Skip to content

SSO & Access

Access to the browser-based UIs (OpenSearch Dashboards, subscription/threat editors) is protected by Amazon Cognito. On higher tiers, you can federate Cognito with your own identity provider for single sign-on, and use role-based access control (RBAC) to scope what each user can do.

Single sign-on

SAML and OIDC federation with Okta, Azure AD, Google, or any standards-compliant identity provider (enterprise tier). Add your identity provider to the Cognito User Pool using the provided sso helper script; users then see a "Sign in with [Provider]" button on the login page.

Role-based access control

After first login, assign users to groups with the provided groups script to control access by role.

See Log Processor → RBAC & SSO for the Log Processor specifics.