Skip to main content
Connect Google Workspace or a SAML identity provider to let your team sign in through single sign-on (SSO). User provisioning keeps their Hyperline memberships up to date as they join, change teams, or leave. You choose separately whether to manage their roles in Hyperline, through identity provider groups, or through roles supplied directly by SCIM.

Before you start

Single sign-on and user provisioning are enterprise features available on demand. Contact Hyperline through the in-app chat to enable them for your account.
You need the Manage authentication permission and pop-ups allowed in your browser. Configure a separate connection for each Hyperline account. See Users & permissions.

Connect your identity provider

You need a Google Workspace administrator account and the Google Admin SDK Directory API enabled for users and groups.
  1. Open Settings > General. In Single sign-on, click Set up and select Google Workspace.
  2. Complete the setup assistant to configure sign-in and verify your domain, then return to Hyperline.
  3. Click Configure next to Directory synchronization from Google Workspace. Authorize access to both users and groups with your administrator account.
  4. Keep the authorization window open until synchronization completes. Directory synchronization changes from In progress to Connected.
Hyperline retrieves directory users and groups automatically. You can also start a manual synchronization.
Single sign-on can show Connected before directory synchronization is ready. Complete both steps to use automatic provisioning.

Configure provisioning and roles

Single sign-on controls how members sign in. Provision users in Hyperline controls automatic membership updates. Sync roles from identity provider groups separately controls whether group memberships determine roles. For SAML and SCIM, completing setup with SCIM configured enables user provisioning automatically. Group role sync is off by default for new connections. Reconfiguring an existing connection keeps its group role sync setting, so review it before completing setup.

Choose how roles are managed

Choose whether to assign roles manually in Hyperline, through identity provider groups, or directly through SCIM. The following table applies while user provisioning is on; account owners are excluded from automatic role changes. If a direct SCIM role is stored, follow the SCIM rows regardless of the group role sync setting. Direct SCIM roles take precedence over group mappings and manual assignments. They are available only for SAML and SCIM connections. Omitting the role attribute from a later update does not clear a role previously supplied through SCIM; see Assign roles directly through SCIM before switching methods. Without a direct SCIM role, group role sync uses the first valid matching mapping by priority, then creation time. A member receives one role, even if several groups match. For existing active members, no groups, no mappings, and no matching groups lead to the default role only when group role sync is on. While provisioning is on, you can edit roles in Settings > Team > Members only when group role sync is off and no direct SCIM role is stored, subject to your permissions. Hyperline rejects manual changes to a role managed through SCIM and asks you to change it in your identity provider. Pausing user provisioning allows manual role edits, even if group role sync remains selected.

Choose a default role

Open Settings > Team > Roles > Role provisioning, select the Default role, and click Save changes. If none is selected when provisioning is enabled, Hyperline uses the account’s standard default role. The default is the fallback shown in the table above. While group role sync is off and no direct SCIM role is stored, changing it preserves existing members’ roles. Returning members follow the reactivation rules.

Enable user provisioning

In Settings > General > Single sign-on, check Provision users in Hyperline. Enable it if needed and click Save changes. This setting is available once directory synchronization or SCIM provisioning is configured. Hyperline imports existing identity provider users and applies future profile and membership changes. If an email matches an existing Hyperline user, the identity provider manages their membership in this account, except for account owners. Keep group role sync off while preparing mappings. If you re-enable provisioning on a connection where group role sync is already on, review and confirm the proposed roles before saving.

Configure your chosen role management method

Keep Sync roles from identity provider groups off and leave the direct SCIM user-role mapping unconfigured in your identity provider. Assign roles in Settings > Team > Members.If you previously used another method, follow Pause provisioning or switch role management before making manual assignments.

