01 — Overview
Okta usually arrives at Chamfer as the front door. Connect it for single sign-on over SAML 2.0 or OIDC, turn on SCIM provisioning, and Chamfer creates, updates and deactivates users as your directory changes. Map Okta groups to Chamfer roles, and a new analyst gets the right apps on their first day and loses them the day they leave.
Okta is also a data source. Connect the Okta API with a scoped token and describe the tool, and the Bench builds IT apps on users, groups and application assignments. Quarterly access reviews, onboarding checklists and group request forms become apps with approvals, and group changes made from an app are logged in both Chamfer and Okta’s System Log. SSO is on Business and Enterprise, SCIM is on Enterprise, and the API connection works on every plan.
02 — What you can do
SSO and SCIM
Sign in over SAML 2.0 or OIDC, with users and groups provisioned through SCIM.
Groups become roles
Map Okta groups to Chamfer roles, so app access follows your directory.
IT tools on the API
Build access reviews and request forms on Okta users, groups and apps.
03 — FAQ
Before you connect Okta
Which Chamfer plans include Okta SSO?
What happens when someone leaves?
Can app permissions follow Okta groups?
Can apps change Okta groups?
04 — Pairs well with