Security, SSO, and SCIM for an organization
The five controls on the organization's Security page: an identity provider, requiring single sign-on, provisioning on first sign-in, directory sync over SCIM, and emergency access.
The Security section of your organization dashboard is five things. Each one is a separate decision, and this page says what they are and where the detail lives.
Identity provider
Connect your identity provider and members sign in the way they sign in to everything else, rather than with a Dropstone password. Both SAML and OIDC are supported. See Single sign-on.
Require single sign-on
Once the provider is connected, this makes it the only way in for the organization. It is the difference between offering SSO and enforcing it, and it is worth being deliberate about: it applies to everyone, the owner included.
Create accounts on first sign-in
Instead of inviting each person, an account is created the first time someone signs in through the provider. This is how most organizations avoid a roster that drifts from the directory.
Directory sync over SCIM
SCIM 2.0 keeps the roster in step with your directory: joiners appear, and leavers are deactivated, without anyone remembering to do it. It works alongside SSO rather than instead of it. See SCIM provisioning.
Emergency access
A way back in if the identity provider is the thing that is broken. It is deliberately narrow and deliberately logged: every administrative action, including the ones taken through it, lands in the audit log.
What sits outside this page
What members can use is policy, not security: models, connectors, surfaces, tools, and network rules live in Policies. What is kept is the Data section. Both are worth reading together with this page, since a security review usually asks about all three.
Related articles
- Single sign-on (SSO)Connect your organization's identity provider so members sign in to Dropstone with their work credentials. SAML 2.0 and OpenID Connect are supported, with just-in-time provisioning of new members.
- SCIM provisioningAutomate joiners, leavers, and team membership in Dropstone from your identity provider using SCIM 2.0. Users and groups are supported. Deprovisioning is a soft delete.
- The organization audit logEvery administrative action in a Dropstone organization is recorded, with filters, ranges, and a CSV or JSON export. What is in it, who can read it, and why nobody can edit it.
- Roles and permissionsThe six roles in a Dropstone organization, what each one may do, why reading member conversations is deliberately not an administrator power, how administrators are appointed, and what the gold verified mark means.
- How an organization manages its dataThe three settings an owner controls for an organization, what each one stores, who can read it, and the limits of the strongest setting. Content logging, product telemetry, and retention, in one place.
- How Dropstone handles your dataWhat Dropstone stores, for how long, who can see it, whether it is used to improve the models, and the commitments that apply to every account. A plain-language summary of Dropstone's data practices.