---
title: "Identity, SSO & RBAC · LASSX"
description: "Enterprise OIDC and SAML, JIT provisioning, group→role mapping, org permission matrix, and break-glass local admins when the IdP is offline."
canonical: https://lassx.io/product/identity-sso-rbac
last-updated: 2026-08-23
---

# Identity, SSO & RBAC · LASSX

Enterprise OIDC and SAML, JIT provisioning, group→role mapping, org permission matrix, and break-glass local admins when the IdP is offline.

**Takeaway:** Enterprise SSO plus sovereign fail-safe: federated login on a permission matrix, with audited break-glass local admins.

- OIDC and SAML with JIT provisioning and group→role mapping
- Org-scoped roles: owner, admin, approver, member, viewer
- Permission matrix with route-level enforcement
- Break-glass local accounts (audited) even when IdP is primary
- Maintenance lockout with owner/admin override

Tags: OIDC, SAML, JIT, group → role, break-glass, AC-2 / IA

- Product hub: https://lassx.io/product
- This page: https://lassx.io/product/identity-sso-rbac
- Markdown: https://lassx.io/product/identity-sso-rbac.md
- Security: https://lassx.io/security
- Contact: https://lassx.io/contact
