---
title: "Enterprise auth: SSO, SCIM and audit, self-hosted"
description: "How theAuth answers an enterprise security review: self-hosted data, SSO, SCIM, agent audit and SIEM sinks, with honest limits and no certification claims."
canonical: https://theauth.dev/use-cases/enterprise/
lastmod: 2026-10-08
---

Use case

# Auth for large organizations that review everything.

A security team will ask where the data lives, who can read the code, how people and agents are provisioned and removed, and what the audit trail contains. This page answers those questions for theAuth, including the ones where the answer is "that part is yours".

[Enterprise datasheet](https://theauth.dev/enterprise/) [Review questions](https://theauth.dev/use-cases/enterprise/#uc-answers)

The problem

## Procurement and security review decide the timeline.

Large customers rarely object to a feature. They object to a gap in the questionnaire: a vendor that holds their directory data, a login service with no exit, an AI agent that acts under a shared service account no one can attribute.

An auth library you run yourself changes several of those answers. The code is MIT licensed and readable, the data sits in your database in your region, and nothing leaves your infrastructure unless you send it. The cost is that the controls, and the evidence for them, are yours to operate.

What the review usually asks for

- **Identity federation.**SAML 2.0 or OIDC against the customer's identity provider, with provisioning and removal through SCIM 2.0.
- **Access control.**Organizations, roles, and a clear model for service accounts and AI agents.
- **Audit.**Who did what, to what, when, exportable to the customer's SIEM.
- **Data handling.**Location, export and deletion, with the processor question answered.
- **Supply chain.**Signed releases, an SBOM and a disclosure process.

The theAuth answers

## Each question, with what ships and what does not.

Pitfalls

## Where enterprise rollouts slip.

- **Promising a certification.**There is none to promise. Say "mapped to SOC 2 controls" and attach your own evidence.
- **Assuming isolation between tenants.**Tag agents with a tenant, then enforce the boundary in your own authorization checks.
- **Skipping the offboarding test.**Run the SCIM deprovisioning path against the customer's identity provider in staging before the review.
- **Forgetting you operate it.**Backups, key rotation and upgrades are yours. Write them into the runbook the reviewer asks for.
- **Treating the Go and TypeScript libraries as identical.**They share a model, not a feature list. Check the [feature page](https://theauth.dev/features/) for what each supports.

## Keep reading

- [Enterprise datasheet](https://theauth.dev/enterprise/)
- [Auth for B2B SaaS](https://theauth.dev/use-cases/saas/)
- [Security practices](https://theauth.dev/security/)
- [Compare with hosted vendors](https://theauth.dev/compare/)
- [theauth-go for Go services](https://theauth.dev/go/)
