Single Sign-On and Directory Sync
SubImage lets your team log in with your existing identity provider and, optionally, provision accounts automatically. Both are powered by WorkOS, so the actual setup happens in the WorkOS admin portal. The Single Sign-On settings page in SubImage shows the current status and gives admins a button to open that portal.
Single sign-on
Single sign-on (SSO) lets people sign in to SubImage with their corporate identity provider instead of a separate password. SubImage supports SAML and OIDC connections to Okta, Microsoft Entra ID (Azure AD), Google Workspace, and the other providers WorkOS supports.
To set it up:
- Go to Settings → Single Sign-On.
- On the Single Sign-On card, click Manage. This opens the WorkOS admin portal in a new tab.
- Choose your identity provider and follow the portal steps (upload metadata or certificates, map attributes, and so on).
- Return to SubImage. Once the connection is active, the card shows "enabled" along with the provider type.
A connection only counts as enabled once it reaches the active state in WorkOS. Connections still in draft or inactive are not yet live.
Directory sync
Directory sync (SCIM) keeps SubImage accounts in step with your identity provider's directory: users are provisioned when added and deprovisioned when removed, without manual invitations. It is configured separately from SSO.
Setup mirrors SSO: on the Directory Sync card, click Manage to open the WorkOS portal, connect your directory, and return to SubImage. The card shows "enabled" once a directory is active.
How roles are assigned
When someone signs in through SSO, their SubImage role comes from the role mapped in your identity provider. If no role is mapped, or the mapped value is not recognized, the user is assigned the Member role by default so access is never accidentally elevated.
To change a person's role after they have signed in, or to invite users manually, see Team management.
Note
Domain verification, just-in-time provisioning, and attribute or role mapping are all configured in the WorkOS admin portal, not in SubImage. The Manage links are generated for your organization each time you open the page and open in a new tab.