Okta (SAML 2.0)
SAML
neww.ai handles Okta via existing scim/auth.ts; full metadata exchange ships cycle 79.
Identity OS · cycle 78 · 2026-05-18
Start selling to enterprise customers with a single integration: SAML, OIDC, SCIM, audit logs, MFA, RBAC, vault, radar. Same primitives WorkOS sells — wired directly into neww.ai’s run-state machine so identity controls agent capability, not just routes.
11 agent-OS differentiators · 15 radar signals
02 · Connector catalog
Same 20+ enterprise services WorkOS supports — Okta, Entra ID, Google, JumpCloud, Ping, OneLogin, ADFS, BambooHR, Rippling, Workday — plus social and HRIS extensions WorkOS does not list (GitHub, Gusto).
Okta (SAML 2.0)
SAML
neww.ai handles Okta via existing scim/auth.ts; full metadata exchange ships cycle 79.
Okta (OIDC)
OIDC
OIDC provider config slot exists; production metadata cycle 79.
Microsoft Entra ID (Azure AD)
SAML
Entra ID profile shaped; tenant-ID claim parsing pending.
Google Workspace SAML
SAML
Google Workspace OAuth flow live via NextAuth Google provider.
OneLogin (SAML)
SAML
Targeted cycle 79.
Microsoft ADFS
SAML
Legacy on-prem; lower priority — most customers run Entra.
JumpCloud
SAML
Targeted cycle 79.
Ping Identity (PingFederate)
SAML
Enterprise demand catalyst.
Duo SSO
SAML
Cisco-acquired; bundle with MFA push provider.
Generic OIDC
OIDC
Generic OIDC provider slot exists in NextAuth config.
Okta (SCIM 2.0)
SCIM
SCIM endpoints exist at /api/scim/*; full attribute mapping cycle 79.
Entra ID (SCIM)
SCIM
SCIM 2.0 endpoint mounted; Entra-flavoured patch ops pending.
JumpCloud (SCIM)
SCIM
Targeted cycle 79.
Google Workspace (Directory)
SCIM
Google directory API bridge.
Rippling (HRIS)
HRIS
Differentiator: HRIS → agent capability provisioning.
BambooHR
HRIS
SMB-segment HRIS.
Workday HCM
HRIS
Mid-market+ HRIS; SOAP API.
Gusto
HRIS
neww.ai advantage — WorkOS does not ship Gusto bridge.
Google (Social)
SOCIAL
Google OAuth live via NextAuth.
Microsoft (Social)
SOCIAL
Microsoft personal + work in single provider slot.
GitHub
SOCIAL
neww.ai dev-segment advantage — WorkOS does not list GitHub.
Sign in with Apple
SOCIAL
Required for consumer iOS submissions.
03 · Competitive matrix
20 capabilities scored deterministically. neww.ai leads by +-8 points against the next-best vendor (WorkOS).
| Capability | neww.ai | WorkOS | Auth0 | Stytch | Frontegg | BoxyHQ |
|---|---|---|---|---|---|---|
Magic Auth (6-digit OTP) AUTH | Full | Full | Full | Full | Partial | — |
Passwordless magic-link AUTH | Full | Full | Full | Full | Full | — |
MFA — TOTP AUTH | Full | Full | Full | Full | Full | Partial |
MFA — WebAuthn / passkeys AUTH | Full | Full | Full | Full | Full | — |
MFA — SMS AUTH | Partial | Full | Full | Full | Full | — |
Social login (Google, MS, Apple, GitHub) AUTH | Full | Full | Full | Full | Full | Partial |
Enterprise SAML 2.0 SSO SSO | Partial | Full | Full | Full | Full | Full |
Enterprise OIDC SSO SSO | Partial | Full | Full | Full | Full | Full |
IdP-initiated discovery (domain-based) SSO | Partial | Full | Full | Partial | Full | Partial |
SCIM 2.0 directory sync DIRECTORY | Partial | Full | Full | Partial | Full | Full |
HRIS bridge (Rippling, Workday, Bamboo, Gusto) DIRECTORY | Partial | Full | — | — | Partial | — |
Real-time directory webhooks DIRECTORY | Partial | Full | Full | Full | Full | Partial |
Immutable audit logs (SOC2 / HIPAA) GOVERNANCE | Full | Full | Full | Full | Full | Full |
Role-based access control GOVERNANCE | Full | Full | Full | Partial | Full | Partial |
ABAC — agent skill scope GOVERNANCE | Full | — | Partial | — | Partial | — |
Bot / abuse / anomaly radar GOVERNANCE | Partial | Add-on $ | Partial | Partial | — | — |
Encrypted secret / PII vault GOVERNANCE | Partial | Add-on $ | Add-on $ | — | — | — |
Hosted Admin Portal (CNAME, white-label) DEVELOPER | Partial | Full | Add-on $ | — | Full | Partial |
Multi-environment (dev/stg/prod) DEVELOPER | Partial | Full | Full | Full | Full | Partial |
Agent run ↔ audit log binding AGENT_OS | Full | — | — | — | — | — |
neww.ai differentiator
Magic Auth (6-digit OTP)
Agent context preserved across magic-auth — user lands back in the agent run.
