Skip to main content
All CollectionsBusiness HubsManaging users via an IdP and business hub
Provision users to your apps via an IdP and business hub

Provision users to your apps via an IdP and business hub

This article describes how to provision users to your external seat-based and paid social apps via an IdP and business hub.

Cerby Team avatar
Written by Cerby Team
Updated over 2 weeks ago

Who can use this feature?

  • IT admins with a tenant in an identity provider

  • Business hub Owners

  • Only supported using the Cerby web app

As an IT admin collaborating with a business hub Owner, you can provision users to your external seat-based and paid social apps via your identity provider (IdP), such as Okta or Entra ID, and a business hub.

For this identity lifecycle management functionality to work, Cerby leverages user and group provisioning from the IdP to create and update Cerby teams. These teams must have shared access to a business hub integration with specific roles or permissions both in Cerby and the external app, including assets if supported, as shown in Figure 1.

Diagram of a Cerby business integration leveraging identity provider groups. The diagram shows the multiple systems involved, such as the identity provider, Cerby, and the external app, and the components, such as users, groups, teams, the business hub integration, and the add user management task

Figure 1. User provisioning in external apps from IdP group assignments

With this approach, any user assigned to an IdP group is automatically pushed to the corresponding Cerby team. Given that the team already has access to the business hub, Cerby detects the new users and takes action as follows:

  • Cerby grants the users the same role as the team on the business hub integration: Owner or Collaborator.

  • Cerby triggers automated tasks to add these users to the external app with the app role assigned to the team. Invites to join the app are sent to all new users.

  • Cerby identifies existing users in the external app (whether they previously had access individually or through another team) and determines their role. Based on all the access grants they have, users get the highest role, so if needed, Cerby triggers an automated task to update their role in the external app.

IMPORTANT: You must plan ahead for the roles you want to assign to the teams with shared access to the business hub integration. Remember that the team's roles will be assigned to all team members both in Cerby and in the external app, including assets if supported.


Requirements

The following are the requirements to provision user to your external apps via your IdP and business hub:


Provision users to your apps via your IdP and business hub

To provision users to your external apps via your IdP and business hub, you must complete the following steps:

  1. Log in to the IdP admin console or center of your organization.

  2. Add users or members to the groups assigned to the Cerby app integration. For instructions, read the official documentation of your IdP:

    Given that IdP users and groups are automatically pushed to your Cerby workspace, the new team members also receive shared access to the business hub integration automatically. Therefore, Cerby triggers the automated task to add the users to the external app, including assets if supported.

    TIP: You can view the progress of the automated tasks in the Automation page.

Now you are done.

Did this answer your question?