Skip to main content
CBAM definitive period is now in force. 2026 annual declarations are due — prepare your evidence dossier early.Trust registry →See the ruleset →
CBAMValidCarbon Border Compliance Validation
ProductHow It WorksSamplePricingVerify
Sign InStart a Dossier
ProductHow It WorksSamplePricingVerifyPublished RulesetsMethodology & SourcesStructure ReviewTrust RegistrySecurity & DPABuyer Share LinkAnswer BankEnterprise ExclusivePartnersBook a DemoSign InStart a Dossier
Enterprise Exclusive · SSO

SSO / IdP federation
plain English, then the cutover

Enterprise buyers log in with their company identity provider. We simulate the cutover path here so procurement can see the flow before the first tenant is wired.

Request SSO enablementEnterprise overview
Glossary · 30 seconds

What IdP and MSA mean

IdP = Identity Provider

Your company login system — Microsoft Entra ID (Azure AD), Google Workspace, or Okta. Staff already use it for email and apps. Enterprise SSO connects CBAMValid to that IdP so preparers do not invent another password.

MSA = Master Service Agreement

The signed Enterprise contract that covers pricing, SLA, DPA, and which domains / entities are in scope. SSO is enabled after the MSA/SOW — not on self-serve Single Pack.

Simulation vs live tenant: The flow below is the contracted cutover model. A real Entra/Okta/Google binding is provisioned when the first Enterprise customer closes — same pattern competitors show before a named IdP is connected.
Cutover simulation

How login works after SSO is enabled

01

IdP login

Employee signs in at Entra, Google, or Okta — your company login, not a new CBAMValid password.

02

Assertion

IdP sends a signed OIDC/SAML assertion proving who they are and which email domain they belong to.

03

Identity Platform

Firebase Identity Platform accepts the assertion for that Enterprise tenant only.

04

Server session

CBAMValid creates an HttpOnly __session cookie. Browser tokens are never trusted alone.

05

Tenant checks

Every case, evidence object, and download still checks ownership — SSO does not widen seal scope.

PROTOCOLS

OIDC · SAML 2.0

Supported under Firebase Identity Platform for Enterprise tenants.

IdP EXAMPLES

Microsoft Entra ID · Google Workspace · Okta

Metadata and domain allow-list collected in the SOW.

SESSION

Server cookie remains authoritative

IdP assertion → Firebase Identity Platform → server createSessionCookie() → HttpOnly __session → tenant authorization

Provisioning checklist

How SSO goes live for a real tenant

  1. Enterprise SOW signed (tenant domain + IdP metadata)
  2. Identity Platform SAML/OIDC provider bound to tenant
  3. Domain allow-list and role mapping confirmed
  4. Pilot users verified; then production cutover
Not included on Single Pack: SSO is not enabled on self-serve Single Pack · No shared IdP across unrelated tenants · SSO does not replace case/tenant authorization

Request SSO scoping

  1. Home/
  2. SSO / IdP federation — contracted per tenant
Answer engine authority chain

Does CBAMValid support SSO for Enterprise buyers?

01Direct answer

Yes under Enterprise contract. CBAMValid federates Microsoft Entra ID, Google Workspace, or Okta via OIDC/SAML. The server HttpOnly session remains authoritative; SSO does not replace tenant or case authorization.

The pressure you are under

IT will block any SaaS that cannot federate Entra, Google, or Okta.

  1. 02Calculation

    SSO does not alter emissions calculations.

  2. 03Explanation

    Provisioning requires SOW, IdP metadata, domain allow-list, and pilot cutover.

  3. 04Methodology

    Firebase Identity Platform SAML/OIDC bound per tenant.

  4. 05Evidence

    Published /enterprise/sso provisioning steps.

  5. 06Expert

    SSO is contracted enablement, not a Single Pack feature.

Related problems

  • EnterpriseFull package
  • SecuritySession model
Defined entities
  • SSO
  • OIDC
  • SAML
  • Entra
  • Okta
Answer + Evidence

SSO answers

Each answer is written so a person — or an answer engine — can cite a single clear statement with supporting evidence and legal/product boundaries. Browse the full answer bank · Entity glossary

Direct answer

Does CBAMValid Enterprise support SSO with Entra, Google, or Okta?

Yes under Enterprise contract. CBAMValid federates Microsoft Entra ID, Google Workspace, or Okta via OIDC or SAML. After IdP login, the server still issues an HttpOnly session cookie and enforces tenant/case authorization. SSO is not included on self-serve Single Pack.

Why this matters

IT security blocks SaaS tools that cannot join the corporate IdP. Checkbox “SSO coming soon” fails procurement.

Evidence

  • Enterprise SSO page. Protocols, IdP examples, and provisioning steps Learn moreverified
  • Security session model. Server-verified HttpOnly __session remains authoritative Learn moreverified

Direct answer

What do IdP and MSA mean for CBAMValid Enterprise SSO?

IdP means Identity Provider — your company login (Microsoft Entra ID, Google Workspace, or Okta). MSA means Master Service Agreement — the signed Enterprise contract covering pricing, SLA, DPA, and which domains are in scope. SSO is enabled after that contract; it is not on Single Pack.

Why this matters

Procurement jargon blocks deals. Plain labels unblock Enterprise scoping.

