K

Connect SSO and your directory

Let people sign in with company accounts, and pull in your org chart so departments and teams fill themselves.

This page covers two screens in the admin console: Users & teams › SSO/SCIM and Directory.
One is about signing in with company accounts; the other is about importing your org chart as-is.

These are two different things

The names look alike, but they do completely different jobs, and you can turn each on independently.

What it decides
SSO providersWhich account people sign in with (Okta, Microsoft, Google, …)
Directory syncWho belongs to which department — your roster and org structure

You can wire up sign-in only, or import the org chart only. Do both and people land in their own department when they sign in.

Registering an SSO provider

On the SSO/SCIM screen, click Register IdP in the SSO providers card. The dialog has two steps.

Step 1 — pick a provider. Choose Okta, Microsoft (Entra ID), or OIDC (custom). Google isn't listed because it's provided as sign-in from the start.

Step 2 — fill in the values. Numbered instructions for the provider you picked appear at the top. Follow them in order.

  • Register the two redirect URIs from those instructions in your IdP's app first. Use the copy buttons next to them
  • Then enter the Issuer, Client ID, and Client secret you got from the IdP and register

Once registered, it shows up in the card's list, where you manage it:

  • The switch on the right turns it on or off — whether it appears on the sign-in screen. At least one must stay on
  • Edit — re-enter the values
  • Delete — the button only appears on providers that are switched off. Deleting keeps the user accounts and only severs sign-in through that IdP
  • Google can't be edited or deleted. You can only switch it on and off

Register several and people pick one on the sign-in screen.

Importing your org chart

Use the Directory sync card lower down on the same screen. You can pick only one of four:

MethodHow it comes in
Okta · Microsoft Entra IDThe IdP pushes changes (SCIM). Updates land soon after they happen
Google WorkspaceAxHub reads it on a schedule
CSV uploadFor when there's no IdP. You upload the roster yourself

Okta and Microsoft Entra ID

Issue SCIM token shows a SCIM URL and a token once. Copy them now — you can't see them again.

Then paste both into your IdP's SCIM app. Numbered, provider-specific instructions appear on screen alongside.

Google Workspace

You have to open up permissions in the Google admin console first, and that needs a super admin account.

  1. admin.google.comSecurity → Access and data control → API controls → Domain-wide delegation
  2. Click Add new, paste in the client ID and OAuth scopes shown on the AxHub screen, and authorize
  3. Come back to AxHub, enter your domain and a lookup admin email, and click Connect

The lookup admin has to be an account that can read the directory.

CSV upload

No IdP needed — a roster is enough. One person per line, with email (required), name, and department. You can download the template from the screen, and Excel files work too.

The file you upload becomes the org chart. Departments and people missing from the new roster disappear. Even for a small change, upload the complete roster.

After it's connected

The card shows the connection status, with buttons on the right.

  • Sync now — pull immediately instead of waiting for the next cycle (for CSV, Re-place members)
  • Reissue token — issues a new SCIM token. Update your IdP with it too
  • Disconnect — severs the connection. Teams created by the sync are deleted along with it

Reading the Directory screen

Directory in the left menu shows the org structure you imported. The department list shows name, headcount, and joined, and clicking a department expands its people.

  • Joined reads like "3/12" — people who are on the org chart but haven't come into AxHub yet are listed too
  • Anyone with no department collects in an Unassigned row at the bottom
  • If anyone was moved to a team by hand, a Re-sync all button appears. Clicking it returns all of them to their directory placement

Letting people on the org chart join themselves

At the top of the Directory screen is a Directory auto-join switch. Turn it on and anyone on the org chart joins just by signing in — no invitation. No inviting 300 people one at a time.

  • You need an org chart to turn it on; without one the switch is locked
  • Auto-join happens when they arrive through your company's sign-in screen. If they're signed in elsewhere, your company appears as a card in their list and they click to join
  • They land in their org-chart department the moment they join
  • If they already have a pending invitation, the invitation wins — the role you set on it is preserved
  • Auto-joins aren't announced. Check the member list to see who came in

If you register a company email domain, every account on that domain joins automatically regardless of the org chart. That's a separate switch under Settings in the admin console, and it works independently of directory auto-join.