Use case · Enterprise Identity

Your IdP, your org structure, your revocation button

Sign-in through your identity provider, isolated per tenant, revocable in one action.

The problem

“We’ll add SSO later” is where agent pilots go to die in security review.

01

Buyers ask about SSO and revocation before features

02

Homegrown auth schemes fail review

03

Revocation at token expiry isn’t revocation

04

Admin access mixed with daily use is a finding

How identity carries through

Sign in
Your IdP is the front door

Okta or any OIDC provider — the way your people already sign in.

Map
Your org structure carries over

Organizations, teams, and invitations are first-class from day one.

Act
Agents work as real identities

Every action ties back to the signed-in person an agent acted for.

Revoke
Sessions die on command

Revocation takes effect now — not at the next token expiry.

See it

Okta / OIDC
your IdP · per-tenant realm
maya@ · session⬡ Agentic Fabriq
her agents · scoped access
revoke → dead now, not at expiry

SIGN IN THROUGH YOUR IDP — REVOKE A SESSION AND IT DIES NOW, NOT AT EXPIRY

Capabilities

What you get

01
Sign in through your IdP.
Okta and any OIDC-compatible provider plug straight in.
02
Standards-based SSO under the hood.
Standard token exchange behind sign-in — nothing homegrown to review.
03
Revocation that means now.
Cut a session and it dies immediately — not at token expiry.
04
A separately hardened admin plane.
Platform admin sits behind its own auth, TOTP, and recovery codes.
05
Multi-tenant from day one.
Organizations, teams, and invitations are first-class from the start.
06
Permissions that follow your org chart.
Grants resolve org → team → member, default-deny, with per-user overrides.

The payoff

The security review starts with identity. This one starts answered.

Questions

Common questions

Related solutions