SSO Setup Process (Keen Platform)

SSO Setup Process (Keen Platform)

SSO Setup Process (Keen Platform)

Overview

This document outlines the step-by-step process followed to configure Single Sign-On (SSO) for a client using Okta and WorkOS, including internal coordination, client requirements, setup steps, troubleshooting, and validation.

1. Initial Request & Communication

  • Client submits a request for SSO Setup.

  • Account Director (AD) creates a KPS ticket.

  • Communication is primarily handled within the KPS ticket unless escalation is needed.

  • Keen Product Support team manages communication and updates.

  • Optional: Client can be added directly to the KPS ticket for transparency.

2. Required Information from Client

The support ticket must include:

  • Client Domain(s): (e.g., @keends.com, @company.com)

  • Timing Requirement: Minimum one-week notice before desired go-live date

  • Client IT Contact Info:

    • Must be an admin of the client’s Identity Provider (IdP)

3. Internal Setup Responsibilities

Product Support Manager + Infrastructure Lead

  • The Infra Lead will add client domain(s) to WorkOS

  • The Infra Lead will Generate and send SSO setup link to client IT admin

  • AD will then create a client admin user within the Keen Platform

4. SSO Configuration Details (Provided to Client)

WorkOS SAML Configuration

5. SSO Setup Instructions (Client-Side)

Step 1: Create App

  • In application IE: Okta Navigate to: Applications > Create App Integration

  • Select: SAML 2.0

Step 2: General Settings

  • Name the app (e.g., "[Client Name] SSO")

Step 3: SAML Settings

  • Paste:

    • ACS URL

    • Audience URI

Step 4: Assignments

  • Assign users or groups to the application

  • If not assigned, users cannot log in

Step 5: Feedback

  • Select: "I'm an Okta customer adding an internal app"

  • Click Finish

6. Required Information from Client After Setup

Client must provide ONE of the following:

Preferred

  • IdP Metadata URL

Alternative Options

  • Metadata XML file

  • Manual values:

    • IdP Entity ID

    • SSO URL

    • X.509 Certificate

7. Connection Activation

  • Once metadata is received Infrastructure team will:

    • Link the connection in WorkOS

    • Activate SSO connection

  • Status remains inactive until client completes setup and final import is done

8. SAML Attribute Statements

If an issue occurs with the SSO Login ensure that the client has updated Okta SAML Attribute Statements:

  • email → user.email

  • firstName → user.firstName

  • lastName → user.lastName

9. Additional Client Questions

Q: Can Keen enforce SSO-only logins?

  • Answer: Yes, this is supported

10. Validation & Final Steps

  • Confirm SSO login works successfully

  • Ask client to test authentication flow

  • Monitor logs for errors

  • Offer support call if needed

Closure Process

11. Final Outcome (Case Summary)

  • Client completed setup

  • Metadata provided and integrated

  • Attribute mappings corrected

  • SSO login successfully validated

  • Implementation marked as complete

Notes

  • Always ensure attribute mappings include email for domain validation

  • Early coordination with client IT reduces delays

  • Encourage metadata URL usage for easier integration