SSO, SAML and MFA for organisations
Your people should sign in with the identity system you already run — and you should control what each of them can see once they're in. Learnivo supports single sign-on, automated user provisioning and multi-factor authentication policy, layered on role-based access control.
What these mean in plain English
- SSO / OIDC — staff sign in with your identity provider (e.g. Google Workspace) using the same credentials as their email; no separate password to manage or forget.
- SAML federation — the enterprise-standard SSO protocol for identity providers like Okta, Azure AD/Entra and Ping.
- SCIM provisioning — joiners, movers and leavers sync automatically from your HR or identity directory; leavers lose access the day they leave.
- MFA policy enforcement — a proposed way to require a second factor for app sign-in; universal app-level enforcement is not currently available. Use your identity provider's MFA settings in the meantime.
How it works
- Connect your identity provider — OIDC for Google-workspace-style providers, SAML for enterprise IdPs.
- Provision users via SCIM, CSV bulk import, or invitation links.
- Assign roles — learner, instructor, manager, admin and custom roles — under role-based access control with organisation-level data isolation.
- Set MFA at your identity provider, and review administrative actions in audit logs.
Plan availability
- Role-based access control (RBAC) and bulk CSV user import — every plan, including Free
- SSO / OIDC, custom user roles, group & team management — Pro plans and above
- MFA policy enforcement, SAML federation, SCIM provisioning, delegated branch administration — Max plans and above
- Audit logs — every plan
Honest limits
Google OIDC is configured today. Universal MFA enforcement for app sign-in is not available; configure MFA through your organisation's identity provider. SAML, SCIM and delegated access need confirmation for your organisation before rollout. See the current readiness notes for each feature below.
Questions people ask
Which identity providers are supported?
Any OIDC provider (Google is configured today) and, on Max and Enterprise, any SAML 2.0 identity provider.
Can we automatically remove access when someone leaves?
SCIM provisioning is intended to sync account changes from your directory. Confirm the connection and suspension flow for your identity provider before relying on it for leaver access.
Can different teams see different data?
Yes — role-based access control plus organisation-level data isolation keeps each team's and tenant's data separate.
Is there a record of administrative actions?
Yes — audit logs record sign-ins and admin actions, on every plan.
Feature-by-feature explanations
Choose a capability below for its meaning, practical benefits and current readiness. Planned features are not yet available; features marked To confirm need validation before relying on them.
- Custom user roles
- Role-based access control (RBAC)
- Bulk user import (CSV)
- SSO / OIDC
- MFA policy enforcement
- Delegated branch administration
- Agent audit logs
- API key management
- SCIM user provisioning
- SAML federation
Custom user roles
What it means: Assign the defined learner, instructor, assessor, manager, auditor and administrator roles. Arbitrary custom-role creation is not connected; King Ambassador supervision is a separate grant.
Why it matters: For administrators, this helps control access and bring new people on board without losing oversight. Instructors can focus on teaching rather than account administration. Learners can reach the right training with the right permissions. Partner organisations can coordinate access across teams while keeping responsibilities clear.
Current status: Planned — Not available as a working product feature yet. The app has defined membership roles, but creating arbitrary roles and permissions is not connected.
Role-based access control (RBAC)
What it means: Every screen and action is permission-gated by role, so people only see what they should.
Why it matters: For administrators, this helps control access and bring new people on board without losing oversight. Instructors can focus on teaching rather than account administration. Learners can reach the right training with the right permissions. Partner organisations can coordinate access across teams while keeping responsibilities clear.
Current status: Available — Available in the app; confirm fit and readiness for your organisation before purchase.
Bulk user import (CSV)
What it means: Upload a spreadsheet to create or update many user accounts at once.
Why it matters: For administrators, this helps control access and bring new people on board without losing oversight. Instructors can focus on teaching rather than account administration. Learners can reach the right training with the right permissions. Partner organisations can coordinate access across teams while keeping responsibilities clear.
Current status: Available — Available in the app; confirm fit and readiness for your organisation before purchase.
SSO / OIDC
What it means: Staff sign in with your existing identity provider (e.g. Google Workspace) instead of a separate password.
Why it matters: For administrators, this helps control access and bring new people on board without losing oversight. Instructors can focus on teaching rather than account administration. Learners can reach the right training with the right permissions. Partner organisations can coordinate access across teams while keeping responsibilities clear.
Current status: Available — Available in the app; confirm fit and readiness for your organisation before purchase.
MFA policy enforcement
What it means: Use your organisation’s identity provider for multi-factor authentication. Universal app-level enforcement is not available.
Why it matters: For administrators, this helps control access and bring new people on board without losing oversight. Instructors can focus on teaching rather than account administration. Learners can reach the right training with the right permissions. Partner organisations can coordinate access across teams while keeping responsibilities clear.
Current status: Planned — Not available as a working product feature yet. MFA through your organisation's identity provider is recommended; universal enforcement for app sign-in is not available.
Delegated branch administration
What it means: Give branch or regional managers admin rights over their own sub-organisation only.
Why it matters: For administrators, this helps control access and bring new people on board without losing oversight. Instructors can focus on teaching rather than account administration. Learners can reach the right training with the right permissions. Partner organisations can coordinate access across teams while keeping responsibilities clear.
Current status: To confirm — Listed in the catalogue; end-to-end availability has not been confirmed. Branch-level delegation controls exist; permissions and cross-organisation behaviour need validation.
Agent audit logs
What it means: A record of every action taken by the AI assistants.
Why it matters: For administrators, this helps keep accountable records and review risks. Instructors can work within clear access and evidence rules. Learners can know their information is handled with care. Partner organisations can review controls and evidence consistently.
Current status: Available — Available in the app; confirm fit and readiness for your organisation before purchase.
API key management
What it means: Create, scope and revoke API keys for programmatic access.
Why it matters: For administrators, this helps keep accountable records and review risks. Instructors can work within clear access and evidence rules. Learners can know their information is handled with care. Partner organisations can review controls and evidence consistently.
Current status: Available — Available in the app; confirm fit and readiness for your organisation before purchase.
SCIM user provisioning
What it means: Automatically create, update and suspend user accounts from your identity system.
Why it matters: For administrators, this helps reduce duplicate data entry across systems. Instructors can work with more consistent records. Learners can experience fewer handoffs between tools. Partner organisations can coordinate existing systems with learning.
Current status: To confirm — Listed in the catalogue; end-to-end availability has not been confirmed.
SAML federation
What it means: Enterprise single sign-on via SAML.
Why it matters: For administrators, this helps reduce duplicate data entry across systems. Instructors can work with more consistent records. Learners can experience fewer handoffs between tools. Partner organisations can coordinate existing systems with learning.
Current status: To confirm — Listed in the catalogue; end-to-end availability has not been confirmed.