Single Sign On (SSO) lets you and your team log into Backstory using the credentials already stored in your organization's identity provider (such as Okta), so users do not need a separate password for Backstory. Backstory uses the SAML 2.0 standard, which is a widely adopted security protocol for this type of integration. Setting up SSO is also a required step before using Backstory in Salesforce.
Note: Setting up SSO requires a Backstory administrator account.
Set Up Single Sign On
These steps walk you through connecting your organization's identity provider to Backstory and making it the primary way your team logs in. You will need to complete configuration steps in both Backstory and your identity provider.
Prerequisites: Your organization's identity provider (such as Okta or OneLogin) must be set up and you must have access to its admin settings. Your identity provider must support SAML 2.0.
Log into Backstory as an administrator.
Click the grid icon in the top left corner.
Select Admin Panel.
In the left navigation menu under Organization, click Single Sign On.
Click the Add Provider button in the top right corner.
Enter the following information in the Add Identity Provider dialog:
Identity Provider Name (required)
Metadata URL (required)
XML Text (optional)
Entity ID (required)
Click Next and copy the generated Backstory Metadata URL into your identity provider's configuration.
In your identity provider, map the following values from Backstory's metadata:
Single Sign-On URL: https://app.people.ai/saml/sso
Entity ID: https://app.people.ai
Default Relay State: https://app.people.ai
After completing the mapping in your identity provider, return to Backstory, check the Backstory is integrated checkbox, and click Save.
Click the Test Integration button to verify that login works correctly.
Click the Publish toggle to make the integration live for your organization, then click Confirm in the confirmation dialog.
Click the Backstory WebApp primary authenticator dropdown and select your new integration to set it as the primary authentication method.
Frequently Asked Questions
What identity providers does Backstory support?
Backstory supports any identity provider that follows the SAML 2.0 standard, including Okta, OneLogin, and Duo Security. Backstory is available as a verified app in the Okta app directory for simplified setup.
What is Just-In-Time (JIT) provisioning?
JIT provisioning means Backstory automatically creates a user account the first time someone from your organization logs in via SSO. The new user is created in an inactive state and must be approved by an organization administrator before they can access the application.
Do I need to set up SSO to use Backstory in Salesforce?
Yes. Completing the SSO configuration is a required step before your team can use Backstory in Salesforce.
Can I turn off an SSO integration after it has been published?
Yes. SAML integrations can be toggled on and off as needed from the Single Sign-On settings page.
What should I do if I cannot provide a metadata URL?
If your identity provider cannot consume a metadata URL, you can use the advanced (custom) integration method. You will need to provide Backstory with your Identity Provider Single Sign-On URL, Identity Provider Issuer, and X.509 Certificate. Contact support@backstory.ai for assistance with this setup.
Need Help?
Contact your CSM or email support@backstory.ai.
