Any user accessing the Paxos Dashboard must be authorized and assigned one or more Roles, each of which consists of specific permissions that control access to various actions. Paxos provides a set of predefined roles that are available as soon as you sign up and onboard a new Entity.
Users can have different roles across different Entities.
When inviting users, it is recommended to provide organization-specific instruction on the proper use and storage of passkeys.We recommend using tools like iCloud Keychain, Windows Hello, Google Account, 1Password, Proton Pass, or other third-party password manager that enables passkey sync across devices.
Follow these steps to invite users to your entity:
Interested in using SSO?Paxos supports SAML and OIDC supported Identity Providers. Contact Support to get started.
When using Single Sign-On (SSO), instead of inviting users individually, an Entity Manager uses the Role Mapping interface to map Roles to user groups within your organization’s Identity Provider (i.e., Okta, Azure AD).Typically, you work with your IT team to leverage existing groups; however, you may need to add new Identity Provider groups to match your expected Dashboard workflows.
Once you map the group to an existing Dashboard Role, the next time users sign in with SSO their permissions will update.Follow these steps to map Identity Provider groups to Paxos Dashboard Roles: