Enterprise Controls
API paths that contain tenant keep that word for compatibility. In the product it means your workspace.
Enterprise Controls is the Enterprise plan's home for identity and residency: connect your company single sign-on, let your identity provider create and deactivate users automatically, see who holds which workspace role, and manage where your data lives. Open it at #/enterprise-controls. On other plans the page shows an upgrade panel instead.
Who this is for
- Enterprise workspace owners and admins connecting company identity.
- IT and IAM teams that manage SSO and provisioning from Okta, Microsoft Entra ID, or another IdP.
- Compliance owners who need the data-residency posture on record.
Role-based start here
- Workspace Owner: start with Before you start, then run Step-by-step for SSO.
- IAM engineer: go straight to Step-by-step (SSO, then SCIM) and API and automation.
- Compliance owner: read the Regions part of What each button does and Day-2 operations.
Before you start
- Your workspace must be on the Enterprise plan.
- Have your IdP's SAML values ready: entity ID, sign-in URL (https), and the signing certificate (PEM).
- Decide which team members should hold Owner and Admin roles before you turn on provisioning.
Step-by-step
- Open
#/enterprise-controls. - Connect SSO: open the Single Sign-On tab, copy your ACS URL into your IdP's SAML application, then paste the IdP entity ID, sign-in URL, and signing certificate into the form and select Connect SSO.
- Test sign-in from a private window before rolling it out to the team.
- Enable SCIM: open the SCIM Provisioning tab and select Enable SCIM and issue token. Copy the token into your IdP immediately; it is shown only once.
- Point your IdP's SCIM app at the SCIM base URL shown on the tab.
- Review roles: the Overview tab lists your workspace role groups with live member counts.
- Regions: the Regions tab shows your current region; submit a change request if you need a different one.
Day-2 operations
- Rotate the SCIM token on your credential schedule; issuing a new token revokes the old one immediately.
- After IdP changes (certificate rollover, new sign-in URL), update the SSO form with the new values.
- Check the Overview role counts after onboarding waves to confirm provisioning matched expectations.
Self-check playbook
- Sign in through your IdP from a private window and confirm you land in the right workspace.
- Create a test user in your IdP and confirm it appears in the workspace Members group.
- Deactivate the test user in your IdP and confirm the account is disabled in Dralvia.
- Confirm the Regions tab shows the region your contract specifies.
What each button does
- Connect SSO / Update SSO: saves your SAML identity provider so team sign-in uses company credentials.
- Disconnect: removes the SSO connection; local Dralvia sign-in keeps working.
- Enable SCIM and issue token / Rotate SCIM token: issues the workspace provisioning token (shown once) and revokes any previous token.
- Request region change: opens a support-tracked request; Dralvia support executes region moves inside an agreed migration window.
- Refresh: re-pulls the live SSO, provisioning, role, and region state.
Troubleshooting
- SSO save fails: check the sign-in URL is https and the certificate is the IdP's signing certificate in PEM form.
- Sign-in loops after connecting SSO: confirm the ACS URL registered in your IdP matches the one shown on the tab exactly.
- Provisioned users do not appear: confirm the SCIM token is current (rotating revokes old tokens) and your IdP targets the SCIM base URL from the tab.
- Page shows an upgrade panel: your workspace is not on the Enterprise plan; compare plans on the pricing page.
API and automation
GET /enterprise/controls/summary: SSO, SCIM, role, and region posture in one call.POST /enterprise/sso/samlandDELETE /enterprise/sso/saml: manage the SAML connection.POST /enterprise/scim/token: issue or rotate the SCIM token.- SCIM 2.0 endpoints under
/api/scim/v2:GET /Users,POST /Users,GET /Users/{id}, andPATCH /Users/{id}with areplaceofactive. Authenticate withAuthorization: Bearer <SCIM token>. POST /enterprise/regions/request: submit a region change request.
Supported SCIM operations today: list users, create users, read a user, and deactivate via active=false. Group sync and other PATCH operations are not supported yet and are safely rejected.
Next best actions
- Connect SSO first, verify sign-in, then enable SCIM so accounts stay in sync automatically. See Self-Registration for how new members join once SSO is live.
- Record your region posture in your compliance evidence alongside your EvidencePack exports. See Compliance.
- Remove standing passwords for provisioned users once SSO is confirmed working, then review who holds which role in License Management.
FAQ
- Which IdPs work? Any SAML 2.0 identity provider (Okta, Microsoft Entra ID, Google Workspace SAML apps, and others).
- Is the SCIM token shown again later? No. It is shown once at issue time; rotate it if it is lost.
- Can I move regions myself? No. Region moves change where data lives, so Dralvia support executes them inside an agreed window after your request.
- What happens on other plans? The page shows which plan includes Enterprise Controls and how to upgrade; no controls render.
Next steps
- Pricing & Plans for what each plan unlocks.
- API Keys for programmatic access beyond provisioning.
- Compliance for evidence and audit alignment.
API error quick reference
| Error | Meaning | What to do now |
|---|---|---|
401 Unauthorized | Session token is missing, expired, or invalid. | Sign out and back in, then retry once. |
403 Forbidden | Your plan or role does not include this action (enterprise_required). | Upgrade to Enterprise or ask your workspace owner. |
404 Not Found | The resource (for example a SCIM user id) was not found. | Confirm the id and retry. |
429 Too Many Requests | Rate limit or quota window exceeded. | Wait for cooldown, then retry with backoff. |
500 Internal Server Error | The backend failed unexpectedly. | Retry after a short wait. If it repeats, escalate with your workspace ID and UTC time. |
Known limits and rate limits
- Enterprise Controls are available on the Enterprise plan only. On other plans the page explains what the controls do and how to upgrade, and no controls render.
- SCIM provisioning is user and group scoped. Nested groups are flattened to their direct members.
- A SCIM sync reflects what your identity provider sends. Members removed there are deprovisioned in Dralvia, but members you add directly in Dralvia are not written back to your provider.
- Region moves change where your data lives, so they are executed by Dralvia support inside an agreed window rather than self-served.
- Provisioning endpoints share the standard workspace rate limit. A
429means the window is exhausted: wait for the cooldown and retry with backoff rather than looping.