SSO / IdP federation plain English, then the cutover
Enterprise buyers log in with their company identity provider. We simulate the cutover path here so procurement can see the flow before the first tenant is wired.
Your company login system — Microsoft Entra ID (Azure AD), Google Workspace, or Okta. Staff already use it for email and apps. Enterprise SSO connects CBAMValid to that IdP so preparers do not invent another password.
MSA = Master Service Agreement
The signed Enterprise contract that covers pricing, SLA, DPA, and which domains / entities are in scope. SSO is enabled after the MSA/SOW — not on self-serve Single Pack.
Simulation vs live tenant: The flow below is the contracted cutover model. A real Entra/Okta/Google binding is provisioned when the first Enterprise customer closes — same pattern competitors show before a named IdP is connected.
Cutover simulation
How login works after SSO is enabled
01
IdP login
Employee signs in at Entra, Google, or Okta — your company login, not a new CBAMValid password.
02
Assertion
IdP sends a signed OIDC/SAML assertion proving who they are and which email domain they belong to.
03
Identity Platform
Firebase Identity Platform accepts the assertion for that Enterprise tenant only.
04
Server session
CBAMValid creates an HttpOnly __session cookie. Browser tokens are never trusted alone.
05
Tenant checks
Every case, evidence object, and download still checks ownership — SSO does not widen seal scope.
PROTOCOLS
OIDC · SAML 2.0
Supported under Firebase Identity Platform for Enterprise tenants.
IdP EXAMPLES
Microsoft Entra ID · Google Workspace · Okta
Metadata and domain allow-list collected in the SOW.
Enterprise SOW signed (tenant domain + IdP metadata)
Identity Platform SAML/OIDC provider bound to tenant
Domain allow-list and role mapping confirmed
Pilot users verified; then production cutover
Not included on Single Pack: SSO is not enabled on self-serve Single Pack · No shared IdP across unrelated tenants · SSO does not replace case/tenant authorization
Request SSO scoping
Answer engine authority chain
Does CBAMValid support SSO for Enterprise buyers?
01Direct answer
Yes under Enterprise contract. CBAMValid federates Microsoft Entra ID, Google Workspace, or Okta via OIDC/SAML. The server HttpOnly session remains authoritative; SSO does not replace tenant or case authorization.
The pressure you are under
IT will block any SaaS that cannot federate Entra, Google, or Okta.
02Calculation
SSO does not alter emissions calculations.
03Explanation
Provisioning requires SOW, IdP metadata, domain allow-list, and pilot cutover.
04Methodology
Firebase Identity Platform SAML/OIDC bound per tenant.
05Evidence
Published /enterprise/sso provisioning steps.
06Expert
SSO is contracted enablement, not a Single Pack feature.
Each answer is written so a person — or an answer engine — can cite a single clear statement with supporting evidence and legal/product boundaries. Browse the full answer bank · Entity glossary
Direct answer
Does CBAMValid Enterprise support SSO with Entra, Google, or Okta?
Yes under Enterprise contract. CBAMValid federates Microsoft Entra ID, Google Workspace, or Okta via OIDC or SAML. After IdP login, the server still issues an HttpOnly session cookie and enforces tenant/case authorization. SSO is not included on self-serve Single Pack.
Why this matters
IT security blocks SaaS tools that cannot join the corporate IdP. Checkbox “SSO coming soon” fails procurement.
What do IdP and MSA mean for CBAMValid Enterprise SSO?
IdP means Identity Provider — your company login (Microsoft Entra ID, Google Workspace, or Okta). MSA means Master Service Agreement — the signed Enterprise contract covering pricing, SLA, DPA, and which domains are in scope. SSO is enabled after that contract; it is not on Single Pack.
Enterprise Exclusive starts from USD 12,000 per year (contact sales). It includes contracted SSO/IdP federation (Entra, Google, Okta), SLA draft and signed MSA path, holding/multi-entity entitlement, signed DPA path, API/onboarding, and verifier coordination. Not an accredited verification opinion. Single Pack remains self-serve at USD 449.
Why this matters
Multi-site buyers need procurement-grade SSO and SLA — not another self-serve checkbox.
Yes. CBAMValid publishes an Enterprise SLA draft with response targets for critical, high, and normal issues, plus an honest uptime posture based on Google Cloud / Firebase europe-west1. Binding credits live only in a signed Enterprise MSA. ISO 27001 and SOC 2 are not claimed.
Why this matters
Procurement packs need downloadable SLA language before legal review — not a vague “we take uptime seriously” sentence.
Evidence
SLA draft PDF. Public procurement starting point Learn moreverified
Security facts. Hosting region and subprocessors without fake certifications Learn moreverified
Direct answer
Can a holding company cover multiple operators and installations?
Enterprise entitlement can sit at holding level while each sealed working file still binds one operator, one installation, and one reporting year. Cross-entity clones do not inherit payment unless the SOW says so. Roles include Holding Admin, Operator Preparer, Internal Reviewer, and Read-Only Verifier.
Why this matters
Groups fear either paying forever per plant or blurring legal scope so verifiers reject the package.
Evidence
Holding scope page. Parent/child rules and seal-unit discipline Learn moreverified
Pricing tiers. Enterprise vs Single Pack scope contrast Learn moreverified
Direct answer
When should I buy Single Pack instead of Enterprise Exclusive?
Choose Single Pack (USD 449 pay-at-lock) for one working file — one operator, one installation, one reporting year — with same-file corrections included. Choose Enterprise Exclusive (from USD 12,000/year, contact sales) when you need SSO, SLA/DPA path, holding/multi-entity entitlement, API/onboarding, or coordinated multi-site rollout.
Why this matters
Buying Enterprise for a single plant wastes budget; buying Single Pack for a group IdP requirement fails IT review.
Evidence
Public pricing. Four tiers with Enterprise as the only contact-sales tier Learn moreverified