Sign people in through your identity provider with SAML 2.0 or OIDC, and sync users and groups over SCIM 2.0. Every chat, dashboard, and AI answer then runs under the access your directory groups grant.
14-day trial. No credit card required.
Members
Provisioned by Okta over SCIMPowering analytics for 5000+ teams worldwide
Provisioning
Assign Basedash in Okta or Entra ID and people arrive with their name, title, and groups, no invite email needed. Team changes update their groups, and offboarding deactivates their membership while keeping their work and history.
Okta → Basedash
SCIM 2.0- Ana RuizJoined · Product, Data2m
- Dana KimMoved to Finance18m
- Tom BeckerDeactivated1h
Tom Becker
DeactivatedUnassigned in Okta
- Organization access
- Removed
- Dashboards and charts
- Kept · 6
- Audit history
- Kept
Group-based access
Grant each data source to the groups that should query it, and Basedash enforces it in chat, dashboards, exports, and SQL. On Postgres, row-level security reads the same groups, so an AI answer only covers rows the asker may see.
Manage access · Production Postgres
Everyone in organization
Only the groups and members below can query this source.
- FinanceGroup · 14 members · OktaCan query
- DataGroup · 9 members · OktaCan query
- Lena OkaforMember · [email protected]Can query
Row-level security on Postgres
basedash.groups = 'Finance'create policy invoices_by_group on invoices
for select using (
region = any (string_to_array(
current_setting('basedash.groups', true), ','))
);Single sign-on
Connect Okta, Entra ID, Google Workspace, or any SAML 2.0 or OIDC provider and verify your domain with a DNS record. From then on, everyone on that domain signs in through your IdP, and new hires can join automatically.
Domains
Settings
- acme.comSAML 2.0 · Okta · Auto-join onVerified
- acme.ioSAML 2.0 · OktaVerified
- acme-labs.comWaiting for the DNS TXT recordPending
On the record
Each SCIM create, update, and deactivation is logged with the token that sent it, next to sign-ins, queries, and AI tool calls. Export it to CSV or pull it into your SIEM through the API to answer access reviews.
Audit logs
Today
- scim.user_deactivatedSCIM · Okta production09:42
- scim.group_updatedSCIM · Okta production09:42
- query.executed[email protected]09:38
- ai.tool_executed[email protected]09:37
scim.user_deactivated
- Actor
- SCIM token
- Token
- Okta production
- Target
- [email protected]
- Change
- active: true → false
What's included
SSO and SCIM come with the Enterprise plan, in the cloud or self-hosted, and an organization admin sets both up in Settings.
Enterprise plan
Included with Enterprise, in the cloud or self-hosted.
SAML 2.0 and OIDC
Okta, Entra ID, Google Workspace, OneLogin, and more.
SCIM 2.0
Users, groups, and memberships, with discovery endpoints.
No invite emails
Provisioned people can sign in as soon as they're assigned.
Members by default
SCIM never grants admin; roles stay a Basedash decision.
History kept
Deactivation removes access but keeps dashboards and logs.
Named tokens
Shown once, stored hashed, with last-used dates and revoke.
Works self-hosted
The same endpoints at your own base URL, no extra setup.
“Our selection criteria focused on speed, usability, AI-native exploration, governance, and the ability to move from business question to useful answer without the friction of traditional reporting workflows.”
Amro Alkhatib
AI Strategist · Purpose
Read case study →
“For a security-conscious company like ours, Basedash instantly clicked. Reports that took weeks are ready in hours.”
Claudio Godoy
AI Agents Lead · Taxfyle
Read case study →
Which providers work, what syncs, and how directory groups turn into access in Basedash.
Which identity providers work with Basedash SSO and SCIM?
SSO works with any identity provider that supports SAML 2.0 or OIDC, including Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, Rippling, Ping Identity, and Auth0. SCIM provisioning follows the SCIM 2.0 standard and accepts the request formats Okta and Entra ID send, so those are the most common pairings. Other SCIM 2.0 clients work too, as long as they filter with a single equals condition, since Basedash doesn't support bulk operations, sorting, or ETags.
What does SCIM sync into Basedash?
SCIM syncs users, groups, and group memberships. For each user it carries the email address (the SCIM userName, which can't change after provisioning), first name, display name, job title, active status, and your directory's external ID. Groups are created, renamed, and deleted from the identity provider, and adding or removing someone there updates their Basedash membership. Roles and resource permissions aren't synced: provisioned people join as members, and admins decide in Basedash what each group can access.
How do directory groups map to permissions in Basedash?
Synced groups become Basedash groups, and an admin grants each one access. Data source grants decide who can query a source in chat, dashboards, exports, the SQL editor, and variables, and dashboards can be shared with specific groups. On Postgres, Basedash also passes the asker's groups to the database in the basedash.groups session variable, so row-level security policies filter what every AI answer can read. Customer-facing embeds are scoped by signed tokens instead, as described under embedding.
What happens when someone is offboarded in the identity provider?
When your identity provider deactivates or unassigns someone, it sends a SCIM request and Basedash deactivates their organization membership as soon as it arrives. They lose access to the organization's data, and their open chats are re-scoped right away, so timing depends only on how quickly your provider sends the change. Their dashboards, charts, and audit history stay in place for the team. A SCIM delete also deactivates instead of erasing, re-provisioning the same email restores the same membership, and the last active admin can't be deactivated.
Can we require everyone to sign in through SSO?
Yes. Once SSO is configured for a verified domain, everyone with an email address on that domain has to sign in or sign up through your identity provider. You add the domain in Settings, verify it with a DNS TXT record, and can let people with that domain join the organization automatically. Organizations that don't use SAML can instead require every member to sign in with Google.
Which plans include SSO and SCIM?
SSO and SCIM are part of the Enterprise plan, along with audit logs, and only organization admins can configure them. They're also included in self-hosted deployments, where SCIM uses the same endpoints at your own base URL with no extra environment variables. If SCIM requests return 403 Forbidden, the token is valid but the organization isn't on a plan that includes provisioning. See Enterprise for the rest of the plan, or self-hosting to run Basedash in your own infrastructure.
How do we connect Okta or Microsoft Entra ID over SCIM?
An organization admin opens Settings, then Security, and creates a named SCIM token. It starts with bd_scim_ and is shown only once, since Basedash stores just a hash. In Okta or Entra ID, create a SCIM 2.0 app, set the base URL to https://charts.basedash.com/scim/v2, and use the token as the bearer token. Test the connection, then assign the people and groups that need access. To rotate, create a new token, swap it in, test, and revoke the old one.