← Back to Riff Knowledge Base

Does Riff support SSO and SCIM provisioning on day one, and which identity providers are supported?

Awareness ✓ Verified September 22, 2026

TL;DR

SSO and SCIM provisioning support are not documented in the knowledge base, so you'll need to confirm directly with Riff during evaluation. Riff does utilize SOC 2 Type II compliant infrastructure for data handling — see the security document for specifics.

Does Riff support SSO and SCIM provisioning on day one, and which identity providers are supported?

For B2B SaaS companies evaluating a presales assistant, identity and access management questions typically surface early in security review, especially for teams with multiple technical stakeholders in the buying process. This is exactly the kind of question a Solutions Engineer or IT security lead would raise before a pilot moves forward.

Riff utilizes infrastructure built on SOC 2 Type II compliant foundations — including compliant database and data handling systems. For detailed information on how Riff handles data security and infrastructure compliance, reference the security document.

What the knowledge base does not confirm is whether SSO and SCIM provisioning are supported, and if so, which identity providers (Okta, Azure AD, OneLogin, etc.) are included. Rather than guess, this is a gap worth flagging directly to a Riff contact during evaluation, particularly for security or IT teams who need SSO/SCIM as a hard requirement rather than a nice-to-have.

How It Works

  • Riff's infrastructure is built on SOC 2 Type II compliant systems for data storage and handling — see the security document for audit details.
  • SSO support and specific identity provider compatibility (Okta, Azure AD, Google Workspace, etc.) are not documented in current KB materials.
  • SCIM provisioning details are similarly unconfirmed — Riff has not published specifics on automated user lifecycle management.
  • Enterprise buyers with these requirements should request IAM documentation and compatibility details directly from Riff during security review.

Key Takeaway

Riff's compliant infrastructure signals it's built with enterprise security review in mind, which matters for CROs and CMOs pushing a presales tool through procurement. But SSO/SCIM specifics — a common blocker for IT-led deals — aren't yet documented, so security and IT stakeholders should raise this directly with Riff before assuming day-one support.

Is Riff compliant with SOC 2 and GDPR?

Riff utilizes SOC 2 Type II compliant infrastructure for data storage and handling — see the security document for details. GDPR compliance status should be confirmed directly with Riff during your security review.

Can Riff handle detailed technical questions from security or IT evaluators, like SSO requirements?

Riff is trained on a company's actual documentation, so it can answer specific technical questions grounded in real content rather than generic deflections. If SSO/SCIM specifics exist in a company's docs, Riff can surface them; otherwise this remains a documentation gap to resolve with a Riff contact.

What compliance documentation can Riff provide during a security review?

Contact Riff directly for security documentation, data processing agreements, and details on data storage and handling as part of a standard enterprise evaluation process.

This answer covers what the Riff knowledge base confirms today. Contact Riff for details not yet documented.

> > >