Prerequisites
- An Okta admin account with permission to configure application provisioning.
- A ClosedLoop AI workspace admin account.
- Your ClosedLoop AI workspace ID.
- Your ClosedLoop AI workspace region: US or EU.
- The ClosedLoop AI Okta OIDC SSO setup should be configured before assigning users through SCIM.
- An Okta Identity Governance subscription if you want to manage role entitlements.
Supported Features
ClosedLoop AI treats Okta as the source of truth for provisioned users, group membership, access status, and assigned role entitlements.
Configure Okta
Step 1: Add ClosedLoop AI from the Okta catalog
Step 1: Add ClosedLoop AI from the Okta catalog
- In Okta Admin, go to Applications > Applications.
- Click Browse App Catalog.
- Search for ClosedLoop AI.
- Add the ClosedLoop AI integration.
Step 2: Enter tenant settings
Step 2: Enter tenant settings
Enter the tenant settings for the ClosedLoop AI workspace you are connecting.
Use
us for https://app.closedloop.sh. Use eu for https://eu.app.closedloop.sh.Step 3 (optional): Enable Entitlement Management
Step 3 (optional): Enable Entitlement Management
Complete this step only if your organization uses Okta Identity Governance to manage ClosedLoop AI workspace roles.
- Open the generated ClosedLoop AI app instance in Okta.
- Go to the General tab.
- In the Entitlement Management or Identity Governance section, click Edit.
- Set Entitlement Management or Governance Engine to Enabled.
- Click Save, then refresh the page until the Governance tab appears.
Step 4: Enable API integration
Step 4: Enable API integration
- Open the generated ClosedLoop AI app instance in Okta.
- Go to Provisioning > Integration.
- Click Configure API Integration.
- Select Enable API integration.
- Click Authenticate with ClosedLoop AI.
- Complete the authentication flow.
- Click Test API Credentials.
- Click Save.
Step 5: Enable provisioning operations
Step 5: Enable provisioning operations
In Provisioning > To App, enable:
In Provisioning > To Okta, imports may remain enabled so Okta can import users and profile updates from ClosedLoop AI.
Step 6: Configure username format
Step 6: Configure username format
On the Sign On tab, set Application username format to Email.ClosedLoop AI uses the SCIM
userName value as the user’s primary email address.Step 7: Assign users and groups
Step 7: Assign users and groups
Assign users or groups to the ClosedLoop AI app in Okta.Okta creates or links the user in ClosedLoop AI when the app is assigned. Deactivating the Okta user or unassigning the app removes the user’s ClosedLoop AI workspace access and revokes active sessions.
Okta OIN Values
These are the SCIM values used by the ClosedLoop AI Okta catalog integration.SCIM Attribute Mappings
Keep these mappings in the Okta app profile.
ClosedLoop AI does not use these default Okta profile attributes. Remove the mappings and attributes if they appear in the app profile:
Group Push
ClosedLoop AI supports Okta Group Push.- In Okta, open the ClosedLoop AI app instance.
- Go to Push Groups.
- Add the Okta group you want to push.
- Confirm the group appears in ClosedLoop AI after Okta pushes it.
- Users must be assigned to the ClosedLoop AI app and provisioned through SCIM before they can be added as members of a pushed group.
- ClosedLoop AI stores the Okta group
displayName,externalId, and members. - Group names should be unique within one ClosedLoop AI workspace.
- Removing a user from a pushed group removes that group membership in ClosedLoop AI. It does not delete the user.
Role Entitlements
ClosedLoop AI exposes workspace roles as Okta entitlements. Role entitlements require Okta Identity Governance and the Entitlement Management setup described in Step 3. Resource type mapping:
Entitlement details:
Entitlement values:
ClosedLoop AI supports one workspace role entitlement per user. If no role entitlement is assigned, users are provisioned as Member by default.
Verify Provisioning
- Assign a test user to the ClosedLoop AI app in Okta.
- Confirm Okta creates the user in ClosedLoop AI.
- Update the test user’s first name or last name in Okta and run provisioning.
- Confirm the profile update appears in ClosedLoop AI.
- Push a test group that contains the provisioned user.
- Confirm the group and membership appear in ClosedLoop AI.
- Assign the Admin role entitlement to the test user.
- Confirm the user becomes an admin in ClosedLoop AI.
- Unassign or deactivate the test user in Okta.
- Confirm the user’s ClosedLoop AI workspace access is removed.
Troubleshooting
Support
For help configuring Okta SCIM provisioning with ClosedLoop AI, contactsupport@closedloop.sh.