Troubleshooting
When something breaks, most incidents cluster around identity (SSO, sessions), invitations (email, domain policy), or permissions (roles vs overrides). This reference walks through first-response checks admins can perform before escalating, and signals that indicate a platform issue rather than local configuration.
Keep it open alongside your IdP admin console during onboarding crunch periods.
Overview
Section titled “Overview”If a user cannot sign in, verify IdP status, email alignment, and whether your tenant enforces SSO-only access. For “I should see this record” reports, confirm tenant context, role, and any permission overrides that might narrow visibility.
Integration failures often trace to rotated credentials, IP allowlists, or schema assumptions that no longer match custom fields. Each subsection below will grow with symptom → cause → fix tables and known error strings as we harden operational playbooks.