Single Sign-On (SAML) & RBAC

Configure enterprise identity providers (Okta, Microsoft Entra ID, Google Workspace) and manage role-based access control.

ScanDrix supports enterprise-grade Single Sign-On (SSO) via SAML 2.0, automated user provisioning with SCIM, and granular Role-Based Access Control (RBAC) to ensure least-privilege administrative governance.

Supported identity providers

  • Okta
  • Microsoft Entra ID (Azure AD)
  • Google Workspace (Cloud Identity)
  • PingIdentity & OneLogin
  • Custom SAML 2.0 / OIDC Identity Providers

Configuring SAML 2.0 SSO

1

Retrieve ScanDrix Service Provider Metadata

In the ScanDrix dashboard, navigate to Settings → Authentication & SSO:

  • Single Sign-On URL (ACS): https://api.scandrix.dev/auth/saml/callback
  • Entity ID / Audience URI: https://api.scandrix.dev/auth/saml/metadata
  • Name ID Format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2

Register ScanDrix in your IdP

In your IdP admin console (e.g. Okta or Entra ID), create a new SAML 2.0 application and paste the ACS URL and Entity ID.

3

Map Attributes

Ensure the following SAML assertion attributes are returned:

  • email (User email address)
  • firstName (Given name)
  • lastName (Surname)
  • groups (Optional: map IdP groups directly to ScanDrix workspace roles)
4

Upload IdP Metadata

Download the Identity Provider metadata XML from your IdP and upload it into ScanDrix under Settings → SSO → IdP Configuration.


Role-Based Access Control (RBAC)

ScanDrix enforces three standardized permission tiers across workspaces:

CapabilityWorkspace OwnerTeam AdminEngineer / Member
Manage Billing & Seats✅❌❌
Manage SAML SSO & SCIM✅❌❌
Add / Remove Connected Repos✅✅❌
Create & Edit Drixy Rules✅✅❌
Trigger Dry Run Simulations✅✅✅
View Reviews & Audit Logs✅✅✅
Generate Personal CLI API Keys✅✅✅

Custom granular roles and per-repository permission overrides are available on the Enterprise tier.