Home / Integrations / OneLogin

OIntegration · Security and Identity

Connect OneLogin identity and access data to Salesforce Agentforce

OneLogin is the enterprise SSO and identity management platform that organisations use to manage user authentication, application access, and identity lifecycle events across their application stack. Salesforce holds the commercial record of the employee and customer relationships behind those identities. When a customer or employee contacts support about an access issue, the accurate context is in OneLogin: which applications they are provisioned for, when their account was last authenticated, whether they are active. When an employee is onboarded in HR, their access provisioning in OneLogin should be coordinated with their Salesforce profile creation. When Emerge Digital connects OneLogin to Agentforce, identity and access context is available to IT and service agents during conversations — and Salesforce lifecycle events coordinate with OneLogin provisioning to keep access and CRM records aligned.

All integrations

What this unlocks

  • User access and authentication context during service conversations: when an employee or customer contacts IT support about an access issue, an agent can read the OneLogin user record — which applications are provisioned, the last successful authentication, whether the account is active — and provide a specific response without requiring the support agent to switch to the OneLogin admin console.
  • Salesforce onboarding events trigger OneLogin access provisioning: when a new employee is added to Salesforce — from an HR system or a Salesforce onboarding flow — an agent can create or update the OneLogin user profile, set the application provisioning based on the employee role and department, and confirm the provisioning is complete before the employee's start date.
  • Salesforce offboarding events trigger OneLogin deprovisioning: when an employee offboards in Salesforce — an opportunity closes with a personnel change, or an HR system updates Salesforce — an agent can trigger deprovisioning in OneLogin, remove access to the relevant application set, and log the deprovisioning action in the Salesforce account audit trail.
  • Role change access updates as part of Salesforce lifecycle events: when an employee is promoted or transfers departments in Salesforce, an agent can read the new role's access requirements and update the OneLogin profile — adding new application access and removing the access no longer appropriate — so the employee's application access reflects their current role throughout the organisation.

In the customer journey

Employee locked out of applications — agent reads OneLogin

An employee contacts the IT help desk unable to log in to their project management application. The agent reads the OneLogin user record — the employee's account is active, the application is provisioned, but the last authentication failed three times in the past hour and the account is locked. The agent unlocks the account in OneLogin via the IT admin workflow, confirms the access is restored, and closes the Salesforce case with the resolution. The interaction takes four minutes instead of requiring an IT admin to log in to the OneLogin console.

New hire triggers OneLogin provisioning from Salesforce

A new employee is added to Salesforce as part of the onboarding workflow. The agent reads the employee's role — marketing manager — and the OneLogin application provisioning template for that role. The agent creates the OneLogin user profile, provisions the marketing-tier application set, and sends the welcome email with the OneLogin activation link. The employee arrives on their first day with access to the applications their role requires.

Employee departure triggers immediate deprovisioning

An HR system updates Salesforce with an employee departure date. On the departure date, the agent reads the employee's OneLogin profile, removes access to all provisioned applications, invalidates active sessions, and logs the deprovisioning action in the Salesforce account audit trail. The former employee's access is removed in a coordinated, documented action rather than a manual checklist.

Why not the native OneLogin–Salesforce integration?

OneLogin integrates with Salesforce through its user provisioning APIs and SAML/SCIM protocols for authentication and directory sync. These handle identity lifecycle in the authentication layer. What they do not provide is OneLogin user access context queryable by a Salesforce Agentforce agent in real time during an IT service conversation: a support agent cannot ask OneLogin's sync for the current access status of a specific employee, detect a departure event in Salesforce and trigger immediate deprovisioning across the application set, or confirm provisioning completion for a new hire's role-specific application set. Emerge Digital builds the retrieval and lifecycle coordination layer that makes OneLogin identity management genuinely available to agents in IT service and HR conversations.

OneLogin's Agentforce integration is most active in IT service management and HR operations contexts — where access provisioning and deprovisioning are lifecycle events coordinated between Salesforce and the identity platform. It is relevant for any organisation where Salesforce is used as part of the employee lifecycle record alongside an enterprise SSO platform.

How Emerge integrates OneLogin

Emerge Digital connects OneLogin to Salesforce Agentforce as a consulting engagement. We map which OneLogin user attributes and application provisioning templates are relevant to the Salesforce lifecycle events in scope, configure the onboarding and offboarding triggers that initiate OneLogin provisioning and deprovisioning, build the access context retrieval for IT service agents, and set the governance boundaries around which agents can read and initiate which identity actions. The integration is designed around your OneLogin directory configuration, your Salesforce employee data model, and your IT governance requirements.

How we structure an engagement

FAQ

Can the agent reset passwords or modify user accounts directly in OneLogin?

Account unlock actions in IT service scenarios can be initiated by agents through the IT admin workflow with appropriate authorisation. Password reset initiations — sending a reset link — can be agent-triggered. Direct password changes and full account modifications remain with the IT admin team in OneLogin.

We use Okta rather than OneLogin for SSO — can you build the same integration?

Yes. Emerge has an equivalent integration for Okta. The identity context in service conversations, Salesforce-triggered provisioning, and deprovisioning use cases are the same; the platform is different. Emerge builds to the enterprise SSO platform your IT organisation uses.

Does this work with OneLogin's MFA features?

OneLogin MFA status — whether a user has MFA enrolled, which factors are active — is readable as part of the user context during IT service conversations. MFA enrollment actions stay with the user in OneLogin's own enrollment flow.

How long does a OneLogin + Agentforce integration take?

A focused engagement typically runs four to six weeks: mapping which OneLogin user attributes and provisioning templates are in scope, configuring Salesforce lifecycle event triggers for provisioning and deprovisioning, building access context retrieval for IT service agents, defining role-change access update logic, and testing onboarding, offboarding, and IT service scenarios.

Ground your agents in OneLogin.

Tell us what your agents need to read and write in OneLogin, and we'll design the integration and the governance around it.

Talk to the practice

Prefer email? Write to the practice instead.