Skip to content
Published

Last reviewed: 2026-07-28

Access and single sign-on

Understand access and single sign-on availability: none on Free and Starter, basic SSO on Team, and full SSO on Regulated.

Plan access and SSO levels

Free and Starter do not include single sign-on. Team includes basic SSO. Regulated includes full SSO under its agreement. Check your organization’s current entitlement before planning an identity rollout.

In the app, open Settings → SSO. The page is split into two tabs:

  • Social — join rules for Google, Microsoft, and GitHub on the public login page (domains / GitHub orgs).
  • Enterprise — custom OAuth/OIDC/SAML IdP keys (Regulated). Deep-link: /settings/sso?tab=enterprise.

Roles (short)

Hierarchy: viewer < member < triage < admin ≈ owner.

  • Member: read + scan/sync. No governance writes.
  • Triage: member capabilities plus finding ignore (occurrence, entire rule, or entire CVE), license override / honor, and scoped license allowances at project unit or repository (reason required). Minting tokens with finding:* or policy:read/policy:write requires triage+.
  • Admin / owner: full organization settings, IAM, policies, package@organization allowances, whitelist append, and policy:admin token scopes. Only owners may assign the owner role.

Assign the smallest product role that lets each person do their work.

Roll out safely

Test SSO with an administrator account before enforcing it for everyone, preserve a controlled recovery path, and review access when staff, contractors, or client engagements change.

Boundaries

SSO authenticates people; it does not grant access to another organization or replace repository authorization. A successful sign-in with no visible repository usually indicates organization membership or repository access, not an SSO failure.

Accounts that use email and password can reset their password from the sign-in page. See Reset your password.

Related documentation