Understanding SAML Integration

Coverity on Polaris

Version
latest
Coverity on Polaris has the ability to integrate to a SAML 2.0 Identity Provider (IDP), which is a Single Sign-On (SSO) solution. This allows you to manage all users and groups through your SSO control panel.

Many organizations already have an SSO solution deployed, which serves as a "single source of truth" about the users and groups in the organization. Integrating Coverity on Polaris to your SSO solution means you don't have to worry about maintaining two separate sets of user and group information. Furthermore, users do not need to use a separate password for Coverity on Polaris; they simply use their organizational password to log in.

When you first set up the integration between Coverity on Polaris and your SSO solution, no information gets transferred right away. Users and groups from the SSO solution are created inside Coverity on Polaris only as specific users log in.

When a user attempts to log in, Coverity on Polaris examines the supplied email address. If the address matches the email domains you configured during the SAML 2.0 integration, then Coverity on Polaris calls upon the SSO solution to complete the login. When the login is successful, the user is explicitly created in Coverity on Polaris.

When a user signs in, the SSO solution notifies Coverity on Polaris of the groups to which the user belongs. Groups are updated or created (if they don't yet exist on Coverity on Polaris), including any groups that the user has joined or left since the last Coverity on Polaris sign-in.