All for new users to be created in Gainsight PX via Okta / SAML, and allow privileges to be set through Okta at the time a user is created.
Just in time provisioning would be a great enhancement for the SSO connector. For example, we use this feature with Zendesk and accounts are provisioned when the users login for the first time. It saves administrators from having to create the accounts each time, as well as deactivating them. OneLogin is our SSO provider.
All the votes have been transferred into this idea.
Thanks for pointing the duplicate Idea
If the role is not added from Okta, perhaps the default role can be Viewer.
Also, there’s another similar idea gaining votes that you may want to merge here:
thks
Some requirements as we would define them:
- SCIM configuration separate between sandbox and production Gainsight CS/PX environments. We would want any SCIM/permissions testing isolated to sandbox environments using sandbox identities. no mixing sandbox & production.
- SCIM syncing users (particularly from a certain group) into CS/PX -- we wouldn’t want to bulk sync everyone in our company into Gainsight.
- SCIM syncing groups (either our IAM system creating the group, or prestaging the group in Gainsight tools and then just syncing membership)
- Roles/permissions/entitlements assigned to the groups within Gainsight, not directly to the users. Membership in the group grants the appropriate roles/permissions/entitlements.
- Rest API to allow User/Group management:
- This allows our IAM system to audit permissions in the Gainsight tools match what is assigned via IAM.
- Allows us to discover if a Gainsight admin has changed permissions/entitlements for a user outside of the IAM system.
From a “Process” perspective, we map users to “roles” (such as a CSM versus a Product Manager) so that new employees can inherit permissions similar to their coworkers. We also use the IAM system for an approval workflow if an employee requests an app permission or role that is not added by their base job role (like if a PM needed access to CS in order to see account history).
Is there any sort of ETA when SCIM/JIT will be supported in Gainsight CS or any other of your products like PX? It seems odd that its not supported yet. I would pretty much like to do what rterakedis-9222 stated in a previous reply 9 months ago.
My company's requirements are the following for SCIM/JIT:
- SCIM configuration separate between sandbox and production Gainsight CS/PX environments. We would want any SCIM/permissions testing isolated to sandbox environments using sandbox identities. no mixing sandbox & production.
- SCIM syncing Users and Groups (We would want to use Groups in order to control who syncs) into CS/PX. We don't want to bulk sync everyone in our company into Gainsight.
- SCIM syncing groups (either our IAM (Sailpoint IDN or Entra ID system creating the group, or prestaging the group in Gainsight tools and then just syncing membership)
- Roles/permissions/entitlements assigned to the groups within Gainsight, not directly to the users. Membership in the group grants the appropriate roles/permissions/entitlements.
- Rest API using Sailpoint IDN to allow User/Group management:
- This allows our IAM system to audit permissions in the Gainsight tools match what is assigned via IAM.
- Allows us to discover if a Gainsight admin has changed permissions/entitlements for a user outside of the IAM system.
From a “Process” perspective, we would like to map users to “roles” (such as a CSM versus a Product Manager) so that new employees can inherit permissions similar to their coworkers. We also want to use our IAM system for an approval workflow if an employee requests an app permission or role that is not added by their base job role (like if a PM needed access to CS in order to see account history).
Thanks
Thanks for reaching out
Sign up
If you ever had a profile with us, there's no need to create another one.
Don't worry if your email address has since changed, or you can't remember your login, just let us know at community@gainsight.com and we'll help you get started from where you left.
Else, please continue with the registration below.
Welcome to the Gainsight Community
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.