Syncing Form, Class and Year-Level Information with SSO
When patrons sign in using Single Sign-On (SSO), ePlatform can use information sent by your identity provider to assign their form, class, or year level.
If accounts are being created successfully but form, class, or year-level information is missing, review the SSO attribute mapping and the information supplied by your identity provider.
How syncing works
During SSO, ePlatform receives SAML attributes or claims from your identity provider. These attributes determine which information is added to the patron’s ePlatform account.
If the SSO configuration includes an attribute for form, class, group, or year level, ePlatform can use the supplied value to assign the patron to the corresponding year level.
The patron’s information is received when they sign in. If the mapped value changes in the source system, the updated information can be sent to ePlatform during a later sign-in.
Required SSO attributes
Basic SSO attributes may include the patron’s:
- name;
- email address; and
- username or barcode.
These basic attributes may allow ePlatform to create the patron account, but they do not provide form, class, or year-level information.
To sync this additional information, the SSO assertion must include the relevant attribute or claim from your identity provider.
| SSO information | Result in ePlatform |
|---|---|
| Basic account attributes only | The patron account can be created, but form, class, and year-level information remains blank. |
| Form, class, group, or year-level attribute included | The supplied value can be aligned with the corresponding ePlatform year level. |
| Mapped value changes in the source system | The updated value can be received when the patron signs in again. |
Update the SSO attribute mapping
Updating the SSO attribute mapping is the recommended way to keep form, class, or year-level information synchronised.
- Confirm that the required information exists on the user account in your identity provider.
- Ask your IT or identity-provider administrator to identify the corresponding attribute or claim.
- Include that attribute in the SSO SAML assertion sent to ePlatform.
- Record the exact attribute or claim name being used.
- Contact ePlatform Support so the supplied values can be captured and aligned with the corresponding ePlatform year levels.
Attribute names and configuration steps differ between identity providers. Your IT team should use the instructions for your provider when changing the SAML assertion.
Test the mapping
After changing the attribute mapping, test it with accounts containing known form, class, or year-level values.
- Select two or three test accounts in your identity provider.
- Confirm the form, class, group, or year-level value assigned to each account.
- Sign in to ePlatform using the first test account and the configured SSO method.
- Sign in to ePlatform separately using an administrator account.
- Go to Admin area → Patrons.
- Locate the test patron.
- Confirm that the expected year-level information appears.
- Repeat the test with the remaining accounts.
If you change a test account’s value in the identity provider, ask the patron to sign in again before checking the updated patron record in ePlatform.
Bulk update patron information
If your SSO connection provides authentication details but does not send form, class, year-level, or role-related attributes, you can populate year-level information using a spreadsheet.
- Sign in to ePlatform using an administrator account.
- Go to Admin area → Patrons.
- Select Import / Update Patrons.
- Download your current patron list.
- Fill in or update the Year Level column with the correct value for each student.
- Upload the updated file.
- Open the Patrons page and check the updated records.
Updating these values by spreadsheet does not change how patrons sign in. They can continue using their normal SSO credentials.
Use this spreadsheet option only when your SSO connection is not sending year-level or role-related attributes.
If information is still missing
If the patron can sign in but the expected information does not appear:
- Confirm that the test account contains the correct value in the identity provider.
- Confirm that the corresponding attribute is included in the SAML assertion.
- Confirm that the attribute contains a value during the test sign-in.
- Record the exact attribute or claim name.
- Contact ePlatform Support with the test results.
Need help?
If form, class, or year-level information is not syncing, submit a support request or email support@eplatform.co.
Include:
- your library name;
- the identity provider being used;
- the attribute or claim name being sent;
- an example value supplied by a test account; and
- whether the issue affects one patron or multiple patrons.