Skip to content

Identity and Access Management (IAM)

PlaidCloud’s access controls are organized around a few core concepts:

  • Organization — the top-level billing and identity boundary. An organization contains workspaces and members.
  • Workspace — an isolated environment where actual work happens. Members get access at the workspace level.
  • Member — a user with credentials who belongs to one or more workspaces in one or more organizations.
  • Security group — a bundle of permissions inside a workspace. Members are assigned to security groups to grant them specific capabilities.
  • Single sign-on (SSO) — optional SAML-based federation that delegates authentication to your identity provider (Okta, Auth0, Microsoft Entra, Google, AWS).
Organization Workspace Members people with access assigned to Security group · Analysts Security group · Admins each group = a bundle of permissions Identity provider (SSO) SSO authenticates members before they reach the workspace
An organization contains workspaces; members belong to a workspace and are assigned to security groups, each a bundle of permissions. Optional SSO delegates sign-in to your identity provider.

If you’re setting up a new organization:

  1. Organizations and workspaces explained — the boundaries between them and when to use each
  2. Managing workspace members — invite users, assign them to workspaces, grant capabilities
  3. Managing security groups — bundle permissions and assign them

If you’re integrating with an existing identity provider: