Skip to main content
Okta sends Cimento the people and groups you assign to the Cimento AI app and keeps them up to date over SCIM. The same app sets up SAML single sign-on, so assigned employees sign in to Cimento through Okta.

Before you start

  • An Okta Super Administrator or Application Administrator, to add the app and configure provisioning.
  • A Cimento user with the Admin role, to reveal the API token in step 4. Integrations admins can do every other step.
  • Your organization’s email domains registered with Cimento. Single sign-on only covers those domains, so ask your Cimento contact to add any that are missing.
Your organization connects one directory, and switching to another later needs Cimento support. As soon as you click Begin Setup, employees come from Okta: you can no longer add or upload employees in Cimento, or edit their names, email addresses, status or departments.

Steps

1

Start setup in Cimento

Go to Admin → Integrations → Employee data. Under Directory provider, choose Okta and click Begin Setup. The setup guide opens at Add Application.
2

Add the Cimento AI app in Okta

Click Open Okta Integration Network to open the Cimento AI app. Signed in as an Okta admin, click Add Integration and follow the prompts. On the app’s Assignments tab, assign the people and groups who should be in Cimento. Back in Cimento, click Next.
3

Connect single sign-on

In the Okta Admin Console, open Applications, select Cimento AI and open the Sign On tab. Copy the Metadata URL from the SAML section. Paste it into the Metadata URL step in Cimento and click Save configuration. When Cimento shows SSO configured, people who sign in to Cimento with an address in your domains are sent to Okta.
4

Turn on provisioning

In Okta, open the app’s Provisioning tab, click Configure API Integration and check Enable API integration. In Cimento’s Provisioning step, click Copy next to API Token and paste it into Okta’s API Token field. If Okta also shows a Base URL field, copy that value from Cimento as well. Click Test API Credentials, then Save.
5

Choose what Okta sends

Under Provisioning › To App, click Edit, enable Create Users, Update User Attributes and Deactivate Users, and save. To send groups, open the Push Groups tab and push the groups you want in Cimento. Assigning a group only provisions its members; pushing it creates the group in Cimento.
6

Verify

In Cimento’s Verify step, click Test connection. It checks that single sign-on is live and activates the integration. Okta’s Test API Credentials in step 4 is the check for provisioning.

If something goes wrong

What Okta sends

Cimento uses each employee’s primary email, name, title, department, manager and phone numbers, and mirrors the groups you push. See What Okta and Microsoft Entra ID send for how each attribute maps and what happens when someone leaves.

Stop provisioning

The API token lets Okta create, update and deactivate employees in Cimento, so store it like a password. To stop Okta from updating Cimento, uncheck Enable API integration on the app’s Provisioning tab, or remove the Cimento AI app from Okta.