HubSpot Ideas

StephanSM

Roles based on job titles when using SSO

The company I work for uses Hubspot and Okta.

 

I set up SAML based authentication and it's going well but there is just one problem.

 

When logging in via SAML, the users are assigned a role in Hubspot, based on their job title which comes through from Okta.

 

For example, "Sales" job title, would need a matching role called "Sales" in Hubspot.

 

This is fine, until we come across a situation where two people have the same job title but need different levels of access.

 

It's a security problem when we have a generic job title in Okta such as "Contractor" or even "Marketing Contractor" and one of the people is supposed to be an admin in hubspot and the others shouldn't.

 

I've raised two support tickets about this but can't get any traction. In the last one they said to suggest it here.

 

I think it's really quite critical for the security reason I mentioned. If administrators are not careful, standard users could accidentally get admin level access just through a job title change.

HubSpot Updates
Delivered
April 05, 2024 07:21 AM

In Planning
October 19, 2022 11:25 AM

Hey, @StephanSM we are looking to make a change to switch over to using Roles in OKTA to map to Permission Sets in HubSpot. Would this work for the issue you are having? Happy to chat more if you want to shoot me an email also at jaleonard@hubspot.com

3 Replies
jaleonard19
HubSpot Product Team

Hey, @StephanSM we are looking to make a change to switch over to using Roles in OKTA to map to Permission Sets in HubSpot. Would this work for the issue you are having? Happy to chat more if you want to shoot me an email also at jaleonard@hubspot.com

StephanSM
Member

Yeah, I think that sounds just right, thank you. I'll send you an email. Thanks.

jsg121
HubSpot Product Team