🔒 Permissions: Only Admins can set up SSO and Directory Sync, from Workspace Admin → Security & Access. Learn more about roles →
Single Sign-On (SSO) lets your team sign in to Minikai with the work credentials they already use. Directory Sync keeps your user list in step with your identity provider, so access is granted and removed automatically as people join and leave. This guide sets up Directory Sync first, then Single Sign-On, then maps groups to access roles.
When to use this
You're rolling Minikai out to a large team and don't want to invite and manage everyone by hand.
Your organisation already uses an identity provider like Microsoft Entra ID, Okta, or Google Workspace, and you want staff to sign in with their existing login.
You want joiners and leavers handled automatically, so access follows your directory and offboarding is reliable.
Your IT team manages access centrally and wants to control who can do what from the directory rather than inside Minikai.
How it works
There are two pieces, and most organisations use both:
SSO controls how people sign in. They authenticate with your identity provider instead of a Minikai password.
Directory Sync (SCIM) controls who exists in your workspace and which groups they belong to. Your directory becomes the source of truth for user accounts.
You set both up from one place: Workspace Admin → Security & Access, using the same identity provider connection for each.
Step 1: Open Security & Access
Click your workspace name at the top-left of the sidebar, select Workspace Admin, then choose Security & Access under Access Management in the left sidebar. This is where SSO, Directory Sync, domain verification, and audit log streaming all live.
Step 2: Set up Directory Sync
On the Directory Sync card, select Set up directory, choose your provider, and follow the guided steps to connect. Once connected, the users and groups you assign to Minikai in your provider are created in your workspace automatically, and removing someone in your directory removes their access here. Job titles sync automatically too.
By default, new workspaces require access to come through Directory Sync or a manual invite: someone who successfully signs in via SSO but hasn't been added through either route won't automatically be given access. If you'd rather first-time sign-in alone provisioned access for your workspace, message us through the Help Desk and we can look at enabling that for you.
Step 3: Create groups and map them to roles
Once your directory is connected, the setup shows your synced groups with a role dropdown beside each. In your identity provider, create at least two groups for Minikai, for example "Minikai Admins" and "Minikai Members", assign people to the group that matches the access they need, then map each group to the matching role.
If you put everyone in a single group, everyone receives the same role, most often a workspace full of Admins, or a workspace where nobody has the access they need.
💡 Tip: If a synced user isn't in any mapped group, they're given the default Member role, which has no access to records or Minis until permissions are assigned. A user in several mapped groups receives all of those roles. Plan your groups before you switch Directory Sync on.
Beyond Admin and Member, you can map groups to specific workspace-wide access roles, for example Record All Viewer (view all records) or Mini All Editor (edit all Minis), so the right access is granted automatically as people are provisioned. See App roles and permissions for what each role grants. Create one group per access role you want to use, and map it under Role assignment in the Directory Sync configuration.
Step 4: Add Single Sign-On to the same connection
On the Single Sign-On card, select Set up SSO, choose the same identity provider you connected in Step 2, and select the SAML option for that provider, for example Entra ID (Azure AD) SAML. The setup flow gives you the details your provider needs and lets you test the connection before you turn it on. Test with one account before rolling out to your whole team.
Step 5 (Optional): Map job titles for SAML-only setups
Skip this step if you've set up Directory Sync (Step 2), job titles already sync automatically. It only applies if you're using SAML SSO on its own, without Directory Sync, since SAML doesn't send job titles by default.
To map job title for a SAML connection in Microsoft Entra ID:
In the Microsoft Entra admin centre, open your Minikai enterprise application and go to Single sign-on → Attributes & Claims → Add new claim.
Set Name to job_title, leave Namespace empty, set Source to Attribute, and choose user.jobtitle as the Source attribute.
Save, then have a user sign in again so the updated attribute comes through.
Other providers have an equivalent screen (often called attribute statements or attribute mappings); send the directory's job title field as job_title.
ℹ️ Good to know: When an access role is granted through a directory group, that role is managed in your identity provider. To change it, update the person's group membership in your directory rather than in Minikai, so the change isn't overwritten on the next sync. Per-record and per-Mini label access is still managed inside Minikai, see Fine-Grained Access Controls.
ℹ️ Already using OpenID Connect for SSO with Entra ID? You won't be able to add Directory Sync to that same Entra Enterprise Application. OpenID Connect creates a separate App Registration with no Provisioning tab, so it can't host SCIM. Switch the SSO connection to SAML if you want SSO and Directory Sync together under one Enterprise Application.
⚠️ Let your directory be the source of truth: Once Directory Sync is on, provision and remove people through your directory, not by manual invite. A manually invited user won't be covered by your directory's offboarding, which can leave access in place after someone has left.
Tips for a smooth setup
Test with one account first. Confirm sign-in and the assigned role work before rolling out to everyone.
Decide your groups up front. Map out which directory groups map to which roles before you switch sync on.
Keep group names clear. Names like "Minikai Admins" and "Minikai Members" make it obvious who gets what.
Need help?
Setting up SSO and Directory Sync is something we're glad to do alongside you. One of our team can walk your IT admins through it for your specific provider. Message us through the Help Desk in the app or email [email protected], and we'll help you get it right.








