Purpose
Provide district-account SSO from Google Workspace into Brightly operational workflows.
Current state
Production staff access is in place. Google Workspace is directly configured as the identity provider for Brightly SSO, with strongest current evidence for Brightly Event Manager facilities-use workflows and one additional Brightly module whose exact name still needs confirmation.
Next step
Document the Google Workspace IdP contract, support owner, additional Brightly module name `[placeholder pending review]`, and whether provisioning is separate from authentication as a distinct workflow.
Interfaces
Inputs- Google Workspace identity state
- SSO configuration
Outputs- staff sign-in access to Brightly
Reality to Action trace
Reality IngestionContributes in this stage.
Canonical StorageNot in scope.
Automation EnginesNot in scope.
Human InterfacesContributes in this stage.
Operational AdoptionContributes in this stage.
Core workflow
TBD. Document the 5-10 steps that define the core workflow.
Data integrity and contracts
Source of truth rules
- The district identity provider is canonical for authentication state.
- Brightly remains the target system for operational access.
Safe handling
- Protect identity-provider configuration and vendor admin access.
- Keep staff access logs and troubleshooting details internal.
Operational notes
Reliability posture
Operational value is clear, but the exact IdP contract and provisioning boundary still need explicit documentation.
Observability
- vendor and identity logs
- manual login verification
Security and privacy
Internal staff identity and access data; keep configuration details restricted.
Dependencies
Upstream- Google Workspace IdP configuration
- Brightly availability
Downstream- Brightly Event Manager for facilities use management
- additional Brightly module `[placeholder pending review]`
Ownership
OwnersTechnology Services, Josh Barton
UsersBusiness Services, MOT, Technology Services, Josh Barton (owner)
Brightly SSO Integration
Operational Notes
- The registry frames this as a real operational-tech integration, not just an instructional tool.
- Business Services and MOT are the main business stakeholders.
- Google Workspace is the directly configured IdP for the documented SSO path.
- Behavior classification: authentication-focused SSO integration; automated account provisioning is not yet confirmed in this record.
- Failure creates login friction and fallback to local vendor credentials or support.
Registry Alignment
- Mapped registry entry:
INT-023 - Registry clarified: operations systems like Brightly are part of the district integration footprint and deserve first-class Atlas coverage.
- Validation gaps: document the Google Workspace IdP contract, support owner, additional Brightly module name
[placeholder pending review], and whether user provisioning is separate from authentication.