The two-sided SSO handshake
SAML SSO needs matching details on both sides. LAWDE is the service provider (SP). Your company directory (Okta, Microsoft Entra ID, Google Workspace, and similar) is the identity provider (IdP).
| Side | Who | What they do |
|---|
| Your IT | IdP admin | Create a SAML app, paste LAWDE ACS URL / Entity ID / metadata URL, assign users, then give LAWDE the IdP metadata XML or metadata URL |
| LAWDE | Workspace owner | Open Settings → Enterprise, paste domains and metadata, test the connection, then enable |
Owner steps in LAWDE
- Copy the ACS URL, SP metadata URL, and Entity ID from Settings → Enterprise and send them to IT.
- When IT returns metadata, paste XML or a metadata URL, list email domains (comma separated), and click test.
- Enable the provider once the test passes.
- Optionally turn on enforce SSO-only so listed domains must use company login instead of password or personal OAuth.
Sales-led enablement is still available from the Enterprise page if you are not on the plan yet.
Retention override
Default retention follows the plan (Hobby 7 days, Pro 90, Business 180, Enterprise unlimited). Enterprise owners can set a custom window or keep unlimited from the same Enterprise settings page. This changes how long error history is kept — it does not rewrite audit logs.
Compliance pack
The public pack is at /enterprise/compliance. It describes architecture, subprocessors, and roadmap certifications honestly (SOC 2 / HIPAA are not claimed as current attestations). Owners can also download markdown from Enterprise settings.
Delegated admin roles
On Enterprise, owners can grant extra permissions to trusted members from Team settings without making them owners:
- Rotate API keys
- Manage team (invite)
- Manage billing
- Manage GitHub / Beacon
- View audit logs
Business workspaces still use owner / admin / member roles only. Related: Audit logs · Pricing tiers · Documentation home