Skip to content

Enterprise SSO

Vellocity supports enterprise single sign-on (SSO) so your team signs in with your own identity provider (IdP) instead of a separate Vellocity password. Federation is built on AWS Cognito, which brokers the connection between your IdP and Vellocity.

How to enable it

Enterprise SSO is set up with help from the Vellocity team today — federation is admin-assisted, and self-service configuration is on the roadmap. To get started, talk to your Vellocity contact or email support@vell.ai. The onboarding guide explains what your IT team provides and what we configure on our side.

Availability by plan

SSO login and provisioning are available on the Accelerate plan and above. Requiring SSO (enforcement) is an Enterprise feature. Your organization's seat plan determines what's available.


What you get

Capability What it means
SAML 2.0 & OIDC Federate any standards-compliant IdP — Microsoft Entra ID, Okta, AWS IAM Identity Center, OneLogin, Ping, Auth0, and more.
Just-in-time (JIT) provisioning The first time a teammate signs in through SSO, their Vellocity account is created automatically — no manual invite or CSV import.
Verified email domains Users are matched to your organization by the email domain on their work account (e.g. everyone at @yourcompany.com).
Per-organization scoping Each customer gets its own organization record — its own domains, identity provider, seat plan, and settings. Users only ever land in their own organization.
Organization seat plans Your organization carries the subscription. New SSO users are granted your plan automatically as they join, up to your seat limit. See Seats & plans.
SSO enforcement Optionally require SSO for your domains, so work accounts can't fall back to a password.
Session tracking Every SSO sign-in is recorded (identity provider, time, IP, user agent) for visibility and audit.

How it works

Your users ──▶ Your IdP ──▶ AWS Cognito ──▶ Vellocity
             (Entra ID,     (federation      (JIT account +
              Okta, IdC…)     broker)          org seat plan)
  1. A teammate opens the Vellocity login page and chooses Sign in with Enterprise SSO (or enters their work email, which is detected as an SSO domain).
  2. They authenticate at your identity provider — your policies, your MFA, your conditional access all apply.
  3. Cognito validates the assertion and hands Vellocity a verified identity.
  4. Vellocity finds the organization that owns their email domain, provisions their account if it's their first sign-in, and grants your organization's seat plan.
  5. They land in the dashboard, signed in.

Because your IdP is always the authority, offboarding a user in your IdP immediately stops their Vellocity access through SSO.


Seats and plans

Unlike an individual signup, an SSO user does not go through a separate checkout. Instead:

  • Your organization holds the plan. An administrator sets the seat plan and seat limit on your organization.
  • Seats are claimed as people join. Each user's first SSO sign-in claims a seat and grants them your plan automatically.
  • Seat limits are enforced. If your organization is at its seat limit, a new user still signs in but lands without a plan (feature-limited) and your billing contact is notified so a seat can be added. You can also choose to block sign-in entirely when seats are full.

Full detail — including exactly what JIT does and doesn't create — is in the Security & FAQ page.


Next steps