🔒 Permissions: Only Admins can set up SSO and Directory Sync, from Workspace Admin → Security & Access. Learn more about roles →
Single Sign-On (SSO) lets your team sign in to Minikai with the work credentials they already use. Directory Sync keeps your user list in step with your identity provider, so access is granted and removed automatically as people join and leave. This guide sets up Directory Sync first, then Single Sign-On, then maps groups to access roles.
When to use this
You're rolling Minikai out to a large team and don't want to invite and manage everyone by hand.
Your organisation already uses an identity provider like Microsoft Entra ID, Okta, or Google Workspace, and you want staff to sign in with their existing login.
You want joiners and leavers handled automatically, so access follows your directory and offboarding is reliable.
Your IT team manages access centrally and wants to control who can do what from the directory rather than inside Minikai.
How it works
There are two pieces, and most organisations use both:
SSO controls how people sign in. They authenticate with your identity provider instead of a Minikai password.
Directory Sync (SCIM) controls who exists in your workspace and which groups they belong to. Your directory becomes the source of truth for user accounts and roles.
You set both up from one place: Workspace Admin → Security & Access, using the same identity provider connection for each.
Step 1: Open Security & Access
Click your workspace name at the top-left of the sidebar, select Workspace Admin, then choose Security & Access under Access Management in the left sidebar. This is where SSO, Directory Sync, domain verification, and audit log streaming all live.
Step 2: Set up Directory Sync
On the Directory Sync card, select Set up directory, choose your provider, and follow the guided steps to connect. Once connected, the users and groups you assign to Minikai in your provider are created in your workspace automatically, and removing someone in your directory removes their access here. Job titles sync automatically too.
By default, new workspaces require access to come through Directory Sync: someone who successfully signs in via SSO but hasn't been provisioned through Directory Sync won't automatically be given access. If you'd rather first-time sign-in alone provisioned access for your workspace, message us through the Help Desk and we can look at enabling that for you.
Step 3: Create groups and map them to roles
Once your directory is connected, the setup shows your synced groups with a role dropdown beside each. In your identity provider, create at least two groups for Minikai, for example "Minikai Admins" and "Minikai Members", assign people to the group that matches the access they need, then map each group to the matching role.
If you put everyone in a single group, everyone receives the same role, most often a workspace full of Admins, or a workspace where nobody has the access they need.
💡 Tip: If a synced user isn't in any mapped group, they're given the default Member role, which has no access to records or Minis until permissions are assigned. A user in several mapped groups receives all of those roles. Plan your groups before you switch Directory Sync on.
Beyond Admin and Member, you can map groups to specific workspace-wide access roles, for example Record All Viewer (view all records) or Mini All Editor (edit all Minis), so the right access is granted automatically as people are provisioned. See App roles and permissions for what each role grants. Create one group per access role you want to use, and map it under Role assignment in the Directory Sync configuration.
Step 4: Add Single Sign-On to the same connection
On the Single Sign-On card, select Set up SSO, choose the same identity provider you connected in Step 2, and select the SAML option for that provider, for example Entra ID (Azure AD) SAML. The setup flow gives you the details your provider needs and lets you test the connection before you turn it on. Test with one account before rolling out to your whole team.
Will my team be notified automatically?
No. Neither Directory Sync nor Single Sign-On sends an email or notification, to you or to the people you add. When someone is assigned to a mapped group in your directory, Minikai provisions their account quietly in the background, usually within a few minutes, with nothing sent to announce it.
Once Directory Sync and SSO are live, let people know they can sign in at minikai.com/app with the same work login they already use day to day. See Rolling out Minikai to your team for a message you can adapt.
The order matters too: add someone to the mapped group in your directory first, wait a few minutes for their account to be provisioned, then let them know. If they try to sign in before they're provisioned, they'll be turned away rather than let in automatically. Minikai only creates an account through Directory Sync, never from sign-in alone. See How Single Sign-On decides who can sign in for exactly how sign-in access is gated on the identity-provider side.
ℹ️ Good to know: When an access role is granted through a directory group, that role is managed in your identity provider. To change it, update the person's group membership in your directory rather than in Minikai, so the change isn't overwritten on the next sync. Per-record and per-Mini label access is still managed inside Minikai, see Fine-Grained Access Controls.
ℹ️ Already using OpenID Connect for SSO with Entra ID? You won't be able to add Directory Sync to that same Entra Enterprise Application. OpenID Connect creates a separate App Registration with no Provisioning tab, so it can't host SCIM. Switch the SSO connection to SAML if you want SSO and Directory Sync together under one Enterprise Application.
⚠️ Let your directory be the source of truth: Once Directory Sync is on, provision and remove people through your directory, not by manual invite. A manually invited user won't be covered by your directory's offboarding, which can leave access in place after someone has left.
Tips for a smooth setup
Test with one account first. Confirm sign-in and the assigned role work before rolling out to everyone.
Decide your groups up front. Map out which directory groups map to which roles before you switch sync on.
Keep group names clear. Names like "Minikai Admins" and "Minikai Members" make it obvious who gets what.
Need help?
Setting up SSO and Directory Sync is something we're glad to do alongside you. One of our team can walk your IT admins through it for your specific provider. Message us through the Help Desk in the app or email [email protected], and we'll help you get it right.







