diff --git a/docs/user-guide/account-teams/enterprise-plan.njk b/docs/user-guide/account-teams/enterprise-plan.njk index bf5200fc9c..785f32a47e 100644 --- a/docs/user-guide/account-teams/enterprise-plan.njk +++ b/docs/user-guide/account-teams/enterprise-plan.njk @@ -128,6 +128,37 @@ desc: Learn how the Enterprise plan works in Penpot. Discover its features and h
When an organization is first created, all controls are configured with the most permissive setting; the same setting is used by all teams that are not part of any organization. No behavior changes until you actively configure a Control.
+Single Sign-On lets you require all members of your organization to authenticate through your corporate identity provider (IdP) before accessing any of the organization's teams and files. Once SSO is active, anyone who is removed from your directory automatically loses access to the organization's teams, without you having to manage it manually in Penpot.
+SSO applies to teams and files only. The Admin Console is always accessible without SSO, so you can always reach your configuration to adjust or deactivate it, even if your own directory entry changes.
+ +You can configure SSO with any of the following:
+Clicking the Activate SSO button runs a test connection against your IdP. If the connection fails, your draft is kept and no changes are applied.
+If the test passes, members who are not in your directory will lose access to the organization's teams the moment SSO is activated. Once confirmed, SSO becomes active immediately.
+ +When SSO is activated, any member who is currently inside one of the organization's teams is cut off immediately and sent through the SSO login. This does not log them out of Penpot entirely. They can still reach teams that do not belong to your organization without re-authenticating.
+ +While SSO is active, you can edit any field. As soon as you make a change, Apply changes and Discard changes buttons appear. Discarding restores every field to the current live configuration. Applying runs the same test connection as the initial setup, without a confirmation dialog. If the connection fails, your live configuration is not touched.
+ +Click Deactivate SSO and confirm. The configuration is preserved as a draft so you can reactivate it later without re-entering your credentials. Members are notified by email the first time SSO is activated. If you deactivate and reactivate within 24 hours, the notification is not re-sent.
+ +Members do not need to do anything to prepare. When they next try to access the organization's teams, they will be asked to authenticate through your IdP. If they are already signed in through that provider, the step is skipped automatically.
+Org membership still requires an invitation from you. Being in the directory alone does not grant access to Penpot or to your organization.
+If a member is not in your directory, they remain an org member but cannot enter the organization's teams until they are added. A single email is sent to all current members and pending invitees when SSO is first activated, explaining what changed and who to contact if they cannot get in.
+