Example 💡

Your finance lead assigns roles in Hyperline while Google Workspace creates and removes members automatically. Keep provisioning on and group role sync off. New members receive the default role; directory updates preserve the roles your finance lead assigns.
You can inspect groups and save mappings while group role sync is off. Preparing or editing these mappings does not reassign existing members until you activate synchronization.
  1. Confirm that your provider has synchronized the required groups and memberships. Google Workspace synchronizes them automatically; for SAML and SCIM, configure your identity provider to push them.
  2. Open Settings > Team > Roles > Role provisioning. Click View groups, then View members to check the received memberships. Use the pagination controls to review additional results.
  3. Click Add mapping, select a group and a Hyperline role, then save. Repeat for each group. You can map each group once and use its actions menu to edit or delete the mapping.
  4. Return to Settings > General > Single sign-on, enable Sync roles from identity provider groups, and click Save changes.
  5. Review the current and proposed roles, then click Activate role synchronization. Cancel to continue preparing mappings without applying them.
Activation applies the mappings to existing members as well as new ones. Check default-role assignments in the preview: members without a matching group receive the default unless a direct SCIM role takes precedence.
Once activated, changes to group memberships, mappings, or the default role automatically update provisioned members’ roles. The preview reflects the directory at the time you review it; later membership changes continue to synchronize.
For connections with 1,000 or more directory users, contact Hyperline through the in-app chat before activation. The preview is unavailable because it cannot confirm the complete directory.
For SAML and SCIM connections, configure your identity provider’s SCIM roles attribute to send:
  • A value containing the exact name or ID of an existing role in this Hyperline account, such as Admin. SCIM does not create roles.
  • One role entry, or exactly one entry with primary set to true if your provider sends several.
Keep Provision users in Hyperline enabled. The role assignment table shows how valid, empty, and invalid role values are handled. Do not send an empty role list to mean “leave the role unchanged”: it explicitly selects the default role.To switch to manual roles or group mappings, contact Hyperline through the in-app chat before removing the user-role mapping from your identity provider. Simply stopping the attribute from being sent does not clear the previously stored role.
For an existing connection, contact Hyperline through the in-app chat to confirm that SCIM role attributes are enabled. Configuring the attribute in your identity provider alone may not be sufficient.

Assign managers through SCIM

For SAML and SCIM connections, you can synchronize each provisioned member’s manager from your identity provider. Keep Provision users in Hyperline enabled; manager updates do not depend on Sync roles from identity provider groups. Google Workspace directory synchronization does not synchronize managers.
  1. Provision the manager through the same connection first and confirm that they are a member of the same Hyperline account.
  2. In your identity provider’s attribute mappings, map the manager to the enterprise SCIM manager.value field: urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager.value. Send the manager’s SCIM user id returned during provisioning, not their email address or externalId.
  3. Push the member’s update from your identity provider, then check the Manager column in Settings > Team > Members.
To remove an assignment, configure your provider to send an explicit empty or null manager value. Omitting the attribute does not clear a previously supplied manager. A member cannot be their own manager. If the manager has not been provisioned through the same connection or is missing from the account, Hyperline cannot apply the update. Provision the manager, then push the member’s update again. You can still edit managers manually, but later provisioning can overwrite your changes with the manager supplied by your provider. Account owners are excluded from automatic manager updates. Pausing user provisioning pauses manager updates too. After single sign-on shows Connected:
  1. Open Settings > General > Single sign-on.
  2. Click Copy login URL next to SSO login URL.
  3. Share the link with your team so they can sign in through your identity provider.
Copy the link from the account and environment members need to access: sandbox and production have separate links. Members can bookmark it; entering an email on the standard login page does not automatically select your enterprise connection.

