Single Sign-On (SAML) & RBAC
Configure enterprise identity providers (Okta, Microsoft Entra ID, Google Workspace) and manage role-based access control.
ScanDrix supports enterprise-grade Single Sign-On (SSO) via SAML 2.0, automated user provisioning with SCIM, and granular Role-Based Access Control (RBAC) to ensure least-privilege administrative governance.
Supported identity providers
- Okta
- Microsoft Entra ID (Azure AD)
- Google Workspace (Cloud Identity)
- PingIdentity & OneLogin
- Custom SAML 2.0 / OIDC Identity Providers
Configuring SAML 2.0 SSO
Retrieve ScanDrix Service Provider Metadata
In the ScanDrix dashboard, navigate to Settings → Authentication & SSO:
- Single Sign-On URL (ACS):
https://api.scandrix.dev/auth/saml/callback - Entity ID / Audience URI:
https://api.scandrix.dev/auth/saml/metadata - Name ID Format:
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
Register ScanDrix in your IdP
In your IdP admin console (e.g. Okta or Entra ID), create a new SAML 2.0 application and paste the ACS URL and Entity ID.
Map Attributes
Ensure the following SAML assertion attributes are returned:
email(User email address)firstName(Given name)lastName(Surname)groups(Optional: map IdP groups directly to ScanDrix workspace roles)
Upload IdP Metadata
Download the Identity Provider metadata XML from your IdP and upload it into ScanDrix under Settings → SSO → IdP Configuration.
Role-Based Access Control (RBAC)
ScanDrix enforces three standardized permission tiers across workspaces:
| Capability | Workspace Owner | Team Admin | Engineer / Member |
|---|---|---|---|
| Manage Billing & Seats | ✅ | ❌ | ❌ |
| Manage SAML SSO & SCIM | ✅ | ❌ | ❌ |
| Add / Remove Connected Repos | ✅ | ✅ | ❌ |
| Create & Edit Drixy Rules | ✅ | ✅ | ❌ |
| Trigger Dry Run Simulations | ✅ | ✅ | ✅ |
| View Reviews & Audit Logs | ✅ | ✅ | ✅ |
| Generate Personal CLI API Keys | ✅ | ✅ | ✅ |
Custom granular roles and per-repository permission overrides are available on the Enterprise tier.