Skip to content
English
  • There are no suggestions because the search field is empty.

Manual Roles Management for Okta SSO Provisioning

Manage Roles manually when SSO Provisioning is on

Like manual Groups management, you can keep SSO Provisioning on for user creation / deactivation while managing Role assignment in Consensus directly. Use this when your Okta groups don't cleanly map to the Consensus Role you want each user to have.

When to use manual Roles

  • Custom roles you've built in Consensus don't correspond to any Okta group.
  • Roles depend on context Okta doesn't know (a specific deal, a temporary project assignment).
  • Onboarding flow includes a manual approval / role assignment step.

Configure

  • Settings → Integrations → SSO → SSO Provisioning → toggle "Sync Roles from Okta" OFF.
  • Optionally set a Default Role for new SSO-provisioned users (typically View Only or Sender/Tracker to start).
  • Save.

SSO Provisioning Group / Role Sync settings.

Assigning Roles to users

When a new user is provisioned, an admin assigns the appropriate Role from Settings → Manage Users & Access → Users tab → inline Role dropdown on the user's row, or via Edit User. See "Roles & Permissions - Custom Roles" for role definitions and "How to filter your Manage Users Page" for finding new unconfigured users efficiently.

Mixing manual and auto

You can keep Group sync on while turning Role sync off, or vice versa — the two toggles are independent.