SSO, SAML and MFA for organisations
Your people should sign in with the identity system you already run — and you should control what each of them can see once they're in. Learnivo supports single sign-on, automated user provisioning and multi-factor authentication policy, layered on role-based access control.
What these mean in plain English
- SSO / OIDC — staff sign in with your identity provider (e.g. Google Workspace) using the same credentials as their email; no separate password to manage or forget.
- SAML federation — the enterprise-standard SSO protocol for identity providers like Okta, Azure AD/Entra and Ping.
- SCIM provisioning — joiners, movers and leavers sync automatically from your HR or identity directory; leavers lose access the day they leave.
- MFA policy enforcement — require a second factor (app code, security key) for sign-in across your organisation.
How it works
- Connect your identity provider — OIDC for Google-workspace-style providers, SAML for enterprise IdPs.
- Provision users via SCIM, CSV bulk import, or invitation links.
- Assign roles — learner, instructor, manager, admin and custom roles — under role-based access control with organisation-level data isolation.
- Enforce MFA policy and monitor sign-ins and administrative actions in audit logs.
Plan availability
- Role-based access control (RBAC) and bulk CSV user import — every plan, including Free
- SSO / OIDC, custom user roles, group & team management — Pro plans and above
- MFA policy enforcement, SAML federation, SCIM provisioning, delegated branch administration — Max plans and above
- Audit logs — every plan
Honest limits
Google OIDC is configured and running today; SAML and SCIM are for Max and Enterprise plans. MFA policy is enforced by the platform — for enforced MFA at your identity provider itself, configure it there.
Questions people ask
Which identity providers are supported?
Any OIDC provider (Google is configured today) and, on Max and Enterprise, any SAML 2.0 identity provider.
Can we automatically remove access when someone leaves?
Yes — SCIM provisioning (Max and above) syncs leavers from your directory; access ends with their directory account.
Can different teams see different data?
Yes — role-based access control plus organisation-level data isolation keeps each team's and tenant's data separate.
Is there a record of administrative actions?
Yes — audit logs record sign-ins and admin actions, on every plan.