Skip to content

Identity provider pilot runbooks

End-to-end checklists for connecting SchoolRota to your school's identity provider — SCIM roster sync, OIDC sign-in, group roles, and pilot testing in one place.

ProviderRunbookBest for
Microsoft Entra IDEntra pilot runbookMost UK school pilots; full SCIM + SSO
OktaOkta pilot runbookTrusts and MATs on Okta
Google WorkspaceGoogle pilot runbookGoogle-first schools; SSO-first, SCIM via bridge or Entra/Okta

Generic reference

Use these when you need API details rather than IdP click-paths:

Typical pilot flow

  1. Collect SchoolRota URLs and tokens from Admin
  2. Configure SCIM in your IdP (users + groups)
  3. Configure OIDC for login
  4. Map security groups to SchoolRota roles
  5. Run the provider runbook test checklist
  6. Expand from pilot group to full staff

SAML

SchoolRota supports OIDC only today. Configure OIDC on Entra, Okta, or Google — not SAML.

SchoolRota documentation — every slot covered, every day.