> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/web-application-and-api-protection-waap/settings/configuration/teams/saml/set-up-saml-group-mapping-with-onelogin.md).

# Set Up SAML Group Mapping with OneLogin

This topic explains how to configure SAML-based Single Sign-On (SSO) with OneLogin and enable group mapping so Traceable can automatically assign roles based on OneLogin group membership.

This guide is intended for OneLogin administrators.

***

## Before you begin

Ensure you have the following:

* Admin access to your OneLogin account.
* The Traceable app has already been created and assigned in OneLogin.
* User groups are configured, and users are assigned to those groups.
* Admin access to the Traceable UI.

***

## Step 1: Add Group Attribute in OneLogin

1. Log in to your OneLogin Admin portal
2. Navigate to **Applications → Applications**
3. Click the **Traceable** app
4. Go to the **Parameters** tab
5. Click **+** to add a new field
6. Set:
   * Field name: `groups`
   * Value: Select **Macro** and choose `User Roles` or another field that maps to user group membership
   * Check **Include in SAML assertion**
7. Click **Save**

This ensures the SAML assertion sent to Traceable includes the user's group or role information.

***

## Step 2: Test and verify the assertion

1. Assign users to the Traceable app in OneLogin
2. Use a test user to sign in via OneLogin SSO
3. Use **SAML-tracer** or a SAML debugging tool to inspect the login response
4. Look for:

   ```language-xml
   <Attribute Name="groups">
     <AttributeValue>Security Admins</AttributeValue>
   </Attribute>
   ```

Note the attribute name and group value for use in Traceable.

***

## Step 3: Map Groups to Roles in Traceable

1. In the Traceable UI, go to **Configuration > Team**
2. Click the **SAML Config** tab
3. Enter `groups` in the Group Attribute Name field
4. Click **+ Add Group** and define mappings:
   * SAML Group: Enter values such as `Security Admins` or `Developer`
   * Role: Select the appropriate Traceable role
   * Scope: Define whether the role applies globally or to specific apps
5. Click **Add Role**, then **Save**

***

## What’s Next?

After setup:

* Users signing in via OneLogin will receive the correct roles based on their group
* You can update or remove mappings from the Traceable UI at any time

Return to the [SAML Configuration](/web-application-and-api-protection-waap/settings/configuration/teams/saml/saml-configuration.md) topic to continue with the rest of the SAML configuration process.
