Skip to main content
Identity Sync pulls users, groups, and group membership from your identity provider into Oso, so a policy can scope to a specific person or group instead of (or alongside) a tool, integration, or agent.

Supported providers

Okta is supported today. See Okta to connect your organization.

Using synced identity in a policy

Once connected, users and groups become available as a condition when writing a policy - for example, alerting on any tool call from someone in your Engineering group, or blocking writes from a specific person. Changes to group membership in your identity provider take effect the next time Oso syncs, which can take a few minutes.