SSO Integration
EmberCORE has no password of its own. People sign in with an account they already have, and their role in your organization decides what they see. Fireball adds your organization to EmberNet and sets up how your people sign in, so there is nothing for you to register or configure in your own identity provider.
Ways to sign in
| Sign-in | Who it is for |
|---|---|
| Microsoft | People who sign in with their organization's Microsoft work account |
| People who sign in with a Google account, limited to the email domains Fireball allows for your organization | |
| Vord | People with a Vord account, Fireball's own sign-in service |
Microsoft sign-in is always available. Google and Vord are turned on by Fireball where your organization needs them. EmberCORE's sign-in page is being redesigned, so the screens may look different from one release to the next, but the choices are these three.
How your organization gets set up
- Fireball adds your organization. We create it on the platform and connect your sites and nodes to it.
- Fireball invites your first Admin. That person can sign in and manage your organization from the Admin view.
- Your Admins invite everyone else. An Admin invites people by email and picks the role each one holds in your organization. An Admin can grant any role up to their own.
- Directory groups, if you use them. If your people sign in with Microsoft and you manage access with directory groups, Fireball can map those groups to your organization and its roles, so access follows your directory.
People who sign in with Google or Vord need an invitation before they get any access at all.
Your email domain is not a key
Signing in with an address at your company's domain does not put someone in your organization. Access comes from an invitation or a mapped directory group, and nothing else. Someone who signs in without either sees that they have no organization yet, and sees none of your data.
Roles are per organization
A person's role is held in each organization separately. Someone can be an Admin in one organization and a Viewer in another, and each organization sees them in exactly that role. A role granted in one organization never raises what they can do in another.
| Role | What it is for |
|---|---|
| Admin | Runs the organization: users, sites, devices, apps, storage, and shells on what the organization owns |
| Engineer | Day-to-day engineering: deploying apps, logs, events, metrics, network devices, and a read-only broker view |
| Operator | Live status, opening apps, acknowledging alerts, operator notes, and end of shift |
| Viewer | A read-only view of nodes and sites, and nothing more |
Admins land in the Admin view and Engineers in the Engineer view. Operators and Viewers land in the Operator view, with only what their role allows. See EmberCORE Overview.
Global Command is Fireball's own platform role. It is the only role that sees across organizations, and it is never granted to a customer account.
Apps that sign you in
Some apps accept your EmberCORE sign-in, so you do not log in twice. Where Ignition is turned on for your organization, Admins and Engineers who open an Ignition gateway arrive already signed in. See Ignition Cloud.
If something looks wrong
- Signed in, but no organization. You have not been invited yet, or your directory group is not mapped. Ask your Admin, or Fireball for your first Admin.
- Wrong role. Your role is set per organization by your Admin. If you belong to more than one organization, check which one is selected.
Next steps
- Multi-Tenancy: how organizations and roles fit together
- EmberCORE Overview: the views each role lands in
- API Reference: how the same identity governs API access