Skip to main content

Enterprise Controls

note

API paths that contain tenant keep that word for compatibility. In the product it means your workspace.

Enterprise Controls is the Enterprise plan's home for identity and residency: connect your company single sign-on, let your identity provider create and deactivate users automatically, see who holds which workspace role, and manage where your data lives. Open it at #/enterprise-controls. On other plans the page shows an upgrade panel instead.

Who this is for​

  • Enterprise workspace owners and admins connecting company identity.
  • IT and IAM teams that manage SSO and provisioning from Okta, Microsoft Entra ID, or another IdP.
  • Compliance owners who need the data-residency posture on record.

Role-based start here​

  • Workspace Owner: start with Before you start, then run Step-by-step for SSO.
  • IAM engineer: go straight to Step-by-step (SSO, then SCIM) and API and automation.
  • Compliance owner: read the Regions part of What each button does and Day-2 operations.

Before you start​

  • Your workspace must be on the Enterprise plan.
  • Have your IdP's SAML values ready: entity ID, sign-in URL (https), and the signing certificate (PEM).
  • Decide which team members should hold Owner and Admin roles before you turn on provisioning.

Step-by-step​

  1. Open #/enterprise-controls.
  2. Connect SSO: open the Single Sign-On tab, copy your ACS URL into your IdP's SAML application, then paste the IdP entity ID, sign-in URL, and signing certificate into the form and select Connect SSO.
  3. Test sign-in from a private window before rolling it out to the team.
  4. Enable SCIM: open the SCIM Provisioning tab and select Enable SCIM and issue token. Copy the token into your IdP immediately; it is shown only once.
  5. Point your IdP's SCIM app at the SCIM base URL shown on the tab.
  6. Review roles: the Overview tab lists your workspace role groups with live member counts.
  7. Regions: the Regions tab shows your current region; submit a change request if you need a different one.

Day-2 operations​

  • Rotate the SCIM token on your credential schedule; issuing a new token revokes the old one immediately.
  • After IdP changes (certificate rollover, new sign-in URL), update the SSO form with the new values.
  • Check the Overview role counts after onboarding waves to confirm provisioning matched expectations.

Self-check playbook​

  1. Sign in through your IdP from a private window and confirm you land in the right workspace.
  2. Create a test user in your IdP and confirm it appears in the workspace Members group.
  3. Deactivate the test user in your IdP and confirm the account is disabled in Dralvia.
  4. Confirm the Regions tab shows the region your contract specifies.

What each button does​

  • Connect SSO / Update SSO: saves your SAML identity provider so team sign-in uses company credentials.
  • Disconnect: removes the SSO connection; local Dralvia sign-in keeps working.
  • Enable SCIM and issue token / Rotate SCIM token: issues the workspace provisioning token (shown once) and revokes any previous token.
  • Request region change: opens a support-tracked request; Dralvia support executes region moves inside an agreed migration window.
  • Refresh: re-pulls the live SSO, provisioning, role, and region state.

Troubleshooting​

  • SSO save fails: check the sign-in URL is https and the certificate is the IdP's signing certificate in PEM form.
  • Sign-in loops after connecting SSO: confirm the ACS URL registered in your IdP matches the one shown on the tab exactly.
  • Provisioned users do not appear: confirm the SCIM token is current (rotating revokes old tokens) and your IdP targets the SCIM base URL from the tab.
  • Page shows an upgrade panel: your workspace is not on the Enterprise plan; compare plans on the pricing page.

API and automation​

  • GET /enterprise/controls/summary: SSO, SCIM, role, and region posture in one call.
  • POST /enterprise/sso/saml and DELETE /enterprise/sso/saml: manage the SAML connection.
  • POST /enterprise/scim/token: issue or rotate the SCIM token.
  • SCIM 2.0 endpoints under /api/scim/v2: GET /Users, POST /Users, GET /Users/{id}, and PATCH /Users/{id} with a replace of active. Authenticate with Authorization: Bearer <SCIM token>.
  • POST /enterprise/regions/request: submit a region change request.

Supported SCIM operations today: list users, create users, read a user, and deactivate via active=false. Group sync and other PATCH operations are not supported yet and are safely rejected.

Next best actions​

  • Connect SSO first, verify sign-in, then enable SCIM so accounts stay in sync automatically. See Self-Registration for how new members join once SSO is live.
  • Record your region posture in your compliance evidence alongside your EvidencePack exports. See Compliance.
  • Remove standing passwords for provisioned users once SSO is confirmed working, then review who holds which role in License Management.

FAQ​

  • Which IdPs work? Any SAML 2.0 identity provider (Okta, Microsoft Entra ID, Google Workspace SAML apps, and others).
  • Is the SCIM token shown again later? No. It is shown once at issue time; rotate it if it is lost.
  • Can I move regions myself? No. Region moves change where data lives, so Dralvia support executes them inside an agreed window after your request.
  • What happens on other plans? The page shows which plan includes Enterprise Controls and how to upgrade; no controls render.

Next steps​

API error quick reference​

ErrorMeaningWhat to do now
401 UnauthorizedSession token is missing, expired, or invalid.Sign out and back in, then retry once.
403 ForbiddenYour plan or role does not include this action (enterprise_required).Upgrade to Enterprise or ask your workspace owner.
404 Not FoundThe resource (for example a SCIM user id) was not found.Confirm the id and retry.
429 Too Many RequestsRate limit or quota window exceeded.Wait for cooldown, then retry with backoff.
500 Internal Server ErrorThe backend failed unexpectedly.Retry after a short wait. If it repeats, escalate with your workspace ID and UTC time.

Known limits and rate limits​

  • Enterprise Controls are available on the Enterprise plan only. On other plans the page explains what the controls do and how to upgrade, and no controls render.
  • SCIM provisioning is user and group scoped. Nested groups are flattened to their direct members.
  • A SCIM sync reflects what your identity provider sends. Members removed there are deprovisioned in Dralvia, but members you add directly in Dralvia are not written back to your provider.
  • Region moves change where your data lives, so they are executed by Dralvia support inside an agreed window rather than self-served.
  • Provisioning endpoints share the standard workspace rate limit. A 429 means the window is exhausted: wait for the cooldown and retry with backoff rather than looping.