What you can do
User lifecycle management
Activate and suspend users in OneLogin from workflow actions
Group and role management
Add or remove users from OneLogin groups and roles, and check group membership
Password and authentication
Generate password reset tokens and set user passwords
Application sync
Sync visible OneLogin applications into your Ravenna application catalog, skipping hidden ones
User sync
Sync user profiles with department, manager, and company data
Group and role provisioning
Map access levels to OneLogin groups or roles so approved access requests provision automatically
Access provisioning
OneLogin supports the Group, Workflow, and Manual provisioning methods, the same set as every provider except Okta. An access level can map to either a OneLogin group or a OneLogin role, and the Group method covers both. Direct user-to-application assignment is not available, so Application is Okta only. Groups and roles provision differently, and the difference decides which one you should map:
Revocation is equally conservative. Ravenna checks the user’s current group first, and if they have since been moved elsewhere it marks the entitlement skipped revocation with a reason and leaves OneLogin untouched rather than clearing a group it did not grant.
Learn more about access provisioning
User profile data
Ravenna syncs OneLogin user profiles for org hierarchy, approval workflows, and dynamic values.Available fields
Only approved OneLogin users sync. An unapproved, rejected, or unlicensed user is skipped, and one
who loses approval is removed from Ravenna on the next sync, so
status reads 1 on every synced
user.Using profile data in workflows
Access these fields through the user’s OneLogin metadata when building conditions or actions:- Route approval requests based on department or company
- Scope eligibility by job title
- Include contact information in notifications
- Build manager-based approval chains using the manager relationship
Group and role sync
OneLogin uses both groups and roles to organize users. Ravenna syncs both into user groups with clear labeling:- Groups sync with their original name (e.g., “Engineering Team”)
- Roles sync with a “Role: ” prefix (e.g., “Role: Administrator”)
If an access level mapped to a group or role fails to provision with a metadata error, run a resync of the OneLogin integration. Provisioning reads the synced record to tell a group from a role.
Learn more about OneLogin workflow actions