Skip to content

Identity provider pilot runbooks ​

End-to-end checklists for connecting SchoolRota to your school's identity provider. SCIM roster sync, OIDC sign-in, group roles, optional Microsoft profile photos, and pilot testing in one place.

ProviderRunbookBest for
Microsoft Entra IDEntra pilot runbookMost UK school pilots; full SCIM + SSO + optional photos
OktaOkta pilot runbookTrusts and MATs on Okta
Google WorkspaceGoogle pilot runbookGoogle-first schools; SSO-first, SCIM via bridge or Entra/Okta

Generic reference ​

Use these when you need API details rather than IdP click-paths:

Typical pilot flow ​

  1. Collect SchoolRota URLs and tokens from Admin
  2. Configure SCIM in your IdP (users + groups)
  3. Configure OIDC for login
  4. Map security groups to SchoolRota roles
  5. Run the provider runbook test checklist
  6. Expand from pilot group to full staff
  7. Microsoft 365 schools: optionally enable profile photos after staff have access

SAML

SchoolRota supports OIDC only today. Configure OIDC on Entra, Okta, or Google: not SAML.

SchoolRota documentation. Every slot covered, every day.