Stratum guide
Configure identity, ACLs, and Okta
Manage users, groups, workspace/design grants, local passwords, and Okta OIDC group mapping.
Global roles establish product responsibility. ACLs decide which workspaces and designs a user or group can read, create, edit, comment on, review, or manage.
Local users
The first account is administrator. Admins can add users, assign roles, change status, and generate one-time password reset links. Existing passwords are never exposed.
Workspace and design access
New workspaces are private by default. During creation or later in Access Center, owners and administrators can grant access to users or groups. Design grants apply to a particular board.
Groups
Create local groups for reusable permission bundles and manual members. Groups can map to an Okta group claim value so SSO claims use the same policy layer.
Okta OIDC
- Create an OIDC web application in Okta.
- Set redirect URIs to the externally visible Stratum HTTPS URL.
- Enter issuer, client ID, client secret, scopes, and groups claim in Admin console → Sign-in and SSO.
- Map Okta groups to Stratum groups or roles.
- Test a non-admin account before disabling local sign-in.