SSO and directory sync
Enterprise plan. Owner and Admin. Settings → General.
On Starter or Growth, the card explains that Self-serve SSO and directory sync are on Enterprise. Upgrade in Billing.
If you do not see a Security tab after you open Manage organization, ask Bruchim to enable enterprise SSO for this workspace.
Sign in
After SSO is on, staff use the usual Bruchim sign-in screen with their company login. Bruchim does not host a separate SAML form.
Turn on SSO
- Open the workspace switcher → Manage organization → Security.
- Add your domain, set up SAML or OIDC, test, then turn the connection on.
Only Owners and Admins can open that Security tab.
Directory Sync
After the SSO connection is live, enable Directory Sync (SCIM) on that connection so your identity provider creates, updates, and deactivates people here.
- People from directory sync show a Directory sync badge on Users.
- Full name and Work email show Updated from your identity provider. Title, phone, and host eligibility stay in Bruchim unless the host policy below overwrites hosts.
- Turning someone off in the identity provider deactivates them here and removes app access. They stay in the directory as deactivated.
Turn off “create users during sign-in” (JIT) on that connection if the directory should be the only way accounts appear.
People who join through SSO or directory sync without a Bruchim invite become Employee. Roles such as Owner, Admin, Location Manager, and Reception stay assigned in Users.
Host locations for provisioned people
On the same Settings card, Host locations for provisioned people:
| Choice | What happens |
|---|---|
| All locations | They can host at every site (empty host list). |
| One default location | Host locations and Primary location are that site. |
| From an identity-provider attribute | Map each attribute value to a location. |
Unmapped values use If the value is not mapped (a fallback location, or All locations if you leave it blank).
Directory-synced people get this rule on each sync, including when the attribute changes. People you invited or edited by hand keep the hosts you set, unless they are marked Directory sync.
Map Entra Office (or any attribute)
- In Directory Sync, map Office (or another field) to a Clerk custom attribute, for example
office. - In Bruchim, set Clerk attribute key to that name (
office). - Select Add mapping. Enter the attribute value (for example
Toronto HQ) and the Bruchim location.
The key is the Clerk custom attribute on the user, not the Entra field name.