Identity & single sign-on

Sign in with the Identity You Already Run

kiLM federates to your existing identity provider and directory — OpenID Connect, SAML 2.0, SCIM 2.0, and LDAP / Active Directory — so people keep one corporate login and your admins keep one source of truth. There is no separate kiLM password to manage.

Two Ways kiLM Meets Your Identity Stack

Single sign-on brokers your IdP for login; directory federation imports users and groups from LDAP/AD. Use either, or both.

Single Sign-on (Brokering)

kiLM delegates login to your IdP over OIDC or SAML 2.0. Users click "Sign in with your provider", authenticate and pass MFA there, and land in kiLM — no kiLM-side password ever exists.

Directory Federation (LDAP/AD)

kiLM connects read-only to your LDAP or Active Directory, imports user accounts, and re-syncs on a schedule so joiners and leavers flow through automatically.

Authorization (Group → Role)

Map an upstream group, claim, or attribute to a kiLM role. Membership re-evaluates on every login, so access follows your directory — not a spreadsheet.

Single Sign-on — OIDC & SAML 2.0

One-click wizards for the major providers, plus generic OpenID Connect and SAML 2.0 for everything else.

Microsoft Entra ID (Azure AD)

Guided setup: register kiLM, paste your tenant and client credentials, and endpoints are discovered automatically.

Okta & Google Workspace

Dedicated presets for Okta and Google Workspace with the same single-form configuration.

Any OIDC or SAML 2.0 IdP

Generic connectors cover ADFS, Ping, OneLogin, Auth0, Authentik, Zitadel, Keycloak and more — by discovery URL (OIDC) or metadata URL / pasted XML (SAML, which works air-gapped).

Directory Integration — LDAP & Active Directory

LDAP v3 over LDAPS, read-only, with per-directory defaults you can override attribute by attribute.

Active Directory

Defaults tuned for AD (sAMAccountName / objectGUID / member groups) — the common enterprise case, configured in one form.

OpenLDAP (RFC 2307)

inetOrgPerson / uid / entryUUID defaults for OpenLDAP and other RFC 2307 directories.

Red Hat DS / 389-DS / FreeIPA

A profile for Red Hat Directory Server, 389 Directory Server, and FreeIPA. Any attribute can be overridden when your schema differs.

SCIM 2.0 — Inbound Provisioning

Your IdP pushes user create, update, and deactivate to kiLM in real time over the SCIM 2.0 standard (RFC 7643 / 7644) — no waiting for the next directory sync or login.

Real-Time Joiner / Mover / Leaver

Entra ID, Okta, and any SCIM 2.0 IdP push account create, update, and deactivate the moment they happen, so deprovisioning is instant rather than at next sync or login.

Standards-Compliant /scim/v2

A full SCIM 2.0 Users endpoint — create, replace, patch, deactivate, filtered list and ServiceProviderConfig — backed by the same identity store as SSO. SCIM groups map to kiLM roles per IdP.

Secure and Opt-in by Default

Each IdP authenticates with its own bearer token, shown once and stored only as a SHA-256 hash. SCIM stays disabled until you switch it on, and a drift check flags any divergence between your IdP and kiLM.

Roles, MFA, and the Joiner–Leaver Lifecycle

Your identity system stays the source of truth; kiLM follows it.

Group → Role Mapping

Bind an IdP group/claim or an LDAP group to a kiLM role. Elevated (admin / executive) roles require an explicit acknowledgement before they can be auto-granted from an upstream group.

MFA Stays at Your IdP

Multi-factor happens in your identity provider, so your existing MFA policy applies. kiLM also supports per-role MFA enforcement and admin-initiated session revocation.

Joiners & Leavers

Disable or remove someone at the source: SSO blocks their next login immediately, and scheduled LDAP re-sync (daily / weekly) reflects directory changes automatically.

Access Control

Who can see what is enforced everywhere kiLM reads. Identity from your IdP maps to a kiLM role; every chunk of data carries a sensitivity class; and retrieval, chat and tools honour both — deny-by-default, least-privilege, fully audited.

Role-Based Access from Your IdP

A user’s kiLM role comes from your identity provider’s groups, claims or LDAP groups — never a local copy that can drift. Roles carry entitlements; access is deny-by-default and least-privilege.

Per-Chunk Sensitivity Classes

Every chunk carries a classification — public, internal, confidential, restricted or secret — that follows the data across vector, lexical, graph and visual retrieval. A chunk a user’s role can’t see is never surfaced or cited.

Source ACLs Captured at Ingest

When kiLM ingests from SharePoint, PLM, drives and other systems, it captures the source’s access-control lists, so the permissions your systems of record already enforce carry into kiLM and apply at query time.

Enforced in the Retrieval Path

Governance, access control and audit are part of retrieval itself, not a wrapper around it. The chat agent refuses to surface anything a role can’t see, and answers are grounded only in permissioned evidence, returned with citations.

Least-Privilege by Policy

Elevated (admin / executive) roles require an explicit acknowledgement before they auto-grant; per-functionality entitlements stay off until enabled; and every tool, connector and MCP call is ACL-checked per caller.

Audit & Drift Detection

Every access decision and MCP invocation is written to an audit trail. A daily reconciliation cross-checks the source-of-truth classification against every retrieval store and fires a high-severity finding on any drift — resolvable in one click.

Works in Every Deployment Posture

Identity integration honours your network Model — see Deployment Patterns.

On-Prem & Air-Gap

On-prem IdPs (ADFS, on-prem Keycloak) and LDAP / AD are intranet-only and work fully air-gapped — no outbound connection required at run time.

Cloud IdPs via Controlled Egress

Cloud providers such as Entra, Okta, and Google are reached through your approved egress; under a sealed air-gap profile they are deliberately blocked.

Managed Service (Private Cloud)

Running kiLM as a managed single-tenant instance? The same identity options apply on your chosen cloud.

On the Roadmap

Planned identity enhancements — not yet generally available.

Single Logout (SLO)

Back-channel logout so signing out of your IdP also ends any active kiLM sessions — distinct from admin-initiated session revocation, which is available today.

Bring Your Own Identity

Tell us which IdP or directory you run and we will confirm the integration path in your quote.

Preferences saved on this device.