The intended audience for this article is Agents.
Once Wunderite is integrated with the identity provider (IdP), Wunderite treats the IdP as the source of truth for user-related information. Below is an outline of how updates in the IdP are reflected in Wunderite.
Initial Sync
When Wunderite initially syncs with the IdP, the IdP becomes the source of truth. If any of the following differences exist between the IdP and Wunderite, these changes will occur:
A user exists in the IdP but not in Wunderite: The user will be created in Wunderite.
A user exists in Wunderite but not in the IdP: The user will be locked in Wunderite (and will still count towards the seat limit).
A user exists in Wunderite and the IdP but with different email addresses: A new user will be created in Wunderite with the IdP email address. The original Wunderite user account will be locked and the user will not be able to log in through SSO because their original email address is not present in the IdP.
A user is an Administrator in Wunderite but a Member in the IdP: The user will become a Member in Wunderite.
A user is a Member in Wunderite but an Administrator in the IdP: The user will become an Administrator in Wunderite.
A segment exists in Wunderite but does not exist in the IdP: The segment will be flagged for deletion from Wunderite and the users will be removed from the segment. All Administrators of the agency will be notified with a confirmation request. The Default Segment in Wunderite cannot be removed, so if it is removed from the IdP, it will need to be added back. Segment discrepancies are reviewed using Sync Preview before running the initial sync.
A segment exists in the IdP but does not exist in Wunderite: The segment will be created in Wunderite. Segment discrepancies are reviewed using Sync Preview before running the initial sync.
A user is assigned to a segment in Wunderite but not in the IdP: The user will be removed from the segment in Wunderite.
A user is assigned to a segment in the IdP but not in Wunderite: The user will be added to the segment in Wunderite.
Ongoing Updates in the Identity Provider
After the initial sync, Wunderite will receive updates from the IdP and make the following updates:
A user is deleted in the IdP: The user will be deleted in Wunderite.
A user is created in the IdP: The user will be created in Wunderite.
A user is made inactive in the IdP: The user will be locked in Wunderite and still count towards the agency's seat limit.
A user is made active in the IdP: The user will be unlocked in Wunderite.
Please note that Okta treats deactivation as deletion and activation as creation. So any user who is deactivated in Okta will be deleted in Wunderite, and any user who is activated in Okta will be created as a new user in Wunderite.
A user's name or email changes in the IdP: If a user's first name, last name or email address is updated in the IdP, the user's name or email address will be updated in Wunderite.
A user is added or removed from a group in the IdP: The user will be added or removed from the corresponding Wunderite roles or segments to match the IdP.
A new auth role or security group is created in the IdP: Any users added to this group will be assigned the Member role in Wunderite until Wunderite Customer Success is contacted to update the mapping in WorkOS.
A new segment is created in the IdP: A new segment will be created in Wunderite.
A segment name changes in the IdP: The segment name will be updated in Wunderite.
A segment is deleted in the IdP: The segment will be flagged for deletion in Wunderite and the users will be removed from the segment. All Administrators of the agency will be notified with a confirmation request.
Please note that the Default Segment cannot be deleted in Wunderite. If it is removed from the IdP, it will need to be re-added to the IdP to ensure there are no sync errors.
