This guide walks your team from identity provider to board report: connect SSO and SCIM, set policy, define your domains, enroll every device, and govern with a verifiable audit trail — while Veridenti never sees a single secret at any step.
The path
Veridenti deploys in the order your security review expects: identity first, policy second, boundaries third, people fourth, proof always. Each step is done from one admin console, and nothing in the sequence requires an agent install, a network change, or a maintenance window.
What you need before you start: your identity-provider metadata (SAML XML or OIDC client), a list of directory groups, your company email domains, and about thirty minutes of an IT admin's time.
Point Veridenti at your identity provider — Okta, Entra, Google, or any SAML 2.0 / OIDC IdP — and turn on SCIM. From that moment, joiners get a seat automatically, leavers lose one automatically, and your directory groups map straight onto Veridenti roles.
Plan note: SSO (SAML/OIDC) and SCIM are included on Enterprise plans (50+ seats), and available as an at-cost add-on for smaller teams. No identity feature is held back as a separate premium tier.
Veridenti policy is deliberately simple: each capability is Off, Optional, or Required — per feature, org-wide or per group. Add MFA, a session timeout, and how personal vaults behave on managed devices, and your policy page fits on one screen.
An enrolled work profile is work-only: every login captured on it goes to the company vault, where policy applies. A person's own life lives in a separate, zero-knowledge account the company can never read, subpoena, or wipe — a clean answer for your works council and DPO. Prefer both on one profile? Coexist mode keeps a personal vault alongside, with managed domains routing company logins to the org vault. Enrollment domains decide who may join without SSO.
“The profile boundary is a promise in both directions: an enrolled profile holds only company data, and the company structurally cannot reach what it doesn't own.”
Veridenti deployment principlePeople on SSO enroll by simply signing in — no codes, no tickets. Everyone else uses a short-lived enrollment code issued by an admin and checked against your enrollment domains. Either way, the device lands enrolled, policied, and visible in the console.
Rollout pattern that works: enroll IT and one friendly team in week one, import their existing credentials with the guided importer, then open enrollment org-wide in week two. Self-healing autofill means the first fill works — so adoption doesn't need a second campaign.
From week one, the console turns deployment into governance: adoption you can watch climb, a Human-Risk Index your board can track, quarterly access recertification, and a tamper-evident, hash-chained audit trail streaming to the SIEM you already run.
Lifecycle
When someone leaves, deprovisioning — from SCIM or one console action — does everything the departure checklist used to hope for: the account is disabled, every session dies, and the shared-vault keys they held are dropped and rotated. What was theirs alone stays theirs alone.
“A departure should change what a person can decrypt — not just what a policy says they may open. Rotation makes the leaver's copy of every shared key worthless.”
Veridenti lifecycle principleAt a glance
Hand this to the project owner. Each phase is a bounded piece of work with a visible outcome — and nothing in it blocks the business while it happens.
| Phase | You do | You get |
|---|---|---|
| Day 1 | Connect identity & set policyImport IdP metadata, enable SCIM, map groups to roles; set Off/Optional/Required, MFA, session timeout. | Seats provision from the directory. Policy is live before the first user arrives. |
| Day 2 | Define company domainsList managed domains and enrollment domains in the console. | New logins on the enrolled profile go to the company vault (work-only by default); non-SSO enrollment is restricted to your addresses. The work/personal line is set. |
| Week 1 | Pilot enrollmentIT plus one team enrolls — SSO sign-in or admin code — and imports existing credentials with the guided importer. | Real usage, real fills, first adoption numbers. Issues surface while the audience is small. |
| Week 2 | Org-wide enrollmentOpen enrollment to everyone; self-healing autofill carries day-one adoption without a help-desk surge. | Devices enrolled and policied across the org. The Human-Risk Index baselines. |
| Quarterly | Govern & recertifyReview adoption and risk trend; run access recertification; export audit evidence from the SIEM. | A trend line for the board and workpaper-ready evidence for the auditors. Offboarding stays a one-action event all year. |
Before your security review asks
Deployment questions your reviewers will raise — answered the way we'd answer them in the room, with no claims we can't stand behind.
Vault data is region-pinned and fails closed — if the pinned region is unavailable, data is not silently served from elsewhere. Global today; EU/US and per-country pinning on Enterprise contract.
SOC 2 readiness is in progress, with Type I targeted first; ISO 27001 is on the roadmap. Our security whitepaper and policy pack are available for review today.
DPA and BAA are available at contracting, counsel-approved. Enterprise agreements support security addenda and your standard vendor-review process.
Audit is tamper-evident and hash-chained — integrity-verifiable by your team, not just exportable. Leaked-password and breached-domain monitoring is computed on-device, with no phone-home.
Next step
A deployment engineer will walk your admin through steps one to three live — identity, policy, domains — and leave you with a pilot group enrolled before the call ends.
Bring to the call
Start nowveridenti.com — self-serve deployment, live today
Talk to salessales@veridenti.com — guided rollout, pilots, security review