Please visit SAML & SSO in the Smartsheet Help Center. Starting December 29, 2023 the Brandfolder Knowledge Base will only live on Smartsheet Help.
With SAML (Security Assertion Markup Language), you can quickly implement a seamless authentication process for all your Brandfolder users.
We can connect with any SAML 2.0 authentication provider. Some of the providers include:
Options for user access:
- General Access Setting - You can enable general access for all users.
This is done through the UI by navigating to the Organization level > Settings > Manage Users.
- Select the Organization, a specific Brandfolder, or a Collection you want users to access.
- You will find a drop-down for Default Permission Level in the top right-hand corner. Here you can select None, Guest, or Collaborator.
- When this setting is enabled, any user who logs in through SAML will automatically have access to a specific Brandfolder and/or Collection to that particular permission level.
Be super careful when adding default permissions at the Organization and Brandfolder levels.
- Team Access Settings - Teams allow a specific group of users set up within the IdP to gain a specific level of access within Brandfolder. This allows some or all users to be divided into separate teams (or departments) for different privacy levels across different Brandfolders and Collections.
- This can be accomplished by releasing a custom attribute in the SAML response named teams with the associated group value.
- You can also release a specific claim using ADFS as your IdP.
- Once the configuration is complete, complete the Team Configuration document attached at the end of this article and send it to Brandfolder support at firstname.lastname@example.org or your designated Brandfolder contact.
- This document must include:
- Team Value (the group name)
- The access level the team value should receive (Organization, Brandfolder, Collection)
- The permission level the team should receive (Owner, Admin, Collaborator, Guest)
- Custom Access - If the two options above do not work for your use case, an organization administrator can add a user to a specific Brandfolder or Collection outside the traditional team/general access granted. You can learn more in the User Management, Invitations, and Messaging article.
Attributes for user profiles
- We require the nameid for the user to be an email address.
- We recommend passing the user’s first name: givenname, and last name: surname.
- You can also pass along the company, title, and department associated with a user.
The options in the arrays below are potential values that Brandfolder looks to map off of. These options are beneficial when tracking analytics around your assets.
"first_name": ["first_name", "firstname", "givenname"],
"last_name": ["last_name", "lastname", "surname"],
"company": ["company", "company_name"],
Brandfolder and SSO
SSO (Single Sign On) is another option for user authentication through Brandfolder. SSO allows clients to integrate whichever user account system they have in place with Brandfolder to reduce the number of passwords and login screens users have to manage.
If you have any additional questions on SSO or SAML configurations, please contact email@example.com