SSO — SAML, Okta, Azure AD, Google Workspace
This feature does not exist. SAML single sign-on with Okta, Azure AD and Google Workspace is Wave 2 direction, indicatively Q2 2027, with no committed date.
In short
Single sign-on via SAML with Okta, Azure AD and Google Workspace is not built in KanchanFlow. Authentication today is email and password with multi-factor authentication available. SSO is a Wave 2 item with a Q2 2027 direction and no committed date; our feature matrix lists it under Enterprise as the intended state.
Where this actually stands
For a shop of thirty people, email and password with multi-factor authentication is a reasonable answer. For a manufacturer with an IT policy, a joiners-movers-leavers process and an identity provider, it is a procurement objection — and often a legitimate one, because an account that survives someone's departure is a real risk.
SSO is on the Wave 2 list for that reason, targeted at SAML with Okta, Azure AD and Google Workspace. It is not built. If SSO is a hard requirement for you today, we would rather you knew that before a trial than after one. An objection found late in an evaluation wastes your time and ours.
Capabilities
What this would cover if we build it
What is intended
SAML 2.0 single sign-on with Okta, Azure AD and Google Workspace as the named providers, so access follows your identity provider rather than a separate password.
Deprovisioning that actually works
The real value is that removing someone in your identity provider removes their access here. That is the risk email-and-password leaves open.
What exists today
Email and password with multi-factor authentication, role-based permissions, and custom role-based access control on Enterprise.
Enterprise scope
The feature matrix lists SSO under Enterprise. That row describes the intended capability, not a shipping one.
Why we are explicit about this
SSO appears on Enterprise feature matrices across this category, and buyers reasonably assume a row means a shipping capability. Ours describes intent, so we mark it planned here rather than letting a trial discover it.
What SSO would and would not change
It would change how people sign in and how access is removed when they leave. It would not change role-based permissions, which already exist, or the audit log, which is a separate Professional and Enterprise capability being built for Wave 1 Milestone 5.
Step by step
Where the work stands
There is no workflow to walk through yet. This is what the current position actually is.
- 1
Nothing works yet
There is no SAML implementation and no identity provider integration in the product today.
- 2
Use MFA meanwhile
Multi-factor authentication is available now and is the practical control until SSO exists.
- 3
Deprovisioning is manual
Removing a leaver's access is an administrator action in the workspace today. It should be part of your offboarding checklist.
- 4
Status would change here first
Entering development would put a milestone and a progress figure on this page, with a changelog entry on release.
- 5
What to do in the meantime
Turn on multi-factor authentication for every user, use role-based permissions to limit what each account can reach, and put workspace deprovisioning explicitly on your offboarding checklist rather than assuming it happens.
What this is not
This is not available today — there is no SAML, no Okta, no Azure AD and no Google Workspace sign-in, on any tier including Enterprise.
This is not an ERP, MRP, CAD, BOM, or advanced CPQ system — it manages customer RFQs, quotes, follow-ups, and order handoff.
Tier availability
What you get on each plan
These rows come from the same feature matrix the pricing page publishes. If the two ever disagree, the matrix is wrong and we fix it.
| Plan | Availability |
|---|---|
| Starter | Not available. |
| Professional | Not available. |
| Enterprise | Planned for Enterprise. Not built, no committed date. |
Starter is $39 per user per month, Professional $49, Enterprise $99 plus a $2,000 monthly platform fee. Annual billing is 17% lower. See the full matrix.
Interface
What it looks like
No screenshot. There is nothing built to capture.
We do not publish mockups of unbuilt features as if they were interface captures.
No screenshot. Multi-factor authentication and role-based permissions are live today.
Placeholder retained so this page's structure matches every other feature page.
Screenshots are described rather than mocked up. Captures are taken from the build current at the date shown in the changelog, on a sample workspace.
Connectors
Integrations this feature uses
Starter includes one accounting connector and one lead source; Professional and Enterprise include all of them. Browse every integration.
Questions about sso
No. The feature matrix lists SSO under Enterprise as the intended capability. It is not built, and no tier has it today.
Related features
Multi-company and multi-plant
Multi-company and multi-plant
Read moreOn-premise deployment
On-premise deployment
Read moreImmutable audit log
Immutable audit log for compliance-driven manufacturers
Read moreWhat's shipping today
All 47 features grouped by status on one page, with the newest releases alongside.
Read moreSee a live quote draft built from a real RFQ
Fourteen days, no credit card, sample data pre-loaded. If it does not fit your shop, we will tell you in the first call.
- Delaware LLC
- SOC 2 Type II
- USA Data Centers (AWS)