Identity and Access
This page explains how identity and access work in Costory. It is for buyers comparing Copilot and Copilot Pro, IT or security reviewers checking access controls, and workspace admins deciding how users should join. Authentication is handled by Clerk. For a map of where to invite members, add domains, and manage Costory product settings, see Settings.At-a-glance comparison
Identity features by tier
Copilot: Auto-join by company domain
Let anyone with your company email domain join your Costory workspace without a manual invite.
Copilot Pro: Login through your identity provider
Add login through an IdP, JIT provisioning, SCIM directory sync, RBAC, and unlimited admin accounts.
Key concepts
Auto-join by company domain
Auto-join by company domain adds users automatically when they sign up with your company email domain. Use it when you want low-friction access for a known company domain and do not need IdP-controlled sign-in. This option is available on Copilot. It is not SSO, SAML, OIDC, or login through your provider.Login through your identity provider
Login through your identity provider lets users authenticate through your own IdP. Use it when your IT team requires centralized access policies, Okta Workforce, SAML, OIDC, role assignment, or automated offboarding. This option is available on Copilot Pro. SAML is the usual Okta setup, but Okta Workforce is supported over both SAML and OIDC. Other SAML or OIDC identity providers can also be connected.JIT provisioning vs SCIM directory sync
JIT and SCIM both create user accounts, but they solve different operational problems. In Clerk, SCIM directory sync is called Directory Sync.Which should you choose?
Choose Copilot if:- You want users with a real company email domain to join automatically.
- You do not need SSO, SAML, OIDC, SCIM, or IdP-managed offboarding.
- You can remove users directly in Costory when access should end.
- You use Okta Workforce, Azure AD / Entra, Google Workspace, OneLogin, or another SAML or OIDC provider for workforce access.
- You need SSO, JIT provisioning, SCIM directory sync, RBAC, or unlimited admin accounts.
- You need automatic removal when users leave your IdP.
Security and data scope
Costory ingests only cloud billing and usage data:- Cost line items per service, team, and resource.
- No end-user personally identifiable information (PII).
- No customer application data.
- No other sensitive business data.
Costory itself is not yet certified for SOC 2 or International Organization for Standardization (ISO) 27001.
Frequently asked questions
Do you support Okta?
Do you support Okta?
Yes. Costory supports Okta Workforce natively on Copilot Pro through SAML and OIDC. SAML is the usual setup. Any SAML or OIDC identity provider can be connected, not only Okta.
Should we use JIT or SCIM?
Should we use JIT or SCIM?
Use JIT when it is acceptable for users to be created at first SSO sign-in. Use SCIM when you need Costory to stay aligned with your IdP, create users in advance, and remove users automatically when they leave.
Are you SOC 2 or ISO 27001 certified?
Are you SOC 2 or ISO 27001 certified?
Costory itself is not yet certified for SOC 2 or ISO 27001. Authentication is handled by Clerk, which is SOC 2 Type II certified and compliant with HIPAA, GDPR, and CCPA.
Do extra admins cost more?
Do extra admins cost more?
No. Copilot Pro includes unlimited admin accounts at no extra cost. There is no per-admin fee.
What is the difference between auto-join and SSO?
What is the difference between auto-join and SSO?
Auto-join by company domain adds users who sign up with your approved company email domain. SSO lets users log in through your identity provider and is available on Copilot Pro.
Can I use both on the same domain?
Can I use both on the same domain?
No. For a given workspace and domain, Auto-join by company domain and Enterprise SSO are mutually exclusive. This is a Clerk limitation.
