On (SSO)
Single Sign-On (SSO) lets your team sign in to the Gallium Console with your existing identity provider instead of a separate Gallium password. Your people use the credentials they already have, and you manage access centrally from your directory.
Gallium works with SAML identity providers, including Microsoft Entra ID (Azure AD). It uses SAML for sign-in and SCIM for user provisioning, so members are kept in step with your directory without manual invitations.
How SSO Works
When SSO is enabled, your organization becomes identity-provider managed. Rather than inviting members one by one, you control who has access from your directory, and the Console reflects that.
There are two parts to how this works day to day:
- Provisioning: members are provisioned automatically from your directory over SCIM. As you add or remove people in your identity provider, they appear or disappear in the Console.
- Sign-in: people sign in by entering their email address. The Console uses the email domain to route them to your identity provider, where they authenticate over SAML.
Getting SSO Enabled
SSO is not self-service. Gallium activates it for your organization, so the process starts with a support request.
Contact Gallium support with your identity provider connection details and the email domains your organization uses, so members can be routed to your identity provider when they sign in. Gallium completes the connection, after which your organization becomes identity-provider managed. See Getting Help.
SAML sign-in and SCIM provisioning are licensed separately, as two add-ons. Both are available on every license program.
The SSO Settings Page
Once SSO is active, a Single Sign-On item appears under Settings. It opens a page titled SSO Settings, showing your SAML connection, your SCIM directory, and the email domains tied to your organization.
The page is read-only. It reflects the last state synced from your identity provider, and how often changes are pushed is governed by your identity provider’s settings, so a recent change can take time to appear here.
Connection and Directory
Your SAML connection carries one of three states:
| Status | Meaning |
|---|---|
| Active | The connection is working and members can sign in. |
| Validating | The connection is being checked. |
| Inactive | The connection is not in use, so sign-in does not work. |
Your SCIM directory carries one of four:
| Status | Meaning |
|---|---|
| Linked | The directory is connected and provisioning members. |
| Unlinked | No directory is connected, so members are not provisioned. |
| Deleting | The directory is being removed. |
| Invalid Credentials | The directory has stopped syncing. Members are no longer provisioned, and your member list goes stale until you restore the credentials in your identity provider. |
Domains
Each email domain tied to your organization is listed with its status: Verified, Pending, or Failed. Domains are verified in your identity provider, and Gallium shows the result.
Reconfigure
Reconfigure opens your identity provider portal, where your connection, directory sync, domains, and certificates are managed. It takes you out of Gallium.
What Changes for Your Members
Once your organization is identity-provider managed, membership flows from your directory:
- Members appear in the standard All Users list, which shows only Name and Email. The Invite User and Remove User controls do not appear, because members are added and removed in your identity provider.
- On their own profile, members see User is externally managed in place of the password, multi-factor authentication, and pending invitation controls.
- A member belongs to one organization. They cannot accept invitations to other organizations or create new ones.