What It Does For You
Once provisioning is switched on, your identity provider keeps Reelevant in step with your staff directory:
Nobody has to be invited by hand any more, and nobody keeps access after leaving.
Provisioning creates and maintains accounts. It does not replace single sign-on, which is what lets people log in. The two are configured separately, and provisioning works with or without single sign-on.
Before You Begin
- You need permission to update company settings in Reelevant.
- You need an administrator account in your identity provider.
- Decide which of your groups should become Reelevant Teams.
- Create the roles you want provisioned people to get.
Enabling Provisioning
1
Open the provisioning settings
Go to the account administration section and open the provisioning settings.
2
Turn provisioning on
Switch provisioning on. Until you do, your identity provider is refused access, even with a valid access key.
3
Copy the base address
The settings page shows a base address to paste into your identity provider. It is the same for every company.
4
Generate an access key
Click the button to generate an access key. The value is shown once — copy it straight away.
5
Paste both values into your identity provider
Follow the guide for your tool: Okta or Microsoft Entra ID.
Choosing How Roles Are Decided
Every Reelevant user has exactly one role. You choose where that role comes from:
If the incoming value matches nothing, Reelevant falls back to the default role you picked, and records the miss in the audit log. One wrong value never breaks the whole synchronisation.
Mapping Groups To Teams
Group synchronisation is on by default. Each group your identity provider pushes becomes a Reelevant Team, and its members become members of that Team.- Teams created this way are flat, with no parent or child.
- You can still arrange them into a hierarchy in Reelevant. Provisioning never undoes that.
- A Team that is part of a hierarchy cannot be deleted by your identity provider. Remove the parent and child links first.
- Everyone always keeps at least one Team. If the last one is taken away, Reelevant puts the person back into the company default Teams.
Choosing What Happens When Someone Leaves
Two behaviours are available. This is a Reelevant setting — your identity provider cannot choose per person.
Reelevant always refuses to deactivate or delete the last remaining administrator, so a wrong group assignment cannot lock your company out. The refusal is recorded in the audit log.
Checking That It Works
- The provisioning settings show the date of the last successful synchronisation.
- The audit log lists every account created, updated, deactivated, or deleted, and every value that could not be matched.
- The Users page shows deactivated people, so you can confirm a departure was applied.
What’s Next?
Set up Okta
Step-by-step provisioning setup in Okta.
Set up Microsoft Entra ID
Step-by-step provisioning setup in Microsoft Entra ID.
Audit log
Read what happened to accounts, and when.
Teams
Understand how Teams control access to resources.