Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
53 changes: 42 additions & 11 deletions docs/Advanced Configuration/SCIM Provisioning.md
Original file line number Diff line number Diff line change
@@ -1,30 +1,61 @@
---
title: SCIM User Provisioning
description: Set up SCIM provisioning to automate user lifecycle management in TurboDocx with Okta, Azure AD, and other identity providers.
description: Set up SCIM 2.0 provisioning so your identity provider can create, update, and deactivate TurboDocx accounts automatically.
keywords:
- scim provisioning
- user provisioning
- turbodocx scim
- okta integration
- scim 2.0
- azure ad provisioning
- identity management
- automated user management
---

# SCIM User Provisioning

TurboDocx offers enterprise customers the ability to integrate System for Cross-domain Identity Management (SCIM) provisioning with their platforms, enhancing user and group management across your organization. SCIM provisioning automates the user lifecycle process, ensuring that user accounts are created, updated, and deactivated in a synchronized manner across various applications and services.
TurboDocx supports SCIM 2.0 user provisioning, so your identity provider can automatically create, update, and deactivate TurboDocx accounts within your organization as employees join, change roles, or leave. SCIM manages accounts; pair it with [Single Sign-On](./Single-Sign%20On.md) if you also want your identity provider to handle authentication.

TurboDocx's SCIM implementation supports standard protocols, allowing for seamless integration with a wide range of identity providers (IdPs) that support SCIM standards. This ensures that TurboDocx can work effectively with your organization's existing identity management solutions.
## Prerequisites

## Supported Identity Providers
- A TurboDocx organization that already exists (SCIM manages users inside your organization, it doesn't create the organization itself).
- Admin access to a SCIM-capable app in your identity provider. TurboDocx's SCIM implementation has been exercised against Microsoft Entra ID (Azure AD) in production.
- A SCIM base URL and bearer token for your organization, issued by TurboDocx. There's no self-service page to generate this token today, so it comes from TurboDocx support.

Some of the major identity providers that support SCIM and can be integrated with TurboDocx include:
## Setting up SCIM provisioning

- Okta
- Microsoft Azure Active Directory (Azure AD)
- and more
1. Contact TurboDocx support to request SCIM provisioning for your organization. TurboDocx issues a SCIM base URL and a bearer token unique to your organization.
2. In your identity provider's provisioning app, enter the base URL as the SCIM endpoint and set the token as the Bearer/Authorization credential.
3. Map your identity provider's user attributes to the SCIM 2.0 User schema TurboDocx expects: `name.givenName`, `name.familyName`, `emails` (with a primary address), and `active`. Most SCIM apps do this mapping by default.
4. Turn on provisioning and run your identity provider's test or "provision a single user" action first, then confirm the account appears in TurboDocx before assigning the rest of your users.

Integrating SCIM provisioning with TurboDocx allows your IT teams to manage user identities and access rights efficiently from a central location, reducing administrative overhead and enhancing security. The automation of user account management provided by SCIM also helps in reducing the possibilities of human error during the account setup and maintenance phases.
## What SCIM provisioning does

To set up SCIM provisioning with TurboDocx, please reach out to our support team. They will provide detailed guidance through the necessary steps and offer support throughout the setup process. Once SCIM provisioning is implemented, user account management will be automated according to the configurations set in your identity provider, streamlining the process and ensuring a consistent and secure user experience across all enterprise applications.
- **Create:** a new user assigned in your identity provider creates a matching TurboDocx account in your organization. If an inactive TurboDocx account with the same email already exists, SCIM reactivates it instead of creating a duplicate.
- **Read:** your identity provider can look up TurboDocx users by SCIM filter and page through results, the same way it would query any other SCIM-compliant application.
- **Update:** attribute changes your identity provider pushes with a SCIM `replace` operation, name, email, and active status, update the matching TurboDocx account.
- **Deactivate:** removing or disabling a user in your identity provider deactivates their TurboDocx account and removes them from your organization. It does not delete the underlying account record or their documents.

## Troubleshooting

**New employees aren't appearing in TurboDocx.**
Confirm provisioning is actually turned on for the TurboDocx app in your identity provider, assigning a user to the app isn't always the same setting as enabling provisioning. Also check that the bearer token configured in your identity provider still matches the one TurboDocx issued; a rotated or mistyped token causes every provisioning request to fail.

