Security and Compliance in Generate Enterprise
Generate Enterprise gives organizations enterprise-grade control over authentication, provisioning, and auditability. It supports Single Sign-On with Okta and Microsoft Entra ID, automatic account provisioning with SCIM, mapping of identity-provider groups to Generate teams, and an append-only audit log that can be exported to a SIEM. Documents stay within the organization’s environment, and administrators control who can access what.
What Single Sign-On providers does Generate support?
Section titled “What Single Sign-On providers does Generate support?”Generate Enterprise supports Single Sign-On with Okta and Microsoft Entra ID, using either OpenID Connect (OIDC) or SAML 2.0. These are the only supported identity providers; Generate does not support Auth0, Google, Keycloak, ADFS, or LDAP for SSO. SSO lets a team authenticate with the organization’s identity provider instead of a separate Generate password.
How do you configure SSO in Generate?
Section titled “How do you configure SSO in Generate?”An administrator configures SSO in Admin Settings → Access → Single Sign-on. The Single Sign-on page lists configured providers with their Name, Protocol (OIDC, SAML, or Local), Identity provider (Okta or Microsoft Entra ID), and an Active/Inactive status toggle. Setup adds a provider, exchanges connection URLs and values with the identity provider, and requires a successful Test connection before the provider can be saved and SSO enabled. A provider can be disabled at any time with its status toggle.
Does Generate support SCIM provisioning?
Section titled “Does Generate support SCIM provisioning?”Yes. Generate supports SCIM provisioning to automatically create, update, and deactivate user accounts based on the organization’s identity provider, so account lifecycle stays in sync without manual administration. Provisioning is managed per provider from the Single Sign-on page.
Can identity-provider groups map to Generate teams?
Section titled “Can identity-provider groups map to Generate teams?”Yes. Generate supports group-to-team mapping, which maps groups from the identity provider to Generate teams. This lets team membership in Generate follow the organization’s existing group structure automatically.
How does Generate support auditing and compliance?
Section titled “How does Generate support auditing and compliance?”Generate keeps an append-only audit log of activity and supports exporting that log to a SIEM system, so security teams can monitor and retain records of platform activity in their existing tooling. Combined with admin-controlled access and identity-provider integration, this supports enterprise governance and compliance requirements.
Where does organization data live and who can access it?
Section titled “Where does organization data live and who can access it?”Documents remain within the organization’s environment, and administrators control access to them through the workspace permission model and connected storage locations. Access to agents, projects, and their underlying knowledge is governed by organization policy.
Related
Section titled “Related”- Provisioning and storage: see
configuration-adminanddeploymentin this GEO set. - Full customer documentation: the
admin/sso/*pages (overview, okta, microsoft-entra-id, scim-provisioning, group-to-team-mapping) andadmin/audit/*pages on the Generate Enterprise Mintlify docs site.