SSO, SAML and MFA for organisations

Your people should sign in with the identity system you already run — and you should control what each of them can see once they're in. Learnivo supports single sign-on, automated user provisioning and multi-factor authentication policy, layered on role-based access control.

What these mean in plain English

How it works

  1. Connect your identity provider — OIDC for Google-workspace-style providers, SAML for enterprise IdPs.
  2. Provision users via SCIM, CSV bulk import, or invitation links.
  3. Assign roles — learner, instructor, manager, admin and custom roles — under role-based access control with organisation-level data isolation.
  4. Enforce MFA policy and monitor sign-ins and administrative actions in audit logs.

Plan availability

Honest limits

Google OIDC is configured and running today; SAML and SCIM are for Max and Enterprise plans. MFA policy is enforced by the platform — for enforced MFA at your identity provider itself, configure it there.

Questions people ask

Which identity providers are supported?

Any OIDC provider (Google is configured today) and, on Max and Enterprise, any SAML 2.0 identity provider.

Can we automatically remove access when someone leaves?

Yes — SCIM provisioning (Max and above) syncs leavers from your directory; access ends with their directory account.

Can different teams see different data?

Yes — role-based access control plus organisation-level data isolation keeps each team's and tenant's data separate.

Is there a record of administrative actions?

Yes — audit logs record sign-ins and admin actions, on every plan.

Next step. Loop in your IT reviewer — scope it with us.