**A field update from my identity provider isn't showing up in TurboDocx.**
TurboDocx's SCIM implementation applies `replace` operations. Some identity providers, including Microsoft Entra ID for the `displayName` field, send `add` instead of `replace` for certain attributes; those requests are accepted without an error but the field isn't updated. If an attribute update isn't taking effect, check whether your identity provider can be configured to send `replace` for that field.

**A user I removed from my identity provider still shows as active in TurboDocx.**
Confirm your identity provider is configured to actually deprovision (not just unassign) the user when they're removed. Some identity providers only stop syncing a removed user rather than sending a deactivation request.

## FAQ

**Does SCIM also let users sign in?**
No. SCIM only manages accounts, creation, updates, and deactivation. For sign-in, set up [Single Sign-On](./Single-Sign%20On.md) separately.

**Which identity providers work with TurboDocx's SCIM support?**
Any identity provider that implements the SCIM 2.0 User schema can connect. TurboDocx's implementation has been tested against Microsoft Entra ID.

**Does deactivating a SCIM user delete their documents?**
No. Deactivation removes the person's access and their membership in your organization, but does not delete the documents, templates, or signature records tied to that account.

**Can SCIM provision groups, not just users?**
TurboDocx's current SCIM support is focused on individual user accounts. If your identity provider syncs group membership, confirm with TurboDocx support before relying on it.
57 changes: 40 additions & 17 deletions docs/Advanced Configuration/Single-Sign On.md
Original file line number Diff line number Diff line change
@@ -1,36 +1,59 @@
---
title: Single Sign-On (SSO) Configuration
description: Integrate TurboDocx with your SSO provider using SAML or OpenID Connect. Supports Okta, Azure AD, OneLogin, Auth0, and more.
description: Set up SAML 2.0 or OpenID Connect single sign-on for your TurboDocx organization, including Microsoft Entra ID (Azure AD).
keywords:
- single sign-on
- sso configuration
- saml integration
- openid connect
- okta sso
- azure ad sso
- entra id sso
- turbodocx authentication
---

# Single Sign-On (SSO) Configuration

TurboDocx offers enterprise customers the ability to integrate their Single Sign-On (SSO) solution with the platform, streamlining user authentication and providing a secure and convenient way to access TurboDocx. Our SSO integration supports both Security Assertion Markup Language (SAML) and OpenID Connect (OIDC) protocols, which means we can seamlessly integrate with a wide variety of SSO providers.
TurboDocx supports enterprise single sign-on over SAML 2.0 and OpenID Connect (OIDC), so your organization's members authenticate through your own identity provider instead of a separate TurboDocx password. SSO is an Enterprise-plan feature that the TurboDocx team enables per organization.

## Prerequisites

Some of the major SSO providers that we can integrate with include:
- A TurboDocx Enterprise plan.
- An identity provider that speaks SAML 2.0 or OIDC. TurboDocx's SSO has been used in production with Microsoft Entra ID (Azure AD); other SAML 2.0 or OIDC-compliant providers can also be connected.
- Admin access to that identity provider, to create and configure a TurboDocx application or connection.
- Ownership of the email domain(s) your users sign in with. TurboDocx verifies your domain before trusting sign-ins from your identity provider, so an unverified domain can't be used to claim an existing account.

<br></br>
## Setting up SSO

- Okta
- EntraID - Microsoft Azure Active Directory (Azure AD)
- OneLogin
- Auth0
- Google Cloud Identity
- Ping Identity
- Centrify
- ADFS (Active Directory Federation Services)
and more
There's no self-service toggle for SSO today. TurboDocx configures the connection with you:

By integrating TurboDocx with your SSO solution, you can leverage the benefits of centralized user management, improved security, and simplified access to TurboDocx for your organization. This integration supports various directories, ensuring that you can maintain control over user authentication and access while still providing a seamless experience for your users.
1. Contact TurboDocx support to request SSO for your organization, and let them know whether your identity provider uses SAML 2.0 or OIDC.
2. Provide your identity provider's connection details: SAML metadata (a metadata URL or XML file) for SAML, or the client ID and issuer URL for OIDC, along with the email domain(s) your organization signs in with.
3. TurboDocx configures the connection on its side and verifies ownership of your domain.
4. Test the connection with one user before rolling it out. Have that user sign in from the TurboDocx login page; they should be redirected to your identity provider, authenticate there, and land back in TurboDocx as a member of your organization.

