Administration

Identity & provisioning

Federated authentication and governed workforce lifecycle synchronization.

3?

Single sign-on

Configure governed SAML 2.0 and OpenID Connect providers with verified domains and just-in-time provisioning.

Directory connections

Connect Microsoft Entra ID, Okta, Google Workspace, or a generic SCIM directory.

Attribute mappings

Map external identity attributes and groups to AchieveX users, roles, departments, and teams.

Provisioning monitor

Review synchronization runs, create/update/suspend actions, failures, and correlation identifiers.

Security boundaries

Secrets are write-only, tenant scoped, fingerprinted, and must be backed by KMS in production. Preview runs are side-effect free. Deprovisioning is disabled by default.