Configure Enterprise SSO and SCIM
Prepare a verified company domain, single sign-on connection, and SCIM directory provisioning for a controlled Enterprise rollout.
Prepare a verified company domain, single sign-on connection, and SCIM directory provisioning for a controlled Enterprise rollout.
Enterprise SSO and SCIM are in a controlled rollout. Your JobsiteOn implementation contact must confirm that your identity provider and production connection have completed acceptance testing before you enforce SSO for your company. A saved connection alone is not provider certification.
JobsiteOn supports tenant-specific OIDC or SAML single sign-on and SCIM 2.0 Users and Groups provisioning.
Only a company Owner can manage enterprise identity. Your implementation contact provides a DNS TXT name and one-time value. Publish that exact record, then ask the Owner to verify it. SSO cannot be enabled until JobsiteOn finds the record.
Domain verification restricts JIT sign-in and SCIM provisioning to addresses on the approved company domain. Removing or changing an IdP claim does not let it cross into another company or Sandbox environment.
Keep enforcement off while you test:
The active Owner login is the emergency break-glass path. When enforcement is on, other users on the verified domain must use SSO.
A SCIM bearer token is displayed once. Copy it directly into your identity provider's secure credential store. JobsiteOn keeps only a digest and cannot show the token again.
If the token is exposed, revoke it, create a replacement, and update the IdP. Deactivating a SCIM user suspends that company membership and revokes active JobsiteOn sessions. It does not delete attribution or evidence created by that person.
support@jobsiteon.com with the company name, identity provider,
timestamp, and visible error. Never send a client secret, SAML private key, or
SCIM bearer token.Did this answer your question?