SAML Single Sign-On Integration
Your Connect Rocket account will provide you an SSO URL, Audience URI, Name ID Format and Application Username which you configure within your SAML Application Configuration.
Your SAML Application configuration requires the following attribute statements to be sent to Connect Rocket:
- firstName
- lastName
- role - a filtered list of internal group assignments (See below)
Once setup your SAML Application IDP METADATA URL is added to your Connect Rocket Account.
Role/Group Mapping
Connect Rocket uses roles to determine what permissions a user has. You can map your internal group names to Connect Rocket roles here. A convenient way to do this is to prefix your internal group names with 'Connect Rocket' and use a 'Starts with' filter.
For example, if you have an internal group called "Connect Rocket Admins", you can map that to the "Administrator" role.
If a user is in multiple groups, they will be assigned the highest role of the groups they are in.