SAML is enabling different enterprise systems to communicate securely and share user details, such as user attributes, groups they are members of, and supports Just-in-Time (JIT) Provisioning.
Clerk’s Organizations and verified domains can help streamline the onboarding experience for SAML enterprise users while reducing stress on IT and support.
Verified domains can be configured to automatically enroll new enterprise users to the application, providing a delightful experience for those users.
With Clerk organizations, users using an email address with the verified domain will be automatically invited to join an organization in your application without further action from IT.
Before configuring SAML using Google Workspace, you need an active Clerk account, and a Google Workspace account.
To configure SAML: create a connection in the Clerk Dashboard sidebar, access your Google Workspace Admin panel, add the app, populate App Name, Download Metadata, and back in Clerk Dashboard locate Identity Provider Configuration section.
Attribute mapping explains to Google Workspace which of its user attributes map with the attributes in Clerk and it can be set by adding mapping.
To enable automatic enrollment within your application start by enabling Organizations and toggling on Unlimited membership, Enable verified domains, and Automatic invitation.
Verified domains can be added in the General view by the admins where they can also specify their preferred enrollment settings.
The result is a simplified experience for your customers, their support teams, and their users!