← Blog

Stop managing access by hand

Access management fails quietly. Someone joins the data team and waits two days for the memories they need. Someone leaves the company and their access… stays. Not because anyone decided that — because a human had to remember, and humans forget.

If your company already runs single sign-on, the fix is to stop deciding access twice. Your identity provider already knows who’s in which group. Ontonym can just listen to it.

How it works

An organization owner connects the company’s identity provider — Microsoft Entra ID, Okta, Google, AD FS and Keycloak all work, it’s plain OpenID Connect — and maps groups to what they should mean here. “Engineering” gets these access groups. “Leads” get the admin role.

From then on, it syncs at every sign-in. Someone added to a group in your IdP gets the matching access the next time they sign in. Someone removed from the group loses it the same way. Nobody files a ticket; nobody has to remember.

Hand-outs survive

One detail matters in practice: the sync only manages what the sync created. If you gave a contractor access by hand, a group sync won’t silently take it away. Ontonym tracks how each grant was made — through SSO or by a person — and touches only its own.

Setup lives in your organization’s settings, and needs one DNS record to prove you own your email domain — that’s what keeps someone else from claiming it. After that, access management is a list you edit in one place: your IdP, where you already edit it.