Skip to main content

help.skyfallen.one

ONE Help

Guides for people who run organisations, and references for teams building on ONE.

Start here

Getting oriented with a new account, running things day to day, and how agents can read this documentation.

01

Getting started

How ONE is organised

The subdomains, tenant types, and product areas you will meet when you sign in, administer an organisation, or connect an application.

Read article
02

Getting started

Create your ONE account

Register a ONE ID, pick the tenant type that fits, and know what to expect before your organisation is ready to use.

Read article
03

Organisation administration

Run your organisation in IAM

Manage members, invites, roles, and bulk imports from the IAM area once your tenant is active.

Read article
04

Build integrations

Model Context Protocol (MCP)

Connect AI agents to ONE Help — search articles and fetch full guides through the MCP server.

Read article

Catalogue

Browse by role.

The sections follow the order teams usually work through ONE: account setup, administration, workforce branding, and integration APIs.

5 docs

Getting started

  1. How ONE is organised The subdomains, tenant types, and product areas you will meet when you sign in, administer an organisation, or connect an application.
  2. Your account and security Update your profile, verify contact details, register passkeys on enterprise tenants, and understand what happens when credentials change.
  3. Create your ONE account Register a ONE ID, pick the tenant type that fits, and know what to expect before your organisation is ready to use.
  4. Reset a forgotten password Recover access with a six-digit code by email or SMS when your organisation allows self-service reset.
  5. Information required for commercial and enterprise tenants The personal, organisation, and legal details Skyfallen collects when you set up a commercial or enterprise tenant.
12 docs

Organisation administration

  1. Quick Command reference Search pages, documentation, tenant objects, and Mavi from the dashboard command bar or palette.
  2. Run your organisation in IAM Manage members, invites, roles, and bulk imports from the IAM area once your tenant is active.
  3. Documents required for tenant verification The business and identity documents Skyfallen asks commercial and enterprise tenants to submit after sign-up.
  4. Tenant roles How custom roles work in IAM, how they combine with member permissions, and how delegation limits what administrators can assign.
  5. Submit tenant verification documents Upload business and identity documents at verify.skyfallen.one while Skyfallen reviews your commercial or enterprise tenant.
  6. Manage enterprise domains Add, verify, select, and retire the domains that define an enterprise tenant namespace and member email addresses.
  7. Custom domains for enterprise sign-in Serve branded enterprise sign-in and the workforce portal on your own hostname.
  8. Tenant permissions reference Every IAM permission name, the pages it controls, and how wildcards and delegation limits work in practice.
  9. Connect Google Workspace Link an enterprise tenant to Google, see directory match status on members, and provision accounts when you have manage access.
  10. Configure CAS applications Register CAS connected applications in IAM, set every required field, and hand integrators the credentials they need.
  11. Configure SAML applications Register SAML service provider applications in IAM, map every integration field, and connect them to Workforce Identity sign-in.
  12. Legacy SSO password migration Import members from a legacy identity provider, verify them through a temporary SAML service provider, and let them set their first Skyfallen ONE password.
2 docs

Workforce identity

  1. Brand your sign-in and portal Set sign-in copy, default language, portal text, logo, and background image before members see the workforce experience.
  2. Publish apps on the workforce portal Choose which CAS and SAML apps and custom links members see when they open your organisation portal.
6 docs

Build integrations

  1. Model Context Protocol (MCP) Connect AI agents to ONE Help — search articles and fetch full guides through the MCP server.
  2. API overview A map of ONE API surfaces — domains, authentication styles, response shapes, and habits that keep integrations safe.
  3. CAS sign-in and session API Sign users into your application with Skyfallen CAS, then read the current user, tenant, membership, or billing profile.
  4. Tenant signup API Provision a commercial or enterprise tenant, its first owner, and verification records from an approved partner flow.
  5. SAPP read and metadata API Read tenants, users, and memberships, then patch integration metadata without overwriting core ONE fields.
  6. SAPP webhooks Receive signed account-change events and verify the HMAC signature before reconciling with the read API.

Support

Request Help

Open a Skyfallen ONE support request for your organisation and continue the conversation in Success Manager.

Open a request
English