SSO, SCIM and API integrations

SSO SAML 2.0, SCIM 2.0 provisioning and API. No endpoint agent. Entra ID, Google Workspace and Okta covered; the rest, through API.

Catalog

SSO, SCIM 2.0 and directory

AD

Microsoft Entra ID

Directory

Roster sync, areas, joiners and leavers.

GW

Google Workspace

Directory · Email

Roster, org units and simulation delivery.

OK

Okta

Identity

SSO via SAML 2.0 and SCIM 2.0 provisioning.

SAML

SSO SAML 2.0

Access

Corporate sign-in without one more password.

SCIM

SCIM 2.0

Provisioning

Joiners, leavers and area changes without spreadsheets.

2FA

2FA

Access

Second factor for platform administrators.

What we need from your side

A read permission

Read-only access to the directory to sync the roster. No writes.

Allowlist

Allow our sending domains so the simulation lands in the inbox.

Hours, not a project

Full setup is not a months-long rollout. The first simulation goes out in business days.

A read permission

Read-only access to the directory to sync the roster. No writes.

Allowlist

Allow our sending domains so the simulation lands in the inbox.

Hours, not a project

Full setup is not a months-long rollout. The first simulation goes out in business days.

A read permission

Read-only access to the directory to sync the roster. No writes.

Allowlist

Allow our sending domains so the simulation lands in the inbox.

Hours, not a project

Full setup is not a months-long rollout. The first simulation goes out in business days.

For your engineering team

APIs and webhooks

Employees API

Create, update, deactivate and event history per person.

Custom Events API

Inject real events that affect the Human Risk Score.

External Phishing Reports API

Receive phishing reports generated outside the platform.

Outbound webhooks

With signature verification, retries and idempotency.

API keys

Rotatable, per integration.

In this module

Program capabilities

Roster

Manual import

When there is no SCIM, the roster comes in by spreadsheet. Not the happy path: it is how you avoid a hole in joins and leaves until the directory is connected.

Mail

Whitelisting and sending from your domain

Microsoft 365, Google, or your domain so the simulation reaches the inbox. Without an allowlist, the program measures the filter, not the people.

Access

Users, roles and permissions

Who administers the program: operator, read, audit. Not roster SSO. Who enters the console.

Integrations

Directory, SSO, and API. No agent on the endpoint.

Whalemate connects to what you already use. Roster read, corporate sign-in, and, when needed, API. We do not ask you to open ports or install a binary on laptops.

A human-risk program that does not sync the roster becomes a spreadsheet. The joiner never enters, the leaver stays orphaned, the store does not exist. Directory integration covers that: org units, joiners, and leavers, with a read permission. We do not write to your Active Directory. We do not “take control” of the IdP. IT enables a read and an allowlist for sending. The first campaign is not a six-month project. It is hours of configuration when the identity source is healthy.

SSO avoids one more password for whoever administers the program. SAML 2.0 and, when it applies, SCIM 2.0 to provision without Excel. 2FA for administrators. The catalog names Entra ID, Google Workspace, Okta, and the connectors that are supported. If the IdP is not on the list, the API is discussed at implementation. The engineering team gets documentation in implementation, not a public portal of promises.

The API covers employees, events that feed the index, external phishing reports, and outbound webhooks. Rotatable keys, per integration. Signing and idempotency on the way out. That is what lets the score live in the dashboard you already use. The architecture stays agentless: there is no resident process to “see the click.” If a tender asks for an endpoint agent, the answer is no. If it asks for evidence that the roster syncs, the answer is the joiner-and-leaver log.

Three connections

Roster, identity, and the rest by API

If one of the three is missing, the program is operated by hand again.

Directory

Roster sync, organizational units, joiners, and leavers. Read permission. No writes to your directory. The integration log leaves a trail. If the source is dirty, the program inherits that dirt: it…

SSO

Corporate sign-in to administer the program. SAML 2.0. SCIM 2.0 when provisioning has to be automatic. 2FA for administrators. IT does not keep one more password. People does not wait for security to…

API

Employees, custom events that hit the score, phishing reports born outside, signed webhooks. For the team that already has a SIEM or an iPaaS. It is not a hundred-app marketplace. It is the path for…

Before connecting the directory

Do I need to install an agent for SSO and SCIM?
No. SSO SAML 2.0 and SCIM 2.0 provisioning run via API and read-only directory permissions. There is no endpoint agent.
How often does the roster sync?
According to the connected directory's configuration; integration logs keep a trail of every joiner, change and leaver.
Can I use my LMS?
Yes, via SCORM export.
Is there technical documentation for my team?
It is shared during implementation with your account analyst.
Does Whalemate write to our directory or IdP?
No. The permission is read on the roster. SSO authenticates the people who administer the platform. SCIM provisions into Whalemate, not the other way as owner of your AD. If a flow needs a push to another system, it is discussed via API and declared. There is no silent write.
What happens when someone leaves?
The leaver in the source is reflected in the program roster according to the configured sync. They stop being campaign population. Retention of history is governed by the DPA, not by a marketing “instant delete.” IT can audit the integration log. We do not keep active accounts to inflate coverage.
Our IdP is not in the catalog. Can we still connect?
Almost always via API, sometimes via a connector that is not illustrated. It is evaluated in the technical conversation, not with an automatic “yes” on this page. Bring the IdP name to the demo. We do not list invented compatibilities. If it cannot be done, that is said before the contract.

Is the tool you use not on the list?

The API covers almost every case. We'll evaluate it in the conversation.