User Provisioning and Deprovisioning
Updated
Clockwise can integrate with your identity provider to synchronize enabled users with your paid plan. This lets you decide who you want to pay for using your preferred tools. This article will cover the setup instructions for our available identity access providers.
Set-Up
To set up the integration, you will first need to have access to the admin interface of your identity provider. You will also need to be an admin for your plan in Clockwise.
Please note that the use of an identity provider disables the ability to add users via the Clockwise admin panel: instead, the user list maintained in Okta or OneLogin are the users who may have access. An admin may then allow access through either of these identity providers by provisioning access to the Clockwise application.
Okta
- Navigate to the Organization Plans & Billing area of the Clockwise web app.
- Find your plan and click the discretion arrow to the right.
- Click “Configure SCIM” to be brought to an admin portal with our partner WorkOS.
- Follow the wizard to get set up. Please note: You do not need to configure push groups or custom attributes. Additionally, the token type required is an OAuth Bearer Token.
- The final page of the wizard will show a preview screen. Click “Back to Clockwise”.
- Recommended Step: Update the Clockwise application icon within Okta. To do so;
a. Click the icon in the application administration page to edit the icon
b. Upload the Clockwise icon
7. Recommended Step: Disable the application icon. Due to technical limitations with Okta, we can't configure what happens when users click the icon. Users should use their Clockwise browser extension or the Clockwise web app to sign in.
OneLogin
- Go toOrganization Plans & Billing area.
- Find your plan.
- Click “Configure SCIM” to be brought to the admin panel with our partner WorkOS.
- Follow their wizard to get set up.
- Recommended Step: Update the Clockwise application icon within OneLogin. To do so, click “Info”. Click the Rectangular and Square icons and upload the corresponding images
6. Optional step: You can configure your OneLogin portal so users can click the Clockwise icon and be brought to the Clockwise application. For your convenience, we have a stub SAML implementation that will interrupt the normal SAML login flow and redirect users to our Google SSO login page. Users will not actually login with SAML. You can set both the “SAML Audience URL” and “SAML Consumer URL” to https://www.getclockwise.com/sso/login_redirect. Click “Save”.
7. Each user in the “Users” pane should have a “Provisioned” state. If they are “Unknown”, try clicking “More Actions”→ “Sync Logins”. If they require approval, click on the user and click “Approve”.
8. Return to the WorkOS admin portal and complete the wizard. The final page will be a preview. Click “Back to Clockwise”
Admin Testing
As an admin, you might want to test out your Clockwise <> SCIM connection before adding the majority of your users. To do so, we recommend that you add yourself and up to 9 other users to confirm they are added to the corresponding Clockwise plan. When you add up to 10 users, Clockwise will not augment existing paid plan membership. Once you’ve confirmed things are working as expected, you can add the rest of your users. Please note that adding 10+ users will result in all of the users in your identity group moving to the paid plan; the rest will move to free.