Before you start
Connect your identity provider
- Google Workspace
- SAML and SCIM
- Open Settings > General. In Single sign-on, click Set up and select Google Workspace.
- Complete the setup assistant to configure sign-in and verify your domain, then return to Hyperline.
- Click Configure next to Directory synchronization from Google Workspace. Authorize access to both users and groups with your administrator account.
- Keep the authorization window open until synchronization completes. Directory synchronization changes from
In progresstoConnected.
Connected before directory synchronization is
ready. Complete both steps to use automatic provisioning.Configure provisioning and roles
Single sign-on controls how members sign in. Provision users in Hyperline controls automatic membership updates. Sync roles from identity provider groups separately controls whether group memberships determine roles.Choose how roles are managed
Choose whether to assign roles manually in Hyperline, through identity provider groups, or directly through SCIM. The following table applies while user provisioning is on; account owners are excluded from automatic role changes. If a direct SCIM role is stored, follow the SCIM rows regardless of the group role sync setting.Choose a default role
Open Settings > Team > Roles > Role provisioning, select the Default role, and click Save changes. If none is selected when provisioning is enabled, Hyperline uses the account’s standard default role. The default is the fallback shown in the table above. While group role sync is off and no direct SCIM role is stored, changing it preserves existing members’ roles. Returning members follow the reactivation rules.Enable user provisioning
In Settings > General > Single sign-on, check Provision users in Hyperline. Enable it if needed and click Save changes. This setting is available once directory synchronization or SCIM provisioning is configured. Hyperline imports existing identity provider users and applies future profile and membership changes. If an email matches an existing Hyperline user, the identity provider manages their membership in this account, except for account owners. Keep group role sync off while preparing mappings. If you re-enable provisioning on a connection where group role sync is already on, review and confirm the proposed roles before saving.Configure your chosen role management method
Manage roles in Hyperline
Manage roles in Hyperline
Example 💡
Assign roles through identity provider groups
Assign roles through identity provider groups
- Confirm that your provider has synchronized the required groups and memberships. Google Workspace synchronizes them automatically; for SAML and SCIM, configure your identity provider to push them.
- Open Settings > Team > Roles > Role provisioning. Click View groups, then View members to check the received memberships. Use the pagination controls to review additional results.
- Click Add mapping, select a group and a Hyperline role, then save. Repeat for each group. You can map each group once and use its actions menu to edit or delete the mapping.
- Return to Settings > General > Single sign-on, enable Sync roles from identity provider groups, and click Save changes.
- Review the current and proposed roles, then click Activate role synchronization. Cancel to continue preparing mappings without applying them.
Assign roles directly through SCIM
Assign roles directly through SCIM
roles attribute to send:- A
valuecontaining the exact name or ID of an existing role in this Hyperline account, such asAdmin. SCIM does not create roles. - One role entry, or exactly one entry with
primaryset totrueif your provider sends several.
Assign managers through SCIM
For SAML and SCIM connections, you can synchronize each provisioned member’s manager from your identity provider. Keep Provision users in Hyperline enabled; manager updates do not depend on Sync roles from identity provider groups. Google Workspace directory synchronization does not synchronize managers.- Provision the manager through the same connection first and confirm that they are a member of the same Hyperline account.
- In your identity provider’s attribute mappings, map the manager to the enterprise SCIM
manager.valuefield:urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager.value. Send the manager’s SCIM useridreturned during provisioning, not their email address orexternalId. - Push the member’s update from your identity provider, then check the Manager column in Settings > Team > Members.
Share the login link
After single sign-on showsConnected:
- Open Settings > General > Single sign-on.
- Click Copy login URL next to SSO login URL.
- Share the link with your team so they can sign in through your identity provider.
Manage your connection
Pause provisioning or switch role management
Pause provisioning or switch role management
- Turn group role sync off: existing roles and saved mappings remain in place. Hyperline does not restore the roles members had before synchronization. Direct SCIM roles continue to apply while user provisioning is on; you can edit roles manually for members without one.
- Turn user provisioning off: identity provider changes stop creating, suspending, removing, or changing roles for memberships in this account, including direct SCIM role and manager updates. Existing memberships, roles, managers, and saved settings remain. You can edit roles manually without changing the saved group role sync setting.
- Re-enable provisioning: Hyperline imports users and checks previously linked memberships again. Suspensions and deletions made during the pause can now remove access. If group role sync is already on, mapped and default roles apply; direct SCIM roles apply independently of that setting. Review your provider’s users and the proposed assignments before saving.
Reconfigure single sign-on
Reconfigure single sign-on
Synchronize Google Workspace manually
Synchronize Google Workspace manually
Failed if shown to read the provider error.Google Workspace also synchronizes automatically. A new manual synchronization cannot start if the connection was synchronized during the previous 30 minutes.Understand membership updates and removal
Understand membership updates and removal
- While provisioning is on, suspending or blocking a user in your identity provider removes their provisioned access. Restoring them reactivates the existing membership.
- A returning member follows the current SCIM or group role rules. With group role sync off and no direct SCIM role stored, they keep their previous role if it is still valid; otherwise, they receive the default.
- Removing a member from a mapped group recalculates their role when group role sync is on: another matching mapping applies, or the default if none matches. A direct SCIM role still takes precedence.
- Deleting a user removes linked memberships only in accounts where user provisioning is on, except account owner memberships. Accounts with provisioning paused keep their memberships until it is re-enabled.
- Account owners are never automatically suspended or removed.
- Memberships that remain manually managed in other accounts are unaffected.
Troubleshooting
Single sign-on is connected, but directory synchronization is not
Single sign-on is connected, but directory synchronization is not
A group is missing from role provisioning
A group is missing from role provisioning
SCIM provisioning is not configured
SCIM provisioning is not configured
The login page requests a password
The login page requests a password
Launching Hyperline from the identity provider fails
Launching Hyperline from the identity provider fails
Provisioned users do not appear
Provisioned users do not appear
Connected for Google Workspace or SCIM provisioning shows Configured for SAML. Check that Provision users in Hyperline is enabled and users are included in synchronization or assigned to the Hyperline application in your provider. For SCIM, also review your provider’s provisioning logs.Group mappings do not change roles
Group mappings do not change roles
A manual role change is rejected
A manual role change is rejected
Role preview cannot load the directory
Role preview cannot load the directory
Synchronization failed
Synchronization failed
Failed next to Last synchronization to read the provider error. Resolve the Google Workspace configuration or authorization issue, then click Synchronize now.
