Team & Access

Control who can do what — roles, 2FA, SSO via OIDC or SAML, group-to-role mappings, and SCIM provisioning.

Most of this section is one-time setup that pays off forever: get identity and access right and the rest of governance becomes routine. The guides move from roles and 2FA through single sign-on (OIDC, SAML, group→role mappings) to SCIM provisioning — so your IdP drives who has access and who gets deprovisioned.

Let your IdP be the source of truth. Once SSO plus group→role mappings plus SCIM are in place, joiners and leavers are handled by your directory — no manual account churn in Chainsaw.

Where to next

To issue and rotate credentials for AI agents (a peer of human access), see AI Assistant (Billy) & Agents; for service-token credentials, see Getting Started.