Skip to content

SSO and SCIM

Two capabilities reserved for the Enterprise edition.

Single sign-on (SAML) lets you attach your Restorm organisation to your SAML identity provider.

Your teams then sign in with their corporate credentials, going through your own rules — second factor, device compliance, IP restriction. Restorm no longer manages a password on your behalf.

Signing in itself goes through your system browser (see Accounts and signing in), and therefore through a browser session in which your identity provider applies its rules as normal.

Directory provisioning (SCIM) synchronises your members from your directory.

Someone joining the right group automatically gets their seat; someone leaving loses it. That is what avoids the usual drift between the HR directory and the licence list.

Audit logs complete the set by retaining the organisation’s events — seat assignments, role changes, token issuance.

These capabilities are configured from the organisation dashboard. They assume an Enterprise plan: get in touch from restorm.app/pricing to discuss it.

The advanced MCP tools are included in Pro and Enterprise. Every agent call is recorded in the MCP logs panel, and any change to the firewall made by an agent is audited.