<br></br>
To set up the SSO integration, please contact our support team, who will guide you through the necessary steps and provide any assistance required during the process. Once the integration is complete, your users will be able to access TurboDocx through your organization's SSO solution, ensuring a secure and unified authentication experience across all your enterprise applications.
Once testing succeeds, ask your identity provider admin to assign the TurboDocx application to the rest of your users.

## Troubleshooting

**A user signed in through SSO but didn't get linked to their existing TurboDocx account.**
TurboDocx only auto-links an SSO sign-in to an existing account when your identity provider reports the user's email as verified. An unverified email creates a new account instead of linking to the old one; this is intentional, it stops one person from claiming another person's account by asserting their address. Confirm your identity provider marks the email attribute as verified.

**Sign-in redirects to your identity provider but the user ends up in the wrong TurboDocx organization, or isn't added to one.**
Check that the signing-in user's email domain is one of the domains verified for your organization. A user whose email is on a different domain won't be matched to your organization automatically.

**A user with a personal address (for example, a Gmail account) can't sign in through your organization's SSO.**
That's expected: your SSO connection is scoped to your verified domain(s). Invite that person as a regular TurboDocx member instead.

## FAQ

**Which protocols does TurboDocx support?**
SAML 2.0 and OpenID Connect (OIDC).

**Does SSO replace TurboDocx passwords?**
Once SSO is configured, your organization's members sign in through your identity provider rather than a TurboDocx password.

**Is SSO included in my plan?**
SSO is included with the TurboDocx Enterprise plan.

**Can I combine SSO with automated user provisioning?**
Yes. Pair SSO with [SCIM Provisioning](./SCIM%20Provisioning.md) so accounts are created, updated, and deactivated automatically as your identity provider changes, on top of SSO handling how those users sign in.
54 changes: 43 additions & 11 deletions docs/Integrations/Google Drive.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: Google Drive Integration
description: Connect TurboDocx to Google Drive to import templates and export generated documents directly to your Drive folders.
description: Import Google Docs, Slides, and Office files from Google Drive as TurboDocx templates, and export deliverables back to a Drive folder.
keywords:
- google drive integration
- turbodocx google drive
Expand All @@ -12,25 +12,57 @@ keywords:

# Google Drive Integration

The Google Drive integration in TurboDocx provides a seamless and efficient way to manage your document generation process. With this integration, you can import templates from Google Drive and export deliverables back to your Google Drive environment, streamlining your workflow and enhancing collaboration. Let's delve into the details of the Google Drive integration and explore its features and benefits.
TurboDocx connects to your Google Drive account through Google's own file picker, so you can import a Google Doc, Google Slides file, or Office document as a template, and export a generated deliverable straight into a Drive folder. Google Drive import and export are available on TurboDocx plans that include the integration.

## Importing Templates
## Prerequisites

One of the key advantages of the Google Drive integration is the ability to import templates directly from your Google Drive storage. This functionality eliminates the need to manually upload templates to TurboDocx, saving you time and effort. By simply connecting your Google Drive account to TurboDocx, you can access and import your templates with ease.
- A Google account with access to the files or folders you want to import from or export to.
- Google Drive enabled on your TurboDocx plan. If it isn't, clicking an Import or Export to Google Drive option opens an upgrade prompt instead of the file picker.
- An organization admin hasn't hidden Google Drive from the interface in Tenant Settings.

## Importing a template from Google Drive

The integration provides a seamless browsing experience, allowing you to navigate through your Google Drive folders and select the desired templates for import. Whether you have pre-existing templates or want to import templates created using other applications such as Google Docs or Microsoft Word, the Google Drive integration simplifies the process.
1. From template creation, choose the option to import from Google Drive.
2. The first time you do this, Google asks you to sign in and grant TurboDocx access to your Drive. TurboDocx only requests this access when you actually use the picker.
3. Google's file picker opens, showing files in your Drive. You can select a Google Doc or a `.docx` file; if your organization has PowerPoint template support enabled, Google Slides and `.pptx` files are also selectable.
4. Pick a file. Google Docs and Google Slides are converted to `.docx` and `.pptx` automatically as they're imported; Word and PowerPoint files come in as-is.
5. The imported file opens in TurboDocx's template editor, ready for you to add variables and finish setting it up.

