Skip to content

Set up the organization

This guided step provisions the tenant, configures IdP federation, and confirms product entitlement without a human handoff. See Docs authority & product state.

Steps

Role: Admin with tenant, identity, and subscription settings access.

  1. Open the guided setup and create the tenant.
  2. Claim the organization domain and configure SAML 2.0 or OIDC IdP federation.
  3. Run the test assertion, then map the Admin and Engineer groups.
  4. Confirm the tenant’s product entitlement and enabled setup path.

IdP federation controls how people sign in. It is separate from the identity-resolution connector used later for attribution.

Success evidence

Tenant provisioning, IdP federation, test assertion, role mapping, and entitlement each show Ready in the setup record.

Recovery

Correct the specific domain, issuer, audience, claim, group mapping, or entitlement check shown by validation, then rerun that check. Authentication fails closed until the test assertion passes.