Enable single sign-on (SSO) for your organisation
Set up enterprise single sign-on so your team signs in to PlanOps with your own identity provider (Microsoft Entra ID, Okta or Google Workspace), with new users joining your organisation automatically. Enterprise SSO is set up together with the PlanOps team.
This guide is designed for system admin.
Steps
Step 1: Confirm you are eligible and gather your identity provider details
You need to be an organisation administrator (or owner) in PlanOps and have administrative access to your identity provider. Enterprise SSO is a paid add-on, so check it is included on your plan. Make a note of your identity provider type (Microsoft Entra ID, Okta or Google Workspace) and the email domain or domains your organisation owns and wants managed by SSO (for example, your-company.com).
SSO is matched by email domain. Only domains your organisation genuinely owns can be connected, and each domain can belong to just one organisation.
Step 2: Request SSO from the PlanOps team
Contact PlanOps support or your account manager to start the process. Provide your organisation name, the email domain or domains to be managed by SSO, your identity provider type, and the name of the person who administers your identity provider. PlanOps creates the enterprise connection and guides the technical exchange.
This step exists because setting up the identity-provider connection and verifying domain ownership is handled by PlanOps for security. It is not currently self-serve.
Step 3: Complete the identity-provider connection
Work with the PlanOps team to exchange the connection details between your identity provider and PlanOps. For SAML this is the exchange of metadata (sign-in URL, certificate and entity ID); for OIDC it is the client and issuer details. PlanOps then verifies that your organisation controls the email domain before the connection goes live.
Step 4: Choose the default role for new members
Decide what access people should get the first time they sign in via SSO. By default, users provisioned through SSO join your organisation as Standard members, and an administrator can promote them later. Confirm this default with PlanOps, or ask for a different default if your policy requires it.
Step 5: Map identity-provider groups to roles (optional)
If you use groups in your identity provider (for example, a "PlanOps Admins" group), you can ask PlanOps to map those groups to PlanOps roles so members receive the right access automatically. Groups that are not mapped fall back to the default role.
Step 6: Decide on automatic directory sync (optional)
With Directory Sync enabled, adding or removing a person in your identity provider automatically adds or deactivates their PlanOps membership, and group changes update their role. Without it, membership is created the first time each person signs in via SSO, and removal is handled manually.
Step 7: Keep a break-glass administrator
Make sure at least one organisation administrator can sign in without SSO (a normal email-and-password PlanOps account). This protects you from being locked out if your identity provider is ever unavailable. PlanOps will never remove the last non-SSO administrator of your organisation, even during directory sync.
This is a deliberate safeguard. Treat the break-glass account like an emergency key, with a strong password and two-step verification, and keep its details safe.
Step 8: Test with a pilot user
Once the connection is live, ask one person on your domain to use the "Sign in with SSO" option on the sign-in page and enter their work email. Confirm they are taken to your identity provider, returned to PlanOps, and land inside your organisation with the expected role.
Step 9: Roll out to your team
Let your team know they can now use "Sign in with SSO" with their work email. People on your domain who already had PlanOps accounts are added to your organisation the next time they sign in via SSO; their existing projects and any other organisations they belong to are kept.
SSO membership is additive. Existing personal organisations are left in place, and the organisation switcher continues to work for anyone who belongs to more than one organisation, including contractors added manually.
Related Guides
Last updated: 2026-07-01