The intended audience for this article is Agents.
Prerequisites
Agencies must ensure that their Wunderite subscription plan supports Single Sign-On (SSO) integration. Typically, this feature is available as part of specific plan tiers.
Initial setup will need to be coordinated with Wunderite, as some of the steps require configuration by a Wunderite Administrator.
Preparation for New Wunderite Agencies
If your agency is new to Wunderite and no users exist in Wunderite, please complete the following steps before setting up Single Sign-On.
Ensure the user who will be setting up Single Sign-On is added to your Wunderite agency and can log in as an Administrator.
Note that all users and groups created in the identity provider (IdP) will be created in Wunderite after the initial sync occurs.
Preparation for Existing Wunderite Agencies
If your agency already exists in Wunderite with users, please complete the following steps before setting up Single Sign-On.
Ensure the user who will be setting up Single Sign-On can log in to your Wunderite agency as an Administrator.
Ensure existing users' email addresses match between Wunderite and your identity provider (IdP). If they don’t match, a new user will be created in Wunderite based on the email address in the IdP. Single Sign-On will not work for existing users if the email addresses in Wunderite are not an exact match for the email addresses in the IdP.
Note that users' roles and segments (if enabled) in Wunderite will be synced to those set in the IdP. During the initial sync, the IdP configuration will overwrite any existing role or segment assignments in Wunderite that do not match.
Ensure any users who are locked in Wunderite are made inactive in the IdP if needed. Any users who are locked in Wunderite but active in the IdP will be unlocked in Wunderite after the initial sync. Similarly, any users who are unlocked in Wunderite but inactive in the IdP will be locked in Wunderite after the initial sync.
Segment names in Wunderite and the IdP must be an exact match for mapping to occur. Otherwise, a new segment with the corresponding IdP group name will be created. You will have an opportunity to review segment mappings before completing the initial sync.
Preparation for Agencies with AMS360 Integrations
If your agency is integrated with AMS360 but you do not have segments enabled in Wunderite, no further action is needed.
If your agency is integrated with AMS360 and also has segments enabled, you will need to:
Ensure that the segment groups in your IdP match the corresponding groups in AMS360 exactly, so that users are assigned the correct access in Wunderite.
Keep these segments aligned to ensure correct access levels are maintained.
When AMS360 is enabled, AMS360 is the source of truth for segments that appear in Wunderite and the associated risk profiles, while the IdP remains the source of truth for users' segments. To ensure that users can manage risk profiles associated with segments, the group name from the IdP must exactly match the segment name in AMS360 that appears in Wunderite.
