Skip to main content
SaaS Management centralizes your employees’ accounts and their access to SaaS. Connect your email provider first, then discover the SaaS in use and connect the ones you want to provision automatically.

1. Connect your email provider

Connect Google Workspace or Microsoft Entra ID to Primo to enable SaaS discovery, automated provisioning, and identity management across your organization.

2. Activate SaaS discovery

Discover all SaaS used across your organization by activating SaaS Mapping via Google Workspace or the Primo Chrome Extension.

3. Connect your SaaS

Connect a SaaS from the catalog with SSO, SCIM, or API credentials to provision accounts automatically.

What you can do

  • Create accounts and assign licences, groups, and roles at onboarding with provisioning rules.
  • Revoke access and transfer Drive files and emails at offboarding.
  • Connect any SaaS that supports SAML single sign-on (SSO) as a custom SAML SaaS.
  • Find shadow IT, unused licences, and the SaaS each employee uses.

Glossary

Single sign-on (SSO)

An authentication method that gives an employee access to several SaaS with one set of credentials, for example signing in to Notion with Google.

System for Cross-domain Identity Management (SCIM)

A standard protocol that automates the account lifecycle (creation, update, deletion) in a SaaS from the identity provider.

Just-in-time (JIT) provisioning

An account is created automatically the first time an employee signs in to the SaaS through SSO. Notion, Asana, and Zoom support it.

SSO tax

Some SaaS vendors charge extra to enable SSO or SCIM. See The SSO Wall of Shame for a list.