PARTNER ADMIN GUIDE
Troubleshoot access
Resolve common sign-in, provisioning, domain and role-assignment issues.
Partnership administrator5 min read
Scope: individual tenant
Common access problems
Work through the most likely cause before changing the tenant's identity configuration.
| Problem | Likely cause | Action |
|---|---|---|
| SSO client is not provisioned | Greentic SSO was selected but the managed client has not been activated. | Save the SSO configuration and provision or re-provision the client. |
| The domain page says Awaiting SSO | An email domain was added before SSO became active. | Configure and activate SSO, then return to the Domains tab. |
| Users do not appear | Provisioning has not run, sync is disabled or the identity provider is not connected. | Review the SCIM configuration and use Sync now. |
| A user can sign in but cannot use a Designer capability | The required capability role has not been assigned. | Open Roles and grant the minimum required capability. |
| A user appears in the tenant but not in the expected team | Identity provisioning and team membership are separate. | Open Teams and review the team's Members list. |
SSO client is not provisioned
Greentic SSO has been selected but the managed client has not been activated, so sign-in through SSO will not work.
- 1Open Access → SSO & users → SSO.
- 2Confirm that Greentic SSO is selected.
- 3Save the SSO configuration.
- 4Select Re-provision SSO client.
- 5Confirm that the SSO client status becomes Active.
The Domains tab says Awaiting SSO
An email domain was added before SSO became active, so the domain is not routing anywhere yet.
- 1Configure and activate SSO for the tenant.
- 2Return to Access → SSO & users → Domains.
- 3Confirm that the Awaiting SSO notice has cleared.
- 4Start domain verification.
Always test with a normal user accountAn administrator's existing session may hide routing, permissions or onboarding problems.
Related guides
Choose a sign-in methodEnable local password login or prepare the tenant for single sign-on.4 min readConfigure single sign-onUse Greentic-managed SSO or connect an external OpenID Connect identity provider.5 min readConfigure email domainsRoute users from recognised company domains to the tenant's SSO configuration.4 min read
