Knowledge Base

Enterprise Single Sign-On (SSO)

Single Sign-On (SSO) allows your team to access Narrative using your organization's existing identity provider. Instead of managing separate login credentials, your team authenticates through the same system they use for other enterprise applications—streamlining access while strengthening security.

Why Use SSO?

Simplified Access Management

When employees join your organization, granting Narrative access is as simple as adding them to the appropriate group in your identity provider. When they leave, removing their IdP access immediately revokes their Narrative access too. No separate password resets or account deactivations required.

Enhanced Security

SSO integrates with your existing security policies, including multi-factor authentication requirements enforced by your identity provider. Your security team maintains centralized control over authentication standards across all enterprise applications, including Narrative.

Streamlined User Experience

Your team uses one set of credentials for everything. No more password fatigue from managing dozens of application-specific logins—just a seamless authentication experience that matches how they access other enterprise tools.

How It Works

Narrative uses SAML 2.0, the industry standard for enterprise single sign-on. When a user attempts to access Narrative:

  1. User initiates login — They enter your organization's slug on the Narrative login page
  2. Redirect to your IdP — Narrative redirects them to your identity provider (Okta, Azure AD, etc.)
  3. User authenticates — They log in using your organization's credentials and MFA requirements
  4. Access granted — Your IdP confirms their identity, and Narrative grants access

This flow ensures your identity provider remains the single source of truth for user authentication.

Supported Identity Providers

Narrative supports any SAML 2.0-compliant identity provider. We provide specific configuration guidance for:

  • Okta
  • Microsoft Azure AD (Entra ID)
  • OneLogin

Using a different provider? Our support team can assist with configuration for any SAML-compliant IdP.

Key Features

FeatureDescription
SAML 2.0Industry-standard secure authentication protocol
Just-in-Time ProvisioningAutomatically create Narrative accounts on first login
SSO EnforcementOptionally require SSO for all users—no password fallback
Role-Based AccessAssign admin or standard roles to organization members
Self-Service Admin PortalYour admins manage SSO configuration and members directly

Getting Started

SSO is available to enterprise customers with qualifying contracts. To enable SSO for your organization:

  1. Contact your Narrative Account Manager to confirm eligibility
  2. Narrative will provision your organization and provide your Organization Slug
  3. Follow the Admin Configuration Guide to complete setup

The configuration process typically takes 15–30 minutes for an experienced IT administrator.

Available Guides

  • Admin Configuration Guide — Step-by-step setup instructions for enterprise administrators configuring SSO with your identity provider
< Back
Rosetta

Hi! I’m Rosetta, your big data assistant. Ask me anything! If you want to talk to one of our wonderful human team members, let me know! I can schedule a call for you.