How do I set up SSO / SAML?
Enterprise workspaces can sign in with your identity provider via SAML SSO.
Updated 2026-08-13
Enterprise workspaces can enable SAML SSO so people sign in with your company's identity provider (IdP). Setup uses Settings → Organisation access plus your IdP metadata XML sent to support — there isn't a generic admin console beyond that screen.
Steps
- Confirm the workspace is on Enterprise, or upgrade from Organisation access (non-Enterprise shows Enterprise SSO (SAML) with Okta, Entra, or Google Workspace).
- As an owner or admin, open Settings → Organisation access (iPhone, iPad, or Mac). Copy Entity ID / Audience, ACS URL, and SP metadata URL into your IdP's SAML app.
- Send your IdP metadata XML to FabricLoop support and include the workspace name. We complete the handshake — the app shows SSO status: Not connected until that's done, then Connected.
- When SSO is connected, new teammates who sign in with SSO can join automatically.
- Test with a pilot user before you require SSO for everyone.
Email domain join
The same screen can allow anyone with a matching work email to join without an invite. If SSO is connected and domain join is on, people can skip your IdP and sign in with a magic link. Turn domain join off if SSO should be the only path in.
Tips
- Organisation access is not in the web Settings list today — use the native app or contact us with your metadata XML.
- SCIM provisioning (Enterprise, via support) can keep membership in sync after SSO is live.
- Keep a break-glass owner procedure with your IT team.
Related
- How does SCIM provisioning work?
- What are the workspace roles?
- How do I invite people to my workspace?
- Where do I find audit logs?
Still stuck?
Contact us — for IdP setup, include your metadata XML and workspace name. Or browse all help topics.