Cargo Marshal
Dashboard
Cargo Marshal
Dashboard
Cargo Marshal Docs
Create your first Load PlanAxle loadsSingle sign-on with OktaSingle sign-on with Microsoft Entra IDSingle sign-on with Google WorkspaceSSO break-glass access
Guides

Single sign-on with Google Workspace

Connect Google Workspace to Cargo Marshal as a custom SAML app, verify your email domain, and let your team sign in with their Google work accounts.

Guides

SSO break-glass access

What happens when your identity provider is down while SSO is required, and how Cargo Marshal support restores access.

When Require SSO is on, people on your domain can only sign in through your identity provider. If the identity provider is down or misconfigured, nobody on the domain can sign in, including your owners and admins. There is no owner exemption: an exemption would be a password path that bypasses your identity provider's controls.

For organization owners

Contact Cargo Marshal support from an address on your verified domain and name your organization. Support turns Require SSO off for you. Password and social sign-in then work again for your domain until you turn it back on in Settings → Single sign-on.

Members who still have a session stay signed in for its lifetime, so someone on your team may still be able to turn the setting off themselves.

Runbook for Cargo Marshal support

  1. Confirm the request comes from an owner of the organization, through a channel you can verify (for example a reply from the owner's address on the verified domain, or a call to a known contact).
  2. In the Cargo Marshal admin area, find an owner of the organization and impersonate them. Impersonation is not blocked by Require SSO.
  3. Switch to the affected organization, open Settings → Single sign-on, and turn Require SSO off.
  4. Stop impersonating. Tell the owner that password and social sign-in work again, and that they should turn Require SSO back on once their identity provider is fixed.

Every impersonation is recorded in the server log with the impersonating admin and the target user.

Deleting the SSO connection also lifts the requirement, but it removes the domain verification and the link between members and their identity provider accounts. Prefer turning the requirement off.

Single sign-on with Google Workspace

Connect Google Workspace to Cargo Marshal as a custom SAML app, verify your email domain, and let your team sign in with their Google work accounts.

On this page

For organization ownersRunbook for Cargo Marshal support