Setting up Clarisights integration on Okta
In order to be able to sign-in with Okta, you would need to enable login with SSO on your Clarisights workspace. Please contact your CSM for more details on this, if you'd like to use this feature.
To provide sign-in with Okta as a feature, Clarisights uses an authentication plugin called Descope. Descope is a SOC2 certified and ISO 27001 compliant authentication plugin that allows us to integrate with multiple SSO providers.
To be able to use Okta as SSO option on Clarisights, the company would need to add Clarisights as an application in their Okta workspace.
In order to do this, please follow the steps below.
1. Select "Create App Integration" from the Applications section in Okta
2. Select "SAML 2.0" and click Next.
3. Enter "App Name" as "Clarisights"
4. Enter the values for SSO config
Single Signon URL → Descope ACS Url (
https://api.descope.com/v1/auth/saml/acs?projectId={descope_project_id}&tenantId={descope_tenant_id}). Your CSM will share thedescope_project_idanddescope_tenant_idto you before you start the setup process.Audience URI (SP Entity ID) - (
{descope_project_id}-{descope_tenant_id}).
5. Create User attribute mapping
firstname → user.firstName
email → user.email
Group attribute mapping specifies which configured roles will be passed on to Clarisights from Okta. The following filter is recommended: roles → Starts with Clarisights
This allows you to create roles in Okta named in the pattern: Clarisights_admin, Clarisights_viewer etc.
6. Click on Next and then Select “I’m an Okta customer adding an internal app” from the options menu, and then click Finish
7. Copy the metadata URL and share it with your Clarisights CSM
The above steps complete the setup process. You can now assign the Clarisights roles to users in your Okta workspace and link them to the Clarisights application.