SSO on Team
1
Open org settings
As an admin, go to your organization settings in Zas.
2
Choose SSO provider
Select SAML or OIDC and enter your provider metadata or discovery URL.
3
Test and enable
Run a test login with a non-production account, then enable SSO for all members.
SCIM on Enterprise
SCIM is available on the Enterprise tier. It connects your identity provider to Zas for automatic user provisioning and deprovisioning.What SCIM does
- Creates accounts when a user is added to the Zas app in your IdP
- Updates roles when group mappings change
- Deprovisions users when they are removed from the IdP
SCIM deprovisioning
When SCIM deprovisions a user, everything that person had in transit leaves today. Their items are removed immediately, not at natural expiry. This is by design: corporate data should not outlive the employee’s access.Departure and identity recovery
If a user loses their corporate-only identity (for example, after SCIM deprovisioning or org removal), Zas does not force them to create a new account. Instead, they enter a grace window and use a live device claim flow. The user frame is: “Your Zas is still yours.”SSO sits in Team on purpose. We believe centralized sign-in is a baseline feature, not an Enterprise upsell.