Single sign-on and provisioning
CCTVplanner is a SAML 2.0 service provider on the Enterprise plan. Your people sign in through your own identity provider, and your directory can create and deactivate their accounts. Pick your provider.
The values every provider asks for
Your organization console at cctvplanner.io/organization shows these with copy buttons, and it is the authority. They look like this.
https://auth.cctvplanner.io/auth/v1/sso/saml/metadatahttps://auth.cctvplanner.io/auth/v1/sso/saml/acshttps://auth.cctvplanner.io/auth/v1/sso/saml/metadata?download=trueurn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress- Okta Add the SAML application, map the attributes, paste the metadata URL back.
- Microsoft Entra ID A non-gallery enterprise application, its claims, and the session cap that applies to Entra.
- Google Workspace A custom SAML app, and the certificate rotation that needs a second upload.
- AD FS A relying party trust from our metadata, with the claim rules and the PowerShell.
- Any SAML 2.0 provider What the assertion has to carry, for a provider nobody has written a guide for.
- Directory provisioning (SCIM) Let the directory create, update and deactivate accounts.
- Security review What sign-on enforces, how fast access ends, and the assurance we do not hold.
Setting this up and something is not covered here? Write to [email protected] with the error text the screen showed you. Every refusal we print carries a code, and the code tells us exactly where it came from.
Screens and field names belong to the identity provider and change without telling us. Where this page and their own documentation disagree, theirs is right, and we would like to hear about it.