What happens on every SSO login
1
Find or create the account
Edplay looks up the employee by their email address. If no account exists, one is created automatically.
2
Update profile fields
The employee’s name and avatar are refreshed from the mapped identity provider fields (if configured in Step 1).
3
Assign the Workspace role
Edplay applies the Workspace role based on your Step 2 mapping. If the employee’s group or department value does not match any mapped role, they default to Guest, which has minimal permissions.
4
Sync course and collection access
Edplay grants access to the courses and collections listed in the employee’s SSO data, and removes access to any that are no longer listed. Access is re-evaluated on every login.
Quick troubleshooting
"Save" gives an error
"Save" gives an error
One of the required External field values in Step 1 (name, email, or role) is empty, or a row in Step 2 is missing a Workspace role. Check both steps and fill in any blank fields before saving again.
An employee only has Guest access
An employee only has Guest access
Their group or department value from the identity provider is not mapped in Step 2. Open the role mapping, find the unmapped value, and add the correct Workspace role for it.
Avatars aren't showing up
Avatars aren't showing up
Confirm the Avatar row’s External field matches the exact attribute name your identity provider uses for photo URLs. Even a small typo will prevent avatars from syncing.
Course access isn't updating
Course access isn't updating
Check that the Courses or Collections row’s External field matches the exact attribute name from your identity provider. Edplay only syncs access from fields that are explicitly mapped.