Prerequisites
You must have an Admin or Owner role in elvex
Your company must have an active SAML/SSO connection configured
Step 0. Make sure your identity provider (IdP) has a groups attribute mapping
Your identity provider (Okta, Google, EntraID, etc) must be configured to send a "groups" attribute with relevant role data in order for an elvex group to be aligned with a preexisting department or employee role category in your IdP.
Eg. You want new brand marketing, growth marketing and international marketing employees to be added to the elvex Marketing group. Before you do anything in elvex, you will need your IdP administrator to create an attribute with key "groups" and list the team values that you are already tracking in your IdP.
Understanding the setup as an elvex admin
Before you begin, you'll need to know:
What attribute values your IdP sends - Check with your IdP administrator to see what values are included in the "groups" attribute (e.g., "Engineering", "Marketing", "Sales")
Which elvex groups you want to map to - You can map to previously created groups or as you build new ones
What role users should automatically have in each group - Editor or Viewer
Creating a SAML attribute group from the Groups page
Navigate to edit the group
Select the Idp Configuration tab and click Manage Groups
Click Create in the Manage SAML Attribute Groups modal
Name your elvex mapping
Enter the SAML attribute values from your IdP that should trigger this mapping
Add one or more values that match what your IdP sends (e.g., "Engineering", "AWS Users")
These values are case-sensitive and must match your IdP exactly
Click Create
Associating a SAML attribute group with an elvex group
Open the elvex group you want to associate with a SAML attribute group
Select the IdP Configuration tab
Select the SAML attribute group you created in the dropdown
Choose the role users will receive in this group:
Editor: Can add and remove group members
Viewer: Can only view the group and its members
Click Save
Creating a SAML attribute group from the SAML settings page
Navigate to Settings > SAML
Click Manage Groups in the just-in-time provisioning section
Click Create in the Manage SAML Attribute Groups modal
Enter the attribute values from your IdP that should trigger this mapping
Click Create
Creating a role assignment by SAML attribute group
Navigate to Settings > SAML
In the just-in-time provisioning section, select the SAML attribute group you created in the dropdown
Choose the company role users will receive when they are provisioned:
Member
Creator
Admin
Click Activate/update SAML Connection


