LenderMeldLenderMeld
Operate
HomeInboxCustomersLoans
Money
PaymentsACH
Insight
Reports
Configure
CommsSettings
WorkspacesOnboardingUnderwritingCollectionsLedger activityDocumentsPrint center
PlatformLender administrationLead sourcesVendor performanceEvidenceHardening
LP
Lin Park
Senior Officer - Charlotte
New loan

Auth provider integration

WorkOS/Auth0 - SAML - SCIM - MFA - session and device policy

Demo dataPreview lockSettingsLender administration
Provider path
WorkOS
Auth0 alternative documented
Tenant
loanmeld-prod
org claim maps to active workspace
Access scopes
5
signed session grants enforced
Idle lock
5m
4-digit personal code
ProviderSAMLSCIMSessions
ProviderUseCapabilitiesIntegration state
WorkOSTargetSSO, SAML, SCIM, admin portalOrganization mapping ready
Auth0AlternativeOIDC, SAML enterprise connectionsTenant claim mapping ready
Local headersDevelopment onlyCookie/header staff contextBlocked for production
StepMilestoneAdmin actionState
1Choose providerSelect WorkOS or Auth0 per tenant and store provider org IDReady
2Configure SAML/OIDCExchange metadata, callback URLs, signing certs, and claimsNext
3Enable SCIMMap directory groups to roles and test deprovisioningNext
4Enforce MFARequire step-up for settings, exports, payments, and role changesPolicy
5Cut over sessionsReplace local headers with signed provider sessionsPolicy
Current staff context
local sessions remain visible until signed provider sessions are enabled
Local Staff
staff@loanmeld.local
platform_adminlocal-default
PolicyValueEnforcement
Admin MFARequiredall settings, export, payment, and role actions
Session max age12 hoursreauthenticate before next privileged action
Idle timeout5 minuteslock operator shell and preserve draft state
Unlock code4 digitsrequired when resuming idle session
Trusted devices30 daysdevice-bound with revoke action
Cross-tenant accessDeny by defaulttenant claim must match active workspace
Session lock governance
tenant policy, employee unlock codes, device review, and audit evidence
Staff session lock
Auto-lock operator workspaces after idle time and require a personal unlock code.
Idle
Ready to update staff session lock policy.
EmployeeUnlock codeMFALast activity
Lin Parklin.park@example.testActive4 digitsRequiredMay 3, 2026, 3:42 PM
Henry Walshhenry.walsh@example.testActive4 digitsRequiredMay 3, 2026, 3:18 PM
Session devices
trusted device review and revocation queue
ActorDeviceStateLast seen
Lin ParkMacBook Pro - CharlotteTrusted05/03/2026 09:42 PT
Henry WalshWindows workstation - RaleighReview05/02/2026 16:18 PT
Service accountAPI token workerRestricted05/02/2026 02:10 PT
SAML configuration
metadata fields required before SSO cutover
ItemStateRequirement
Entity IDRequiredtenant-specific issuer and ACS URL
Metadata XMLRequiredcertificate, SSO URL, signature algorithm
Attribute mappingRequiredemail, name, tenant, role groups
JIT provisioningApprovalcreate staff record from signed assertion
Break-glass adminRequiredlocal emergency role with MFA evidence
SCIM directory sync
directory objects mapped to tenant staff and roles
ObjectAttributesAction
Usersemail, displayName, activeCreate, update, deactivate
GroupsexternalId, displayNameMap to tenant roles
Role assignmentsgroup membershipSync privileged grants
Deprovisioningactive=falseSuspend sessions and API tokens
Cutover evidence
controls that must be retained before provider enforcement
EvidenceStatusOwner
MFA policy exportReadySecurity
Session lock reviewSeededAdmin
SCIM deprovision testNextIdentity