Configuring Single Sign-On

Open Settings > Authentication. This area requires Full Access and Manage Settings.

Use the SSO section to connect the workspace to an identity provider. The supported selectable protocol is OpenID Connect (OIDC). SAML is marked coming soon and cannot currently be selected for production sign-in.

Configuration fields

  • SSO Enabled: turns the configured connection on or off.
  • Protocol: the authentication protocol.
  • Identity Provider: identifies the provider used by your organization.
  • Issuer URL: the issuer supplied by that provider.
  • Client ID and Client Secret: the registered application's credentials.
  • Default Role for New Users: the starting role when the identity workflow provisions a user without a more specific mapping.
  • Enforce SSO: applies the stronger sign-in requirement indicated by the control.

Setup sequence

  1. Register the application with your identity provider.
  2. Copy the exact login and callback configuration URLs displayed by CaseWyze into the provider configuration where required.
  3. Enter the provider's values and save the configuration.
  4. Test sign-in with an intended user before enforcing SSO broadly.
  5. Review default roles and group mappings.

Do not place secrets in support screenshots or documentation. SSO authenticates users; their CaseWyze permissions, access level, assignments, and access groups still determine what they can access.