Veridenti
Deployment Guide · Enterprise

Five steps. One console. Zero secrets exposed. Enterprise-ready in a week — governed from day one.

This guide walks your team from identity provider to board report: connect SSO and SCIM, set policy, define your domains, enroll every device, and govern with a verifiable audit trail — while Veridenti never sees a single secret at any step.

DAY 1 DAY 1 DAY 2 WEEK 1 ONGOING 1 2 3 4 Connect identity Set policy Define domains Enroll devices Govern & report SSO + SCIM Off / Optional / Required Route company logins SSO auto or code Adoption · risk · audit
5guided steps from identity provider to board report
0secrets visible to Veridenti at any step — vaults stay zero-knowledge
1weektypical time to org-wide device enrollment
1actionto offboard: sessions killed, shared keys rotated

The path

A rollout you can put on one slide.

Veridenti deploys in the order your security review expects: identity first, policy second, boundaries third, people fourth, proof always. Each step is done from one admin console, and nothing in the sequence requires an agent install, a network change, or a maintenance window.

DAY 1 DAY 2 WEEK 1 WEEK 2 ONGOING 1 · Connect identity 2 · Set policy 3 · Define domains 4 · Enroll devices 5 · Govern & report PILOT ORG-WIDE

What you need before you start: your identity-provider metadata (SAML XML or OIDC client), a list of directory groups, your company email domains, and about thirty minutes of an IT admin's time.

1 Connect identity Day 1 · ~30 minutes

Your directory becomes the source of truth.

Point Veridenti at your identity provider — Okta, Entra, Google, or any SAML 2.0 / OIDC IdP — and turn on SCIM. From that moment, joiners get a seat automatically, leavers lose one automatically, and your directory groups map straight onto Veridenti roles.

Veridenti Console — Identity acme.com SINGLE SIGN-ON O Okta · SAML 2.0 Metadata imported · certificate valid Connection verified SCIM PROVISIONING 412 users · 9 groups Last sync 2 min ago · deprovision on removal Sync active GROUP → ROLE MAPPING All-Staff Member 389 people IT-Admins Admin 6 people Security-Team Auditor 4 people Contractors Restricted 13 people Seats follow the directory: joiners provisioned, leavers deprovisioned — automatically
  • Any SAML 2.0 or OIDC provider. Okta, Microsoft Entra, Google Workspace, Ping, JumpCloud — if it speaks the standard, it connects.
  • Groups become roles. Map directory groups to Member, Admin, Auditor, or Restricted once — role changes then flow from the directory forever.
  • SCIM closes the loop. Removing someone from the directory deprovisions their Veridenti seat — no orphaned accounts to audit later.

Plan note: SSO (SAML/OIDC) and SCIM are included on Enterprise plans (50+ seats), and available as an at-cost add-on for smaller teams. No identity feature is held back as a separate premium tier.

2 Set policy Day 1–2 · Off / Optional / Required

Every feature has exactly three settings.

Veridenti policy is deliberately simple: each capability is Off, Optional, or Required — per feature, org-wide or per group. Add MFA, a session timeout, and how personal vaults behave on managed devices, and your policy page fits on one screen.

Veridenti Console — Policy Org-wide · v14 FEATURES · OFF / OPTIONAL / REQUIRED Autofill & save Off Optional Required Per-site masked email Off Optional Required Leaked-password monitoring computed on-device · no phone-home Off Optional Required Shared vaults Off Optional Required MFA Required · TOTP or passkey SESSION TIMEOUT 8 hours re-auth via SSO · vault locks on idle MANAGED DEVICES Lock personal vault on managed devices Self-disconnect when management ends
  • Three states, no sprawl. Off, Optional, Required — per feature. Policy debates end in minutes because there's nothing else to configure.
  • MFA and sessions, enforced. Require TOTP or passkeys, set an idle timeout, and the extension enforces it — with each change landing in the audit chain.
  • Managed devices, clear boundary. Optionally lock personal vaults on company machines — and have the org connection self-disconnect the moment a device leaves management.
3 Define company domains Day 2 · The line between work and personal

The work/personal line is the browser profile.

An enrolled work profile is work-only: every login captured on it goes to the company vault, where policy applies. A person's own life lives in a separate, zero-knowledge account the company can never read, subpoena, or wipe — a clean answer for your works council and DPO. Prefer both on one profile? Coexist mode keeps a personal vault alongside, with managed domains routing company logins to the org vault. Enrollment domains decide who may join without SSO.

jordan@acme.com signing in to Salesforce · work jordan@gmail.com personal banking · off-hours alex@partnerco.net attempting non-SSO enrollment DOMAIN RULES Managed domains acme.com · acmecorp.io Enrollment @acme.com only GOVERNED Org vault Policy applies · shared vaults Offboarding recoverable Personal vault Zero-knowledge · org-blind Survives offboarding ENROLLMENT BLOCKED not an approved enrollment domain WORK-ONLY BY DEFAULT · COEXIST OPTIONAL · THE PERSONAL SIDE IS NEVER THE ORG’S TO READ

“The profile boundary is a promise in both directions: an enrolled profile holds only company data, and the company structurally cannot reach what it doesn't own.”

Veridenti deployment principle
4 Enroll devices Week 1–2 · Pilot, then org-wide

Two enrollment paths. Both end in the same place.

