Skip to main content
Rulebase can assign member roles from your identity provider groups. This lets your IT team manage Rulebase access in the same place they manage employee groups, instead of updating each member manually in Rulebase. Use this guide if your organization uses Single Sign-On (SSO), Directory Sync, or both.

Before you start

Make sure you have:
  • Administrator access in Rulebase
  • Administrator access to your identity provider
  • The identity provider groups you want to map to Rulebase roles
  • A list of the Rulebase roles each group should receive
You can review available roles in Roles and Permissions.

Open the Admin Portal

The Admin Portal is available from your Rulebase settings page.
  1. Open your Rulebase members settings:
  2. Click Admin portal.
  3. Choose the SSO or Directory Sync setup flow for your organization.
If you do not see the Admin Portal option, contact your Rulebase administrator or reach out to Rulebase.

Choose a role assignment method

If your organization uses Directory Sync, use Directory Sync group role assignment. Directory Sync keeps group membership changes up to date without waiting for users to sign in again. If your organization only uses SSO, use SSO group role assignment. SSO role changes are applied the next time a user signs in with SSO. Avoid configuring both methods for the same role workflow unless your Rulebase team has confirmed the intended setup.

Assign roles with Directory Sync

Directory Sync role assignment is available for SCIM-based directories and Google Workspace directories.
  1. In your identity provider, create or confirm the groups you want to use for Rulebase access.
  2. Push or sync those groups to Rulebase through your directory setup.
  3. In the Rulebase Admin Portal, continue the Directory Sync setup.
  4. When prompted, map each identity provider group to the appropriate Rulebase role.
  5. Save the setup.
After you finish, reach out to Rulebase so we can verify the mappings and complete any Rulebase-side configuration.

Assign roles with SSO

Use SSO role assignment when your organization does not use Directory Sync for Rulebase.
  1. In your identity provider, create or confirm the groups you want to use for Rulebase access.
  2. Configure your SSO application to include group membership data in the SAML or OIDC response.
  3. In the Rulebase Admin Portal, continue the SSO setup.
  4. When prompted, map each identity provider group to the appropriate Rulebase role.
  5. Save the setup.
  6. Ask affected users to sign out and sign back in with SSO.
After you finish, reach out to Rulebase so we can verify the mappings and complete any Rulebase-side configuration.