Corporate SSO + SCIMNEW
Turn on single sign-on via SAML or OIDC with your identity provider, whether Okta, Azure AD/Entra or Google Workspace, and let user provisioning run automatically with SCIM. Whoever joins the company gets access; whoever leaves loses it instantly, with no manual IT work.
- SSO via SAML or OIDC with Okta, Azure AD/Entra and Google Workspace
- Automatic user provisioning and deprovisioning via SCIM
- Access governed by your corporate directory, with one less password to manage
Free in Sellio, you only pay for the machine
SSO and SCIM are included in Sellio, not an enterprise add-on. You only pay for the machine.
Enterprise-grade security
Access inherits your identity provider’s MFA, password and session policies, raising the bar with no extra effort.
Offboarding with no gaps
When someone is removed in the directory, SCIM revokes CRM access instantly, closing the risk of active ex-employee accounts.
IT without repetitive work
Creating, updating and deactivating users stops being a manual task and follows the directory lifecycle instead.
No extra password
Users sign in with the same corporate login, with no additional credential to remember or forget.
Connect your own identity provider: certificates and secrets are kept in an encrypted vault and never shown on screen
Open standards (SAML, OIDC, SCIM): no lock-in to a single identity vendor
SSO and SCIM are usually locked behind competitors’ priciest enterprise tier; here they’re included, you only pay for the machine
Security that doesn’t rely on discipline
Reused passwords and orphaned accounts are the biggest door to incidents. With SSO, access to the CRM goes through the same corporate login, under your provider’s MFA and password policies; with SCIM, whoever leaves the company loses access the moment they’re offboarded in the directory, so no one has to remember to remove them.
Less friction for everyone
IT stops creating and deleting accounts by hand; users sign in with the login they already use daily. Onboarding a new hire becomes part of the directory flow, and auditing gets simpler because identity has a single source of truth.
- 1
Connect your identity provider by exchanging SAML or OIDC metadata, and certificates and secrets stay in a vault and are never shown again
- 2
Enable SCIM to sync directory users and groups with CRM profiles
- 3
Map groups to roles and define the access rules
- 4
Users start signing in via SSO and provisioning runs automatically as they change in the directory
Automatic onboarding
A new rep joins the right directory group and SCIM already creates CRM access with the proper role, on day one.
Fail-safe offboarding
On departure, CRM access disappears along with the other accounts, without relying on a manual IT ticket.
Compliance and auditing
With centralized identity, the company proves who has access to what, meeting security requirements and audits with ease.
Do I need to pay for a pricier plan to get SSO?
No, SSO and SCIM are usually locked behind competitors' priciest enterprise tier; here they're already included, you only pay for the machine.
Does it work with my identity provider?
It works with Okta, Azure AD/Entra and Google Workspace through the open SAML and OIDC standards.
What happens when I remove someone from the company directory?
SCIM revokes CRM access instantly, closing the risk of active ex-employee accounts.
Are my credentials and certificates exposed anywhere?
No, certificates and secrets are kept in an encrypted vault and never shown on screen.
Does SCIM create users automatically or do I still need to add them manually?
It automatically provisions and deprovisions users based on your corporate directory.
Is there a risk of being locked into a single identity vendor?
No, the integration uses open standards, SAML, OIDC and SCIM, with no lock-in to a single vendor.
Do my company's password and MFA policies still apply?
Yes, access inherits the MFA, password and session policies already configured in your identity provider.
Does this help with security audits?
Yes, with centralized identity the company easily proves who has access to what.
Does a new hire start with access already set up on day one?
Yes, once they join the right directory group, SCIM already creates CRM access with the proper role.