Operator sign-in

Operator sign-in — federated identity for Suite Profit

Suite Profit is SSO-first. Operators sign in with the corporate credentials they already hold in the group's identity provider — Okta, Azure AD, or Google Workspace — over SAML 2.0 or OIDC. No local password is ever stored for federated tenants, and session lifetimes are aligned to the policy the group has already agreed with its IdP administrator.

SSO options for the operator console

Suite Profit ships as an OIDC relying party and a SAML 2.0 service provider. Both flows federate directly with the identity provider the corporate revenue office already runs. Users open the operator console URL, get redirected to the IdP, complete whatever MFA the IdP enforces, and are dropped back into Suite Profit with a signed assertion. Suite Profit consumes the assertion and issues a short-lived session bound to the operator's federated identity.

Okta (SAML 2.0 or OIDC)

Suite Profit is packaged as a custom Okta application. The Suite Profit engagement team supplies the ACS URL, entity ID, and public certificate; the group's Okta administrator adds it to the tenant and assigns the operator groups. First sign-in provisions the operator record in Suite Profit through SCIM.

Microsoft Entra ID (Azure AD, SAML 2.0 or OIDC)

Registered as an Enterprise Application in the tenant. The Suite Profit engagement team supplies the metadata document; the group's Entra administrator assigns Conditional Access, MFA policy, and role mapping through group claims.

Google Workspace (SAML 2.0)

Registered as a custom SAML app in the Google Admin console. Suite Profit provides the ACS URL and entity ID; the workspace administrator supplies the IdP metadata and controls which OUs are entitled.

Session and policy hygiene

Federated sessions expire when the IdP says they expire. Suite Profit does not extend a session past the IdP's assertion lifetime, and a revocation at the IdP is reflected on the next protected request. Break-glass emergency accounts are supported, gated by the DPO's approval, and audited on every use.

Suite Profit operator console federated sign-in
Pre-flight checklist for the IdP administrator
  • Group claim ready for operator roles (analyst / district / director)
  • MFA policy on operator groups
  • SCIM provisioning endpoint enabled (optional)
  • Conditional Access rules aligned with the MSA
  • Break-glass account documented with the DPO
Suite Profit operator console signed in
What operators see on first sign-in
  • Portfolio KPI landing based on their role scope
  • Per-property tiles for their district
  • SLA compliance panel for the group operations office
  • Audit trail search across every module
  • Named contact card for their account manager

Bootstrapping the SSO integration

The Suite Profit engagement team drives the SSO bootstrap during the pilot's kickoff week. Typical timeline: metadata exchange on day one, sandbox tenant on day two, production tenant on day three, MFA and Conditional Access alignment on day four. The bootstrap always happens on a non-production Suite Profit tenant first, so the IdP administrator can validate claims and role mapping before flipping the production cutover.

Role mapping

Suite Profit ships five federated roles out of the box: Portfolio Director, Group Operations, District Manager, Property Analyst, and Read-Only Auditor. Any of these can be bound to a group claim asserted by the IdP. Roles are enforced across every module and every write to Profitroom Suite.

SCIM provisioning

Automatic user provisioning through SCIM 2.0 is available on the Group and Enterprise envelopes. Joiners land in Suite Profit the same business day, leavers are de-provisioned within minutes of the IdP change, and role mutations mirror the IdP group membership.

Where the Profitroom Suite token lives

Federated identity gets the operator into Suite Profit. The Profitroom Suite API token that Suite Profit uses on the operator's behalf is issued per property, held encrypted at rest, and rotated by the group's security team through the Corporate SSO Hub module — never in a shared spreadsheet.

Common questions at operator sign-in

Is a local username / password available for operators?
Not for federated tenants. Suite Profit federates identity to the group's IdP as a condition of the Group and Enterprise envelopes. Break-glass emergency accounts exist for a documented outage of the IdP, and their use is audited to the SIEM stream.
The IdP session expired mid-workflow — is unsaved work lost?
No. Suite Profit persists in-flight work against the operator's federated identity. On re-authentication the console returns the operator to the exact tile and pending write they left.
An operator changed districts — do we recreate the account?
No. Change the group claim in the IdP, or SCIM will do it automatically. Suite Profit picks up the new role on the next assertion; historic actions stay attributable to the operator with the role held at the time.
Does the audit stream include failed sign-ins?
Yes. The SIEM audit stream carries successful assertions, failed assertions, role changes, break-glass activations, and every write into Profitroom Suite. Retention on the Suite Profit side is 400 days; retention downstream is your SIEM's policy.

Not federated yet?

If the group has not yet gone through the Suite Profit pilot kickoff, the operator console is not provisioned for the IdP. Start with a scoping memo.

Open the module catalogue SSO federation to Profitroom Suite