# Identity and access

Probo separates authentication from user provisioning. Invite and role-manage members in the organization, use SAML single sign-on (SSO) to authenticate them through your identity provider, and use SCIM to create, update, and deactivate their access.

- [Roles and permissions](/docs/product/roles-and-permissions) — Choose roles and decide whether to manage them in Probo or via SAML
- [Single sign-on](/docs/product/sso/overview) — Configure SAML authentication, verify domains, and optionally map roles
- [SCIM provisioning](/docs/product/scim/overview) — Automate user provisioning and deprovisioning from your identity provider
- [Audit log](/docs/product/audit-log) — Investigate who changed people, roles, and organization records

## How the capabilities work together

SSO verifies a member's identity when they sign in, but it does not create or remove organization memberships. SCIM manages those memberships and user records, but it does not authenticate users. Organizations commonly configure both against the same identity provider so that assignment controls access and SSO protects authentication.

## Recommended rollout

1. Invite initial owners and administrators under [Roles and permissions](/docs/product/roles-and-permissions).
2. Verify the email domain used by organization members.
3. Configure SSO as optional and test both service-provider and identity-provider initiated sign-in.
4. Configure SCIM with a limited group and confirm provisioning, updates, and deprovisioning.
5. Expand the SCIM assignment to the intended population.
6. Require SSO only after confirming that expected members can sign in and that a recovery path is available.

Probo provides setup guides for Google Workspace, Microsoft Entra ID or Microsoft 365, and Okta under the SSO and SCIM sections.

## Role management choices

Keep membership roles in [People](/docs/product/roles-and-permissions), or map them from your identity provider with the SAML **Role Attribute**. SCIM creates and deactivates people and usually starts them as **Employee**; set their Probo role in People afterward. See [Where to manage Probo roles](/docs/product/roles-and-permissions#where-to-manage-probo-roles).
