← All integrations
View the setup guide →
Identity Provider
Integrate Integration Single — Identity Provider with Barndoor
Barndoor connects to Integration Single — Identity Provider and uses your existing users, roles, and groups as the starting point, then scopes further down into least-privileged, runtime-enforced access for AI and agents.
How does Barndoor scope access for humans using AI?
Barndoor connects to Integration Single — Identity Provider via SAML or OIDC, bringing your existing users, roles, and groups in without rebuilding them. Then scope what each person can do when using AI — least privilege for how humans use AI, not just whether they can log in.
How does Barndoor classify autonomous AI agents?
Every agent gets its own AgentProfile: a distinct record with its own credentials and a human sponsor, scoped to the tools, models, and data its job requires. Every tool call, model call, and token traces back to that agent.
Read more about agent profiles →What can you govern when you integrate Integration Single — Identity Provider with Barndoor
| Control | What it covers |
|---|---|
| Tool access | Which MCP servers and tools each person, team, or AI agent can use |
| Data protection | Scope access to specific fields, records, or types, with DLP: PII detection, masking, tokenization |
| Model access | Which LLM models teams & agents can use, through virtual keys, so no one holds raw provider credentials |
| AI cost control | Spend limits and token budgets, usage attributed by user, team, or agent |
| Visibility | Every tool action and model call, logged, down to the user or agent |
Works with every AI client
View all supported AI clients →
Set up Integration Single — Identity Provider with Barndoor
Connect Integration Single — Identity Provider to Barndoor in a few steps.