Skip to main content

Workforce identity · Public

Publish apps on the workforce portal

Choose which CAS and SAML apps and custom links members see when they open your organisation portal.

The workforce portal is where members open connected apps and trusted links after they sign in. What you publish here shapes their day-to-day entry point into your organisation's tools.

Enterprise tenants with a vanity subdomain expose the portal at https://{subdomain}.skyfallen.one. Members reach it after workforce sign-in.

Apps

Open Apps in IAM (iam:apps permission) to manage what appears on the portal. The page lists CAS and SAML apps available to the tenant. Add the apps members should see, then upload an icon when the default one is not enough.

Each portal entry can have a custom title, description, and group. Leave title and description empty to fall back to the underlying SSO application. Groups organise the portal layout into labelled sections.

Icons are stored on the SSO application itself. Uploading an icon from the Apps page updates the CAS or SAML record, so the same icon appears wherever that application is referenced.

Reorder entries with the move controls on each row. Remove an app from the portal without deleting the underlying CAS or SAML configuration.

SSO application management

When enabled for your tenant, IAM includes an SSO section for registering CAS and SAML applications directly:

Non-manager users can only create applications published by and accessible to their own tenant. Skyfallen managers can view all applications or filter to a single tenant.

CAS application secrets are shown once at creation and again only after a reset. SAML applications derive their internal identifier from the Assertion Consumer Service URL automatically — you only need to provide the ACS URL.

Privacy Policy and Terms of Service URLs are required when creating applications through IAM. They also appear in the Filament administration tables.

Page Permission Tenant toggle
CAS Apps cas:manage Manage CAS Apps
SAML Apps saml:manage Manage SAML Apps

Custom links sit beside apps. Use them for internal tools, support pages, HR systems, or policy pages that do not use ONE as their sign-in provider.

Each link needs a name and URL. Description and icon are optional, but they make the portal easier to scan.

Invites and portal access

For Workforce Identity tenants, invite links can be delivered to a separate email address while the account email remains the tenant-domain address. If domain lookup is enabled and the tenant has a vanity subdomain, invite links use that tenant sign-in path.

Branding text and uploaded assets shape the portal around the apps and links you choose here. Set those first under Brand your sign-in and portal.

English