Manage your connection

  • Turn group role sync off: existing roles and saved mappings remain in place. Hyperline does not restore the roles members had before synchronization. Direct SCIM roles continue to apply while user provisioning is on; you can edit roles manually for members without one.
  • Turn user provisioning off: identity provider changes stop creating, suspending, removing, or changing roles for memberships in this account, including direct SCIM role and manager updates. Existing memberships, roles, managers, and saved settings remain. You can edit roles manually without changing the saved group role sync setting.
  • Re-enable provisioning: Hyperline imports users and checks previously linked memberships again. Suspensions and deletions made during the pause can now remove access. If group role sync is already on, mapped and default roles apply; direct SCIM roles apply independently of that setting. Review your provider’s users and the proposed assignments before saving.
For SAML and SCIM, completing setup or reconfiguration with SCIM configured turns user provisioning back on. Check both provisioning and role settings afterward.
In Settings > General > Single sign-on, click Reconfigure to reopen the setup assistant. You can update sign-in, finish domain verification, or complete SCIM configuration without deleting the connection. Hyperline refreshes its details when you close the assistant.For Google Workspace directory authorization, use Configure in the directory synchronization line. For SAML, follow the provider setup instructions and review provisioning after reconfiguration.
In Settings > General > Single sign-on, click Synchronize now and confirm. Synchronization runs in the background. Last synchronization displays its date and time; hover over Failed if shown to read the provider error.Google Workspace also synchronizes automatically. A new manual synchronization cannot start if the connection was synchronized during the previous 30 minutes.
  • While provisioning is on, suspending or blocking a user in your identity provider removes their provisioned access. Restoring them reactivates the existing membership.
  • A returning member follows the current SCIM or group role rules. With group role sync off and no direct SCIM role stored, they keep their previous role if it is still valid; otherwise, they receive the default.
  • Removing a member from a mapped group recalculates their role when group role sync is on: another matching mapping applies, or the default if none matches. A direct SCIM role still takes precedence.
  • Deleting a user removes linked memberships only in accounts where user provisioning is on, except account owner memberships. Accounts with provisioning paused keep their memberships until it is re-enabled.
  • Account owners are never automatically suspended or removed.
  • Memberships that remain manually managed in other accounts are unaffected.
You can still invite members manually. In Settings > Team > Members, hover over a provisioned member’s email to see their identity provider. Remove their access through that provider; role editing follows your role management settings.

Troubleshooting

Only authentication setup is complete. Click Configure in the directory synchronization line and authorize access with a Google Workspace administrator account.
For Google Workspace, confirm that the Google Admin SDK Directory API is enabled and access to both users and groups was authorized. Click Synchronize now in Settings > General and wait for completion. For SCIM, confirm that your identity provider has pushed the group and its memberships. Then reopen View groups or the group selector.
Click Reconfigure and complete SCIM configuration in the setup assistant and your identity provider. Confirm that your provider is configured to provision both users and groups.
Use the dedicated login link to start your enterprise sign-in flow.
SAML setup also enables sign-in from your identity provider. Try Reconfigure to refresh the connection, or use the SSO login URL to start from Hyperline. Contact Hyperline through the in-app chat if the issue persists.
Confirm that Directory synchronization shows Connected for Google Workspace or SCIM provisioning shows Configured for SAML. Check that Provision users in Hyperline is enabled and users are included in synchronization or assigned to the Hyperline application in your provider. For SCIM, also review your provider’s provisioning logs.
Check that Provision users in Hyperline and Sync roles from identity provider groups are enabled and saved. Use View groups > View members to confirm the member belongs to the mapped group. If your provider also supplies a SCIM user role, that role takes precedence. Review your role management method before changing the configuration.
While user provisioning is on, change group-managed or direct SCIM roles in your identity provider. To manage roles manually, pause user provisioning or follow the instructions for switching role management methods. If Hyperline cannot verify whether SCIM manages the role, retry after the provider connection is available.
A directory error stops the preview; it does not assign the default role to users whose groups could not be loaded. Resolve the provider error and retry. Reading groups, inspecting members, and previewing roles do not change existing roles.
Hover over Failed next to Last synchronization to read the provider error. Resolve the Google Workspace configuration or authorization issue, then click Synchronize now.