![TurboDocx file picker browsing Google Drive folders to import templates](https://image.typedream.com/cdn-cgi/image/width=3840,format=auto,fit=scale-down,quality=100/https://api.typedream.com/v0/document/public/de39171b-a5c9-49c5-bd9c-c2dfd5d632a2/2P7GcbCddIpTtDMDZpQltzuC1ff_Import_from_Google_Drive.png)

Upon selecting the templates, TurboDocx securely imports them into your TurboDocx account, ready for customization and document generation. This ensures that your templates are readily available within TurboDocx, eliminating the need for manual file transfers or duplicate storage.
## Exporting a deliverable to Google Drive

![TurboDocx file picker browsing Google Drive folders to import templates](https://image.typedream.com/cdn-cgi/image/width=3840,format=auto,fit=scale-down,quality=100/https://api.typedream.com/v0/document/public/de39171b-a5c9-49c5-bd9c-c2dfd5d632a2/2P7GcbCddIpTtDMDZpQltzuC1ff_Import_from_Google_Drive.png)
1. After generating a deliverable, choose the option to export it to Google Drive.
2. Grant Drive access if you haven't already. The picker opens in folder-selection mode instead of file-selection mode.
3. Choose the destination folder in your Drive.
4. TurboDocx uploads the deliverable into that folder and opens the folder in a new browser tab so you can confirm it arrived.

![TurboDocx export dialog saving a generated deliverable to Google Drive](https://image.typedream.com/cdn-cgi/image/width=3840,format=auto,fit=scale-down,quality=100/https://api.typedream.com/v0/document/public/de39171b-a5c9-49c5-bd9c-c2dfd5d632a2/2P7LjJqYUUFwjrpmKHYZreunEVm_Export_to_Google_Drive.png)

## Troubleshooting

**I don't see the file I'm looking for in the picker.**
Only Google Docs, Google Slides, `.docx`, and `.pptx` files are shown, and only from your own Drive. Other file types, and files that live only in a Shared Drive, won't appear in the picker today.

**Nothing happens after I close the Google picker.**
If you cancel the picker without selecting a file (or folder, when exporting), TurboDocx treats it as canceled and doesn't import or upload anything. Click the button again to retry.

**The Google Drive option opens an upgrade prompt instead of the picker.**
Google Drive import and export are gated by your TurboDocx plan. The prompt means your organization's current plan doesn't include the integration.

**An admin can't find the Google Drive option anywhere in the app.**
Check Tenant Settings. An admin can hide Google Drive from the interface even when it's enabled on the plan, separately from whether the plan includes it.

### **Exporting Deliverables**
## FAQ

The Google Drive integration also enables you to export deliverables generated by TurboDocx back to your Google Drive. Once you have personalized and generated documents based on your templates, you can seamlessly export them to your Google Drive storage for easy access and sharing.
**Which file types can I import?**
Google Docs and `.docx` files always. Google Slides and `.pptx` files too, if your organization has PowerPoint (presentation) template support turned on.

Exporting deliverables to Google Drive ensures that your documents are stored securely in the cloud, providing a reliable backup and making them accessible from any device with an internet connection. By leveraging the familiar Google Drive interface, you can organize your deliverables into folders, share them with collaborators, and control access permissions as needed.
**Does TurboDocx store my Google password?**
No. Sign-in happens through Google's own consent screen. TurboDocx receives a temporary access token to read or write the files you pick, never your Google credentials.

**Can I import from or export to a Shared Drive?**
Not currently. Import and export both work against your personal Drive.

![TurboDocx export dialog saving a generated deliverable to Google Drive](https://image.typedream.com/cdn-cgi/image/width=3840,format=auto,fit=scale-down,quality=100/https://api.typedream.com/v0/document/public/de39171b-a5c9-49c5-bd9c-c2dfd5d632a2/2P7LjJqYUUFwjrpmKHYZreunEVm_Export_to_Google_Drive.png)
**Where do exported documents land?**
In whichever folder you choose in the picker at export time. TurboDocx doesn't create or reuse a default folder for you, you pick the destination every time.
2 changes: 1 addition & 1 deletion docs/Pipelines/Pipeline Notifications.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: Pipeline Notifications
sidebar_position: 3
description: Choose who is notified when a pipeline run succeeds or fails, override recipients per routing store, and customize the completion email including a signed-document ZIP attachment.
description: Choose who is notified when a pipeline run succeeds or fails, override recipients per routing store, and customize the completion email and ZIP.
keywords:
- pipeline notifications
- signed and delivered email
Expand Down
Loading
Loading