Sastrify’s IdP Discovery feature provides organization-wide visibility into the SaaS tools your employees access daily. By monitoring sign-in activity through your Identity Provider (IdP), the platform identifies both sanctioned applications and independent "shadow" tools, ensuring your software stack is always accurate and up-to-date.


Identity Provider (IdP) Discovery analyzes your IdP logs (Google Workspace, Microsoft Entra ID, Okta, etc.) to detect when a user authenticates into any SaaS applications using company credentials.


Once detected, new tools appear in the Discovered tab within your Tool Stack. From there, you can quickly review and categorize each one—marking it as “In Use” or archiving it if it’s not relevant to your current subscriptions. Continuous detection keeps your stack accurate and up to date, giving IT and compliance teams real-time visibility into tool usage and potential shadow IT.


Setting Up Discovery via your Identity Provider (IdP)



Requirement: To enable this integration, you must have Admin permissions in both Sastrify and your selected IdP.


  1. Navigate to Integrations > Discovery & Usage.

  2. Locate your provider (Google Workspace, Microsoft Entra ID, Okta, or JumpCloud) and click Connect.

  3. Toggle "Usage Analytics". Ensure the switch is set to Active to enable tracking of login patterns.
  4. Authenticate:
    • Google/Microsoft: Sign in and accept the authorization prompt.
    • Okta: Enter your OAuth 2.0 app credentials. See our Okta Step-by-Step Guide for details.


Note on Spend: IdP Discovery does not collect spend data. It focuses purely on "Who is using what." To see the financial impact of discovered tools, we recommend connecting your ERP/Accounting software.

Data Retrieved by IdP Discovery


To protect privacy while providing deep insights, Sastrify only retrieves the following data points related to the login event:

  • User Identity: ID and email address.

  • Login Activity: Success/Failure status and timestamps.

  • Application Context: The name and URL of the tool being accessed.


Managing Your Discoveries



Once connected, you can then take action from the Discovered tab of your tool stack:

  • Review detected tools.
  • Decide whether to move tools to the In Use tab or mark them as Inactive.
  • Assign tool owners before moving tools to the In Use tab.
  • Search and filter the list for easier review.

Frequently Asked Questions


Please refer to the Identity Provider (IdP) Discovery FAQ page for a complete list of frequently asked questions