Security, Roles, and Access
Identity setup for managed provider teams.
BondiByte supports Microsoft single sign-on and SCIM provisioning foundations, with role-aware access. SSO and SCIM are configured for your organisation and complement BondiByte's own roles and permissions.
Overview
Single sign-on (SSO) lets your team sign in to BondiByte using your existing Microsoft Entra ID (Azure AD) accounts.
SCIM provisioning foundations help align user provisioning and roles with your identity provider.
These features suit larger or identity-managed provider teams; smaller teams can use standard BondiByte logins.
Before you begin
- Have a Microsoft Entra ID (Azure AD) administrator available on your side.
- Decide which users need workspace access and which only need Staff Portal access.
- Understand that SSO and SCIM complement, not replace, BondiByte roles and permissions.
Recommended setup order
- Talk to BondiByte about enabling Microsoft SSO for your organisation.
- Work with BondiByte to provide the identity details your administrator manages on your side, using a safe handover rather than email or chat.
- Once enabled, your team can sign in with Microsoft on your organisation's login.
- Where SCIM is used, configure provisioning and group-to-role mapping with admin involvement.
- Confirm that customer users, Staff Portal users, auditor access, and platform administration remain separate.
Key fields and settings
SSO (single sign-on)
Signing in with your existing Microsoft Entra ID accounts instead of separate BondiByte passwords.
SCIM
A standard for provisioning and de-provisioning users, with directory sync and group-to-role mapping foundations.
Configured for your organisation
SSO is set up specifically for your organisation's workspace, not applied automatically.
Role-aware access
Signed-in users still receive BondiByte roles that control what they can see and do.
Best practice
- Use SSO when your organisation already manages identity centrally.
- Keep at least one owner or admin able to sign in during setup.
- Coordinate setup with your Microsoft administrator.
Common mistakes to avoid
- Assuming SSO or SCIM is automatic. Setup is configured for your organisation with admin involvement.
- Assuming SCIM is fully hands-off. Initial setup and role mapping require configuration.
- Assuming SSO replaces roles. BondiByte still enforces its own roles and permissions.
- Sharing sign-in configuration values through unsafe channels such as email or chat.
What to do next
Related guides
Roles and Access
Understand Owner, Admin, Manager, Staff, Staff Portal access, auditor access, and platform administration separation.
Staff WorkflowsStaff Portal
Help staff use portal access for shifts, availability, interest, swaps, cancellations, timesheets, reports, documents, notifications, and profile details.
Getting StartedGetting Started
Learn the recommended first-time setup order for BondiByte before inviting users or relying on daily workflows.
Need help applying this setup path?
Book a BondiByte demo and we can walk through the right setup order for your provider.