Docs enterprise
SSO
OIDC and SAML single sign-on for RetrySight Enterprise, available from Core, plus API keys for agents.
On this page
Enterprise Core includes an SSO wizard. You do not need Analytics or Integration to put the dashboard behind your IdP.
What Core provides
- OIDC and SAML
- Encrypted IdP configuration at rest
- API key management with rotation grace (for fleet agents — separate from human SSO)
Higher tiers add SSO-related APIs (for example source-tools at Integration). Human login SSO itself starts at Core.
Typical flow
- Deploy the manager stack (Docker or Helm).
- Sign in with the bootstrap admin account.
- Open the SSO wizard and enter your IdP metadata (OIDC discovery URL or SAML descriptor).
- Map groups or claims to RetrySight roles as prompted.
- Confirm a non-admin user can sign in before you disable local passwords.
Keep at least one break-glass local admin until SSO is verified.
Agents vs humans
- Humans use SSO (or local accounts) in the dashboard.
- Fleet agents use API keys (
Admin → API keys), not IdP login. Put the key in agent config.
Security review
Data residency, BYO PostgreSQL, and tenancy notes: Security. For a written review pack, contact us.