Enterprise · SSO setup

Single sign-on for your whole organization.

Microsoft Entra or Google Workspace, no SAML metadata required. Once configured, anyone on your domain auto-joins your limena workspace at the role you set.

At a glance

  • OAuth 2.0 + OIDC — works with every Microsoft 365 and Google Workspace tenant.
  • Domain auto-join on the Public tier.
  • No password ever touches limena.
  • Five minutes to set up.

How limena SSO works

limena uses standard OAuth 2.0 + OpenID Connect for sign-in. You don't need to deploy a SAML metadata file or stand up an Enterprise Application — every Microsoft 365 / Entra tenant and every Google Workspace tenant can sign users into limena out of the box.

The Enterprise-tier piece is domain auto-join: a workspace owner claims their email domain in limena Settings. After that, anyone in your organization who signs in to limena using their work email lands directly in your workspace with the default role you set — typically Viewer for most staff, Editor for the accessibility team.

Setup steps

1. Sign in to limena as a workspace owner

Go to console.limena.app/signin and sign in with your Microsoft (or Google) work account. The email you sign in with becomes the claim signal for your domain in step 3.

2. Verify you're on the Public tier

SSO domain auto-join is included on the Public tier. Lower tiers support per-user OAuth sign-in but don't auto-add new sign-ins to your workspace.

3. Claim your email domain

Go to Settings → SSO. In the "Add a domain" field, enter your organization's email domain — e.g. acme.com — and click Add.

limena verifies that your own sign-in email matches the domain you're claiming. If you signed in as jane@acme.com, you can claim acme.com. You can't claim a domain you don't have a verified email at — this prevents domain hijacking.

4. Set the default role

Pick the role new sign-ins from your domain receive automatically:

  • Viewer — can see findings and reports; can't push to trackers or change settings. Right for most staff.
  • Editor — full read/write inside the workspace except billing and team management. Right for the accessibility team.
  • Admin — including billing and team management. Reserve for owners.

You can change any individual member's role later from the Team tab.

5. (Optional) Restrict your Entra app to limena

If your security policy requires explicit per-app SSO authorization, your Entra administrator can register limena in your tenant's Enterprise Applications list:

  1. Sign in to portal.azure.com as a Global Administrator
  2. Microsoft Entra ID → Enterprise applications → New application → Non-gallery
  3. Name: limena
  4. Sign-on URL: https://console.limena.app/signin
  5. (Optional) Restrict access via the Users and groups assignment list

This step is OPTIONAL — limena works without it for any user with a Microsoft account at your claimed domain. It's only needed if your tenant policy requires explicit app authorization.

What happens when a new user signs in

  1. User goes to console.limena.app/signin
  2. Clicks Sign in with Microsoft (or Google)
  3. Microsoft authenticates them against your tenant
  4. limena receives the verified email + tenant id from Microsoft
  5. If their email domain matches a workspace's claimed domain, they auto-join that workspace with the default role
  6. If no match, they're prompted to create their own personal workspace (or accept an invitation if one's pending)

Data residency

OAuth flows redirect through Microsoft (or Google) directly — limena never sees the user's password or any directory data beyond the verified email, display name, and tenant id. The authentication round-trip happens between the user's browser and Microsoft; limena stores only the resulting verified email.

All other limena data (audit results, findings, integration tokens) lives in Supabase's Canada Central region (Montreal). See Privacy for the full data-residency posture.

Revoking access

When an employee leaves your organization, their Microsoft account is deprovisioned by your IT team in the normal way — they immediately lose the ability to sign into limena. Their existing membership in your limena workspace remains (so their annotations, audits, and history aren't orphaned) but they can no longer authenticate.

A workspace admin can remove their limena membership entirely from the Team tab.

SAML support

limena currently uses OAuth 2.0 + OpenID Connect, which works with every Microsoft Entra / Google Workspace tenant. Full SAML support (for organizations that require it explicitly) is on the Enterprise roadmap. Contact ryan@limena.app if your procurement requires SAML.

Questions

Email ryan@limena.app — we respond within one business day.

Ready to set it up?

The free trial includes the full Enterprise feature set so you can verify SSO against your tenant before signing.