SSO, SCIM and API integrations
SSO SAML 2.0, SCIM 2.0 provisioning and API. No endpoint agent. Entra ID, Google Workspace and Okta covered; the rest, through API.
SSO, SCIM 2.0 and directory
Microsoft Entra ID
Directory
Roster sync, areas, joiners and leavers.
Google Workspace
Directory · Email
Roster, org units and simulation delivery.
Okta
Identity
SSO via SAML 2.0 and SCIM 2.0 provisioning.
SSO SAML 2.0
Access
Corporate sign-in without one more password.
SCIM 2.0
Provisioning
Joiners, leavers and area changes without spreadsheets.
2FA
Access
Second factor for platform administrators.
What we need from your side
Read-only access to the directory to sync the roster. No writes.
Allow our sending domains so the simulation lands in the inbox.
Full setup is not a months-long rollout. The first simulation goes out in business days.
Read-only access to the directory to sync the roster. No writes.
Allow our sending domains so the simulation lands in the inbox.
Full setup is not a months-long rollout. The first simulation goes out in business days.
Read-only access to the directory to sync the roster. No writes.
Allow our sending domains so the simulation lands in the inbox.
Full setup is not a months-long rollout. The first simulation goes out in business days.
APIs and webhooks
Employees API
Create, update, deactivate and event history per person.
Custom Events API
Inject real events that affect the Human Risk Score.
External Phishing Reports API
Receive phishing reports generated outside the platform.
Outbound webhooks
With signature verification, retries and idempotency.
API keys
Rotatable, per integration.
How this module is used
Program capabilities
Manual import
When there is no SCIM, the roster comes in by spreadsheet. Not the happy path: it is how you avoid a hole in joins and leaves until the directory is connected.
Whitelisting and sending from your domain
Microsoft 365, Google, or your domain so the simulation reaches the inbox. Without an allowlist, the program measures the filter, not the people.
Users, roles and permissions
Who administers the program: operator, read, audit. Not roster SSO. Who enters the console.
Directory, SSO, and API. No agent on the endpoint.
Whalemate connects to what you already use. Roster read, corporate sign-in, and, when needed, API. We do not ask you to open ports or install a binary on laptops.
A human-risk program that does not sync the roster becomes a spreadsheet. The joiner never enters, the leaver stays orphaned, the store does not exist. Directory integration covers that: org units, joiners, and leavers, with a read permission. We do not write to your Active Directory. We do not “take control” of the IdP. IT enables a read and an allowlist for sending. The first campaign is not a six-month project. It is hours of configuration when the identity source is healthy.
SSO avoids one more password for whoever administers the program. SAML 2.0 and, when it applies, SCIM 2.0 to provision without Excel. 2FA for administrators. The catalog names Entra ID, Google Workspace, Okta, and the connectors that are supported. If the IdP is not on the list, the API is discussed at implementation. The engineering team gets documentation in implementation, not a public portal of promises.
The API covers employees, events that feed the index, external phishing reports, and outbound webhooks. Rotatable keys, per integration. Signing and idempotency on the way out. That is what lets the score live in the dashboard you already use. The architecture stays agentless: there is no resident process to “see the click.” If a tender asks for an endpoint agent, the answer is no. If it asks for evidence that the roster syncs, the answer is the joiner-and-leaver log.
Roster, identity, and the rest by API
If one of the three is missing, the program is operated by hand again.
Directory
Roster sync, organizational units, joiners, and leavers. Read permission. No writes to your directory. The integration log leaves a trail. If the source is dirty, the program inherits that dirt: it…
SSO
Corporate sign-in to administer the program. SAML 2.0. SCIM 2.0 when provisioning has to be automatic. 2FA for administrators. IT does not keep one more password. People does not wait for security to…
API
Employees, custom events that hit the score, phishing reports born outside, signed webhooks. For the team that already has a SIEM or an iPaaS. It is not a hundred-app marketplace. It is the path for…
Before connecting the directory
Do I need to install an agent for SSO and SCIM?
How often does the roster sync?
Can I use my LMS?
Is there technical documentation for my team?
Does Whalemate write to our directory or IdP?
What happens when someone leaves?
Our IdP is not in the catalog. Can we still connect?
Is the tool you use not on the list?
The API covers almost every case. We'll evaluate it in the conversation.