Identity

Identity and sign-in

Set up authenticators, company SSO, session limits, and recovery.

Sign-in and recovery

Email/password users can enable two-factor verification or add a backup authenticator in Settings → Account security. Each new password session then requires a six-digit code. Removing the final authenticator disables two-factor verification. If all authenticators are lost, contact support@embrasure.ai; recovery verifies account ownership and signs out existing sessions.

Company SSO uses SAML for allowed email domains. Enforce MFA in your identity provider; Embrasure does not add an authenticator prompt to SSO sessions. The workspace session limit measures time from sign-in, not inactivity.

Roll out SSO

  1. Create the workspace and confirm two administrators can sign in.
  2. Open Settings → Admin → Sign-in, add company domains, and set the maximum session length.
  3. Register the identity provider with Require SSO off and test sign-in.
  4. Enable Require SSO after the test passes. Keep an administrator browser open to correct configuration errors.
  5. Pilot Google Workspace directory sync or SCIM with a small group. SSO controls sign-in; provisioning controls membership and roles.

Warehouse identity federation

Databricks and Snowflake can run interactive queries as the requesting member after a source sign-in verifies their provider identity. Query tokens are short-lived and kept in memory.

For Databricks, choose an Embrasure-managed issuer with a tenant-isolated AWS KMS keyring, or a customer-controlled broker that revalidates the native identity and signs with your own key. Your administrator installs the account-wide trust policy using generated instructions; Embrasure does not receive account-admin credentials. Choose customer-controlled mode if your organization prohibits partner-managed issuers.

Removing trust or a member mapping, disconnecting a member, or deactivating them through SCIM blocks the next query before schema release or model execution.