Evidence

  • Enterprise SSO page. Plain-English IdP/MSA glossary + cutover simulation Learn moreverified
  • Enterprise Exclusive. SSO · SLA · Holding package overview Learn moreverified

Direct answer

What does CBAMValid Enterprise Exclusive include?

Enterprise Exclusive starts from USD 12,000 per year (contact sales). It includes contracted SSO/IdP federation (Entra, Google, Okta), SLA draft and signed MSA path, holding/multi-entity entitlement, signed DPA path, API/onboarding, and verifier coordination. Not an accredited verification opinion. Single Pack remains self-serve at USD 449.

Why this matters

Multi-site buyers need procurement-grade SSO and SLA — not another self-serve checkbox.

Evidence

  • Enterprise Exclusive. SSO · SLA · Holding commercial package Learn moreverified
  • SLA draft PDF. Procurement starting-point draft Learn moreverified
  • SSO page. OIDC/SAML provisioning path Learn moreverified

Direct answer

Does CBAMValid publish an Enterprise SLA?

Yes. CBAMValid publishes an Enterprise SLA draft with response targets for critical, high, and normal issues, plus an honest uptime posture based on Google Cloud / Firebase europe-west1. Binding credits live only in a signed Enterprise MSA. ISO 27001 and SOC 2 are not claimed.

Why this matters

Procurement packs need downloadable SLA language before legal review — not a vague “we take uptime seriously” sentence.

Evidence

  • SLA draft PDF. Public procurement starting point Learn moreverified
  • DPA draft PDF. Companion data-protection draft Learn moreverified
  • Security facts. Hosting region and subprocessors without fake certifications Learn moreverified

Direct answer

Can a holding company cover multiple operators and installations?

Enterprise entitlement can sit at holding level while each sealed working file still binds one operator, one installation, and one reporting year. Cross-entity clones do not inherit payment unless the SOW says so. Roles include Holding Admin, Operator Preparer, Internal Reviewer, and Read-Only Verifier.

Why this matters

Groups fear either paying forever per plant or blurring legal scope so verifiers reject the package.

Evidence

  • Holding scope page. Parent/child rules and seal-unit discipline Learn moreverified
  • Pricing tiers. Enterprise vs Single Pack scope contrast Learn moreverified

Direct answer

When should I buy Single Pack instead of Enterprise Exclusive?

Choose Single Pack (USD 449 pay-at-lock) for one working file — one operator, one installation, one reporting year — with same-file corrections included. Choose Enterprise Exclusive (from USD 12,000/year, contact sales) when you need SSO, SLA/DPA path, holding/multi-entity entitlement, API/onboarding, or coordinated multi-site rollout.

Why this matters

Buying Enterprise for a single plant wastes budget; buying Single Pack for a group IdP requirement fails IT review.

Evidence

  • Public pricing. Four tiers with Enterprise as the only contact-sales tier Learn moreverified
  • Enterprise Exclusive. SSO · SLA · Holding module map Learn moreverified
  • Sample dossier. Inspect the self-serve package before you pay Learn moreverified
Query fan-out

Questions this page is built to absorb

These follow-ups map topic → entity → internal link so answer engines can cite one clear page instead of stitching fragmented claims.

  • CBAMValid SSO
  • CBAMValid SAML
  • CBAMValid Entra ID
Topical map

Continue in this topic cluster

Related pages that answer follow-up questions without repeating the same claim.

  • Enterprise ExclusiveEnterprise Exclusive — SSO SLA Holding
  • Security & DPASecurity and data protection facts
  • Book a demoBook a demo — Annual & Enterprise

Last content review 2026-07-26 · Ruleset claims use pinned EU instruments — not inventing deadlines.

CBAMValidCarbon Border Compliance Validation

Independent software for CBAM verification preparation — sealed, evidence-linked dossiers for exporters and EU buyers.

EU hostedGDPRTLS
info@cbamvalid.comDublin · Republic of Ireland

Product

  • Product
  • How It Works
  • Sample Dossier
  • Methodology & Sources
  • Pricing
  • Verify a Dossier
  • Book a Demo

Enterprise

  • Enterprise Exclusive
  • Structure Review
  • Published Rulesets
  • Buyer Share Link
  • Platform Architecture
  • Partners
  • Trust Registry

Guides

  • Answer Bank
  • CBAM Glossary
  • 2026 Definitive Period
  • Verification Preparation
  • Non-EU Producer Guide
  • Embedded Emissions
  • CN Code Scope Hub

Company

  • About
  • Contact
  • Security & DPA
  • Case Studies
  • Privacy
  • Terms
  • Legal Notice
PrivacyTermsCookiesRefundsSecurityLegal notice

© 2026 SectorCalc Corporation (CBAMValid). All rights reserved.

SectorCalc Corporation (CBAMValid)

4th Floor, One Burlington Plaza, Burlington Road, Dublin 4, Ireland · Ireland

Company Registration No: 315881

VAT ID: IE1857162AB

Data protection contact: Siobhan O'Connor, Data Protection Officer <info@cbamvalid.com> · privacy@cbamvalid.com

Support: +353 (0)1 676 2671 · info@cbamvalid.com

Independence Notice: CBAMValid is an independent software service for exporter-to-importer evidence packaging. It is not an EU institution, customs authority or accredited CBAM verifier. Actual emissions data must be independently verified where verification is legally required.