DOCS Platform

Teams, SSO & provisioning

Add your team, and connect Microsoft Entra or Google Workspace for single sign-on.

Layer8 is built for a team, not just an individual — with organizations, roles, and single sign-on for the identity provider you already run.

Invite your team

Under Settings → Organization, invite teammates by email and assign a role:

  • Owner / Admin — manage members, billing, and app access.
  • Member — use the apps; see what's shared with them.

Sharing is explicit: maps, notes, and assets are private to their creator until shared with a specific person at a specific permission level. There's no ambient org-wide access.

Single sign-on (SSO)

Layer8 authenticates through Clerk, which supports enterprise SSO out of the box:

  • Microsoft Entra ID (formerly Azure AD) — SAML or OIDC.
  • Google Workspace — OIDC / "Sign in with Google".
  • Okta, OneLogin, and any SAML 2.0 IdP.

Because identity is delegated to your IdP, offboarding is immediate: disable a user in Entra or Workspace and their Layer8 access ends with the next token refresh — no separate account to remember to remove.

Setting it up: SSO connections are configured per-organization on Team plans. Once your IdP is connected, users signing in with a matching email domain are routed to your identity provider automatically.

Automated provisioning (SCIM)

For larger teams, SCIM provisioning keeps Layer8 membership in sync with your directory — users added to (or removed from) an Entra/Workspace group are created or deprovisioned in Layer8 automatically, so your member list is never stale.

Contact us to enable SCIM for your organization.