AdminRoles and SSO

Roles and SSO

Document access governance using this structure.

Default roles

RolePermissions summaryTypical users
AdminManage billing, policies, integrationsProgram owners, compliance leads
AnalystCreate projects, upload evidenceFinance or R&D analysts
ApproverReview and sign off claimsControllers, executives
ViewerRead-only access to reportsAdvisors, auditors

SSO configuration steps

  1. Gather IdP metadata (SAML or OIDC) — Collect metadata from your Identity Provider.
  2. Add Radley Tax as a new application in your IdP — Configure Radley Tax in your IdP settings.
  3. Upload IdP metadata into Admin → AuthenticationProvide the gathered metadata to Radley Tax.
  4. Map IdP groups to Radley roles — Ensure correct role mapping for access control.

Best practices

  • Rotate SAML certificates 30 days before expiry — Maintain up-to-date certificates for security.
  • Use SCIM to automate provisioning and deprovisioning — Streamline user management processes.
  • Audit access quarterly and document results in the compliance tracker — Regularly review and record access permissions.
⚠️
Warning

Use this callout for emergency access guidance, break-glass accounts, or incident response notes.