SSO & team access
Control who can access your workspace and what they can do. SAML single sign-on is available on every plan; SCIM provisioning and audit logs are included on Scale.
On this page
Roles and permissions#
Every teammate has one role per workspace. Roles can be changed at any time by an Owner or Admin under Settings → Team.
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View visitors, scores and reports | ✓ | ✓ | ✓ | ✓ |
| Claim and work leads | ✓ | ✓ | ✓ | — |
| Edit scoring and routing rules | ✓ | ✓ | — | — |
| Manage integrations and webhooks | ✓ | ✓ | — | — |
| Create and revoke API keys | ✓ | ✓ | — | — |
| Invite and remove teammates | ✓ | ✓ | — | — |
| Configure SSO and security settings | ✓ | ✓ | — | — |
| Manage billing, export or delete the workspace | ✓ | — | — | — |
Each workspace has at least one Owner. Viewer seats are free on every paid plan, so managers and executives can follow the pipeline without a paid seat.
Inviting teammates#
Owners and Admins can invite people from Settings → Team → Invite by email. Invitations expire after seven days. You can also allow anyone with a verified email on your company domain to join as a Member automatically — turn on Domain capture and verify the domain with a DNS TXT record.
Set up SAML SSO#
Aurora supports SAML 2.0 with any compliant identity provider (IdP). Pre-built setup guides are available for Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, OneLogin and JumpCloud.
- Start in AuroraGo to Settings → Security → Single sign-on and choose your identity provider. Copy the ACS URL and Entity ID shown on screen.
- Create the app in your IdPCreate a new SAML application, paste the ACS URL and Entity ID, and set the Name ID format to
EmailAddress. - Map attributesSend
email(required), plusfirstNameandlastName. Optionally sendrolewith a value ofadmin,memberorviewerto manage roles from your IdP. - Exchange metadataDownload the IdP metadata XML (or copy the metadata URL) and upload it in Aurora.
- Test, then enforceChoose Test sign-in in a private window. Once it works, turn on Require SSO to disable password and social login for everyone except Owners, who keep a recovery login.
| Setting | Value |
|---|---|
| ACS URL | https://app.aurora.io/sso/saml/acs (EU: https://app.eu.aurora.io/sso/saml/acs) |
| Entity ID | https://app.aurora.io/sso/saml/<workspace-id> |
| Name ID format | urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
| Signed assertions | Required. SHA-256 recommended. |
| IdP-initiated sign-in | Supported |
Keep at least one Owner with a working recovery login before you enforce SSO. If your IdP is misconfigured, that account is how you get back in.
SCIM provisioning#
With SCIM 2.0, your identity provider creates, updates and deactivates Aurora accounts automatically. Available on the Scale plan.
- Generate a tokenIn Settings → Security → Provisioning, choose Generate SCIM token. The token is shown once.
- Configure your IdPEnter the SCIM base URL
https://api.aurora.io/scim/v2and the token in your IdP's provisioning settings. - Assign users and groupsAssign the Aurora app to the people or groups who need access. Group names can map to roles and to routing groups.
When a user is deactivated in the IdP, their Aurora session ends within a minute, their API keys are revoked and their open leads move to the shared inbox, so nothing falls through the cracks.
Session and password policies#
Admins can set a session lifetime from 1 hour to 30 days, require two-factor authentication for password logins, and restrict dashboard access to specific IP ranges under Settings → Security. Two-factor authentication supports authenticator apps and hardware security keys (WebAuthn).
Audit logs#
On the Scale plan, Settings → Security → Audit log records every sign-in, role change, rule change, integration change, API key event and data export, with the actor, IP address and timestamp. Logs are retained for 13 months, can be filtered and exported as CSV, and can be streamed to your SIEM through the audit.event webhook.