neww.ai differentiator
MFA — WebAuthn / passkeys
Step-up triggered by risk-classifier on HIGH/DESTRUCTIVE agent actions.
neww.ai differentiator
Social login (Google, MS, Apple, GitHub)
GitHub social login shipped — WorkOS does not list it.
neww.ai differentiator
HRIS bridge (Rippling, Workday, Bamboo, Gusto)
HRIS events provision agent-capability tokens, not just user accounts.
neww.ai differentiator
Immutable audit logs (SOC2 / HIPAA)
Audit rows link to AgentRun + run-state frames — WorkOS audit cannot.
neww.ai differentiator
Role-based access control
Roles scope to agent skill IDs, not just URL routes.
neww.ai differentiator
ABAC — agent skill scope
Only neww.ai authorizes per-skill access — incumbents lack the agent-OS layer.
neww.ai differentiator
Bot / abuse / anomaly radar
Anomaly scoring on RunEvent streams — detect runaway agent runs.
neww.ai differentiator
Encrypted secret / PII vault
Vault rows scoped to skill IDs — cross-skill access denied at PDP.
neww.ai differentiator
Multi-environment (dev/stg/prod)
Cross-env agent-run replay via cycle 75 replay-engine.
neww.ai differentiator
Agent run ↔ audit log binding
Net-new category — only neww.ai has the agent OS underneath identity.
04 · Admin Portal
Same hosted Admin Portal pattern WorkOS offers — your customer's IT admin self-serves SSO + SCIM setup at acme-corp.admin.neww.ai with your branding, your locale, your IdP guides.
Choose how your team signs in to Acme Corp.
Configure Okta SAML
7 steps · ~8 min
Configure Microsoft Entra ID SAML
7 steps · ~10 min
Configure Google Workspace SAML
7 steps · ~7 min
05 · Feature substrate
Audit logs
61 event types
categories: SSO · directory · MFA · RBAC · vault · radar · agent OS
Hash-chained immutable audit trail with agent-run linkage.
Directory sync
20 attributes mapped
user 11 · group 3 · HRIS 6
SCIM 2.0 + HRIS attribute map across user, group, and employment data.
Radar
15 signal kinds
challenge ≥ 0.5 · block ≥ 0.85
Anomaly scoring across login + agent-run signal streams.
RBAC + skill scope
4 starter roles
admin · member · viewer · agent-operator
Role-based access with per-agent-skill ABAC scope — the WorkOS gap.
Magic Auth
5-attempt limit
10-minute TTL · agent context preserved
6-digit OTP with hash-stored challenge + constant-time verify.
Vault
5 secret kinds
API_KEY · OAUTH · WEBHOOK · DATABASE · PII
Per-skill-scoped secret store. Cross-skill reads denied at PDP.
Roles scope to skill IDs from the cycle-75 agent-OS registry. A user with role.member can run safe skills but not destructive ones. WorkOS, Auth0, Stytch all gate URLs — none gate skills.
lib/identity-os/rbac-policy-engine.ts
Every AgentRun emits an immutable, hash-chained audit row keyed by run ID. Compliance can replay the exact frames of a decision. Incumbents have audit logs; none link them to agent runs.
lib/identity-os/audit-log-schema.ts
When a skill action is classified DESTRUCTIVE, the user must pass WebAuthn within the last 5 minutes — regardless of how recent their login is. Route-gated MFA cannot see agent intent.
lib/identity-os/mfa-policy.ts
A secret is readable only by the skills listed in its skillScope — even when the human user has broad org rights. Cross-skill access denied at the PDP layer. WorkOS Vault has no concept of agent skills.
lib/identity-os/vault-secret-store.ts
Anomaly signals include AGENT_RUNAWAY (cost > P95 × 3 in 5 min) and AGENT_DESTRUCTIVE_CALL (skill outside approved scope). Detect rogue runs before $1k of compute. WorkOS Radar watches logins only.
lib/identity-os/radar-anomaly.ts
Connect any SAML or OIDC IdP, sync your directory, gate your agents — all from one surface, all wired into the run-state machine. No WorkOS-style per-connection bill.