Skip to content
KanchanFlow
PlatformPlanned· Q2 2027

SSO — SAML, Okta, Azure AD, Google Workspace

This feature does not exist. SAML single sign-on with Okta, Azure AD and Google Workspace is Wave 2 direction, indicatively Q2 2027, with no committed date.

In short

Single sign-on via SAML with Okta, Azure AD and Google Workspace is not built in KanchanFlow. Authentication today is email and password with multi-factor authentication available. SSO is a Wave 2 item with a Q2 2027 direction and no committed date; our feature matrix lists it under Enterprise as the intended state.

Status card for SSO: planned with no committed date, with the plans it is included in.

Where this actually stands

For a shop of thirty people, email and password with multi-factor authentication is a reasonable answer. For a manufacturer with an IT policy, a joiners-movers-leavers process and an identity provider, it is a procurement objection — and often a legitimate one, because an account that survives someone's departure is a real risk.

SSO is on the Wave 2 list for that reason, targeted at SAML with Okta, Azure AD and Google Workspace. It is not built. If SSO is a hard requirement for you today, we would rather you knew that before a trial than after one. An objection found late in an evaluation wastes your time and ours.

Capabilities

What this would cover if we build it

What is intended

SAML 2.0 single sign-on with Okta, Azure AD and Google Workspace as the named providers, so access follows your identity provider rather than a separate password.

Deprovisioning that actually works

The real value is that removing someone in your identity provider removes their access here. That is the risk email-and-password leaves open.

What exists today

Email and password with multi-factor authentication, role-based permissions, and custom role-based access control on Enterprise.

Enterprise scope

The feature matrix lists SSO under Enterprise. That row describes the intended capability, not a shipping one.

Why we are explicit about this

SSO appears on Enterprise feature matrices across this category, and buyers reasonably assume a row means a shipping capability. Ours describes intent, so we mark it planned here rather than letting a trial discover it.

What SSO would and would not change

It would change how people sign in and how access is removed when they leave. It would not change role-based permissions, which already exist, or the audit log, which is a separate Professional and Enterprise capability being built for Wave 1 Milestone 5.

Step by step

Where the work stands

There is no workflow to walk through yet. This is what the current position actually is.

  1. 1

    Nothing works yet

    There is no SAML implementation and no identity provider integration in the product today.

  2. 2

    Use MFA meanwhile

    Multi-factor authentication is available now and is the practical control until SSO exists.

  3. 3

    Deprovisioning is manual

    Removing a leaver's access is an administrator action in the workspace today. It should be part of your offboarding checklist.

  4. 4

    Status would change here first

    Entering development would put a milestone and a progress figure on this page, with a changelog entry on release.

  5. 5

    What to do in the meantime

    Turn on multi-factor authentication for every user, use role-based permissions to limit what each account can reach, and put workspace deprovisioning explicitly on your offboarding checklist rather than assuming it happens.

What this is not

This is not available today — there is no SAML, no Okta, no Azure AD and no Google Workspace sign-in, on any tier including Enterprise.

This is not an ERP, MRP, CAD, BOM, or advanced CPQ system — it manages customer RFQs, quotes, follow-ups, and order handoff.

Tier availability

What you get on each plan

These rows come from the same feature matrix the pricing page publishes. If the two ever disagree, the matrix is wrong and we fix it.

Tier availability for SSO. Prices and limits are on the pricing page.
PlanAvailability
StarterNot available.
ProfessionalNot available.
EnterprisePlanned for Enterprise. Not built, no committed date.

Starter is $39 per user per month, Professional $49, Enterprise $99 plus a $2,000 monthly platform fee. Annual billing is 17% lower. See the full matrix.

Interface

What it looks like

No capture — nothing built

No screenshot. There is nothing built to capture.

We do not publish mockups of unbuilt features as if they were interface captures.

No capture — nothing built

No screenshot. Multi-factor authentication and role-based permissions are live today.

Placeholder retained so this page's structure matches every other feature page.

Screenshots are described rather than mocked up. Captures are taken from the build current at the date shown in the changelog, on a sample workspace.

Connectors

Integrations this feature uses

Starter includes one accounting connector and one lead source; Professional and Enterprise include all of them. Browse every integration.

Questions about sso

No. The feature matrix lists SSO under Enterprise as the intended capability. It is not built, and no tier has it today.

See a live quote draft built from a real RFQ

Fourteen days, no credit card, sample data pre-loaded. If it does not fit your shop, we will tell you in the first call.

  • Delaware LLC
  • SOC 2 Type II
  • USA Data Centers (AWS)