SAML Single Sign-On is now fully self-service, and available on the Team plan as well as Company.
The new Authentication panel (Organisation settings → Authentication) allows admins to configure SAML SSO and SCIM provisioning.
Domains are verified using DNS TXT records, and the connection is tested to ensure your IdP is configured correctly, avoiding account lockouts.

You can test the connection to verify your IdP is configured correctly before enforcing SAML SSO for your team.
Once you’ve verified your domain and tested the connection, you can enforce SAML SSO logins for your team, and optionally enable SCIM provisioning to automatically create, update and deactivate accounts from your identity provider.
We’ve also updated our Security and Privacy pages to cover SSO sessions, enforcement and how SSO account data is provisioned.
Read the documentation for more information on how to set up SAML SSO and SCIM provisioning for your organisation.