Skip to main content

SSO and directory sync

Enterprise plan. Owner and Admin. Settings → General.

On Starter or Growth, the card explains that Self-serve SSO and directory sync are on Enterprise. Upgrade in Billing.

If you do not see a Security tab after you open Manage organization, ask Bruchim to enable enterprise SSO for this workspace.

Sign in

After SSO is on, staff use the usual Bruchim sign-in screen with their company login. Bruchim does not host a separate SAML form.

Turn on SSO

  1. Open the workspace switcher → Manage organizationSecurity.
  2. Add your domain, set up SAML or OIDC, test, then turn the connection on.

Only Owners and Admins can open that Security tab.

Directory Sync

After the SSO connection is live, enable Directory Sync (SCIM) on that connection so your identity provider creates, updates, and deactivates people here.

  • People from directory sync show a Directory sync badge on Users.
  • Full name and Work email show Updated from your identity provider. Title, phone, and host eligibility stay in Bruchim unless the host policy below overwrites hosts.
  • Turning someone off in the identity provider deactivates them here and removes app access. They stay in the directory as deactivated.

Turn off “create users during sign-in” (JIT) on that connection if the directory should be the only way accounts appear.

People who join through SSO or directory sync without a Bruchim invite become Employee. Roles such as Owner, Admin, Location Manager, and Reception stay assigned in Users.

Host locations for provisioned people

On the same Settings card, Host locations for provisioned people:

ChoiceWhat happens
All locationsThey can host at every site (empty host list).
One default locationHost locations and Primary location are that site.
From an identity-provider attributeMap each attribute value to a location.

Unmapped values use If the value is not mapped (a fallback location, or All locations if you leave it blank).

Directory-synced people get this rule on each sync, including when the attribute changes. People you invited or edited by hand keep the hosts you set, unless they are marked Directory sync.

See Host and Admin locations.

Map Entra Office (or any attribute)

  1. In Directory Sync, map Office (or another field) to a Clerk custom attribute, for example office.
  2. In Bruchim, set Clerk attribute key to that name (office).
  3. Select Add mapping. Enter the attribute value (for example Toronto HQ) and the Bruchim location.

The key is the Clerk custom attribute on the user, not the Entra field name.