People on SSO enroll by simply signing in — no codes, no tickets. Everyone else uses a short-lived enrollment code issued by an admin and checked against your enrollment domains. Either way, the device lands enrolled, policied, and visible in the console.

WITH SSO · AUTOMATIC Sign in with IdP One SSO prompt after install Seat matched by SCIM Role from group mapping Enrolled · policy applied Visible in console · zero tickets WITHOUT SSO · ENROLLMENT CODE Admin issues code VRD-7K2M-Q4 expires 72 h User enters code + email Address checked against your enrollment domains — others rejected Enrolled · policy applied Same governance, same audit trail

Rollout pattern that works: enroll IT and one friendly team in week one, import their existing credentials with the guided importer, then open enrollment org-wide in week two. Self-healing autofill means the first fill works — so adoption doesn't need a second campaign.

5 Govern & report Ongoing · Proof, not anecdotes

The rollout ends. The evidence keeps accruing.

From week one, the console turns deployment into governance: adoption you can watch climb, a Human-Risk Index your board can track, quarterly access recertification, and a tamper-evident, hash-chained audit trail streaming to the SIEM you already run.

Veridenti Console — Governance Q3 · 412 seats ADOPTION · ENROLLED SEATS 92% ▲ 379 of 412 HUMAN-RISK INDEX 27 lower is better ▼ 18 pts / quarter Computed on-device. Counts leave the endpoint. Secrets never do. Q3 ACCESS RECERTIFICATION 84% attested · shared-vault access reviewed · closes Sep 30 Chain verified tamper-evident audit …c614 → 9f2c → e81b ✓ STREAMING TO YOUR SIEM Splunk HEC Datadog HTTPS collector → Microsoft Sentinel & any SIEM
  • Adoption you can defend. Enrolled seats, active fills, and forms self-healed — the metrics that prove the tool is actually in the path of risk.
  • Recertification built in. Quarterly campaigns route shared-vault access to its owners for attestation — evidence your auditors can lift straight into the workpapers.
  • Your SIEM, natively. Splunk HEC and Datadog out of the box; Microsoft Sentinel and any other SIEM via a generic HTTPS collector. Every event rides the hash chain.

Lifecycle

Offboarding is a cryptographic event, not a checklist.

When someone leaves, deprovisioning — from SCIM or one console action — does everything the departure checklist used to hope for: the account is disabled, every session dies, and the shared-vault keys they held are dropped and rotated. What was theirs alone stays theirs alone.

ONE ACTION Deprovision SCIM removal, or one click in the console Account disabled instantly, org-wide Sessions terminated every device, every browser Shared keys rotated dropped from the leaver, re-issued to the team Personal vault untouched MINUTES, NOT TICKETS · FORMER STAFF HOLD KEYS TO NOTHING · EVERY STEP IN THE AUDIT CHAIN

“A departure should change what a person can decrypt — not just what a policy says they may open. Rotation makes the leaver's copy of every shared key worthless.”

Veridenti lifecycle principle

At a glance

The whole rollout, on one page.

Hand this to the project owner. Each phase is a bounded piece of work with a visible outcome — and nothing in it blocks the business while it happens.

Phase You do You get
Day 1 Connect identity & set policyImport IdP metadata, enable SCIM, map groups to roles; set Off/Optional/Required, MFA, session timeout. Seats provision from the directory. Policy is live before the first user arrives.
Day 2 Define company domainsList managed domains and enrollment domains in the console. New logins on the enrolled profile go to the company vault (work-only by default); non-SSO enrollment is restricted to your addresses. The work/personal line is set.
Week 1 Pilot enrollmentIT plus one team enrolls — SSO sign-in or admin code — and imports existing credentials with the guided importer. Real usage, real fills, first adoption numbers. Issues surface while the audience is small.
Week 2 Org-wide enrollmentOpen enrollment to everyone; self-healing autofill carries day-one adoption without a help-desk surge. Devices enrolled and policied across the org. The Human-Risk Index baselines.
Quarterly Govern & recertifyReview adoption and risk trend; run access recertification; export audit evidence from the SIEM. A trend line for the board and workpaper-ready evidence for the auditors. Offboarding stays a one-action event all year.

Before your security review asks

The fine print, stated plainly.

Deployment questions your reviewers will raise — answered the way we'd answer them in the room, with no claims we can't stand behind.

Data residency

Vault data is region-pinned and fails closed — if the pinned region is unavailable, data is not silently served from elsewhere. Global today; EU/US and per-country pinning on Enterprise contract.

Compliance posture

SOC 2 readiness is in progress, with Type I targeted first; ISO 27001 is on the roadmap. Our security whitepaper and policy pack are available for review today.

Contracts

DPA and BAA are available at contracting, counsel-approved. Enterprise agreements support security addenda and your standard vendor-review process.

Audit & monitoring

Audit is tamper-evident and hash-chained — integrity-verifiable by your team, not just exportable. Leaked-password and breached-domain monitoring is computed on-device, with no phone-home.

Next step

Book the thirty minutes. Ship the rollout.

A deployment engineer will walk your admin through steps one to three live — identity, policy, domains — and leave you with a pilot group enrolled before the call ends.

Bring to the call

  • IdP metadata (SAML XML or OIDC client)
  • Directory groups to map to roles
  • Your company email domains
  • A pilot team of 5–20 people

Start nowveridenti.com — self-serve deployment, live today

Talk to salessales@veridenti.com — guided rollout, pilots, security review