Authentication and Access
How signing in to Tenali works across web, desktop and mobile, what governs who joins your workspace, and where SSO stands today.
How Sign-In Works
Tenali has one hosted sign-in flow, used identically by the web app, both desktop apps and mobile. Sessions are token-based, and the desktop apps use PKCE for the authorization exchange so no client secret is held on the machine.
Work Email Is Required
Sign-up rejects public and free email domains — you'll see "Public email domains are not supported. Please use a corporate work email." Everyone signs in with their company address.
That requirement is also what builds your workspace: accounts sharing an email domain join the same organization automatically. A new colleague signing up with your company domain lands in your workspace rather than creating a separate one.
SSO, SAML and SCIM
Tenali does not support SAML, OIDC enterprise connections, IdP-initiated login, or SCIM directory sync today. There is no tenant to configure with Okta, Entra ID or any other identity provider, and no automated user provisioning or deprovisioning.
In practice that means:
- Members sign in with the hosted flow using their work email.
- Roles are assigned inside Tenali by an admin — they don't come from your directory. See Roles and Permissions.
- Removing someone from your IdP does not remove them from Tenali. Remove them in Tenali as part of your offboarding process.
If SSO is a hard requirement for your rollout, raise it with security@tenali.ai before a trial so you get a straight answer on timing.
Compliance
For current compliance status and what evidence we can share, contact security@tenali.ai. See Prepare an Enterprise Security Review for what to gather.
Related
Was this page helpful?