--- title: "Managing SSO readers and reader groups" slug: "auto-assign-reader-group" description: "Make use of the auto register option to skip the SSO readers addition step in Document360. This is applicable for SAML and OpenID." tags: ["SSO"] updated: 2026-09-10T03:59:53Z published: 2026-09-10T03:59:53Z canonical: "docs.document360.com/auto-assign-reader-group" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.document360.com/llms.txt > Use this file to discover all available pages before exploring further. # Managing SSO readers and reader groups The **Auto assign reader group** feature in Document360 automatically grants knowledge base access to readers who sign in through an Identity Provider (IdP), without requiring you to invite them manually. When a reader authenticates via SSO for the first time, they are assigned to the reader groups you have pre-selected in the SSO configuration. This is especially useful for large or frequently changing user bases where readers are managed centrally in the IdP. --- ## Before you begin - SSO must already be configured for your project using SAML or OpenID Connect. - You must have existing reader groups set up in your project. If you have not created any yet, see [How to create a reader group](#how-to-create-a-reader-group) below. - You must have the **Owner** or **Admin** project role to edit SSO configurations. :::(Info) ( NOTE) If your IdP does not support SCIM provisioning, contact the Document360 Support team to enable the **Auto assign reader group** feature for your account. To know about SCIM, read [SCIM provisioning](https://docs.document360.com/docs/scim-provisioning){target=`_blank`}. ::: :::(Info) ( NOTE) Auto assign reader group and SCIM provisioning cannot both be active on the same SSO configuration. If SCIM provisioning is enabled, use SCIM's own group sync to control which reader groups new SSO readers are added to. To use Auto assign reader group instead, contact [Contact Document360 support](https://document360.com/support){target=`_blank`} to have SCIM disabled for your project first. ::: --- ## How to enable auto assign reader group 1. Navigate to **Settings** () in the left navigation bar of the Knowledge base portal. 2. In the left navigation pane, go to **Users & permissions** > **SSO Configuration**. 3. Hover over the SSO configuration for which you want to enable auto assignment and click the **Edit** () icon. 4. In the SSO configuration panel, navigate to the **More settings** tab. 5. Turn on the **Auto assign reader group** toggle.