Identity & access

SaaS License & Feature Checker

Which documented plan or add-on gives you enterprise SSO, SCIM, or an administrative audit log — with the caveat that matters and a link to the official source.

Three admin controls, normalized across common SaaS vendors from first-party documentation. No prices, no scores, no recommendations.

Free
No login
Source
First-party
Output
Plan / add-on + proof

Evidence boundary

CertPilot summarizes first-party vendor documentation for three admin controls — enterprise SSO, SCIM, and administrative audit logs. Plans and packaging change; confirm the current entitlement with the vendor before purchasing or changing a subscription. This is not pricing data, a recommendation, a security score, or a tenant inspection.

Checker

Compare admin controls by plan

Pick a capability and up to three vendors, or explore one vendor's three controls. Results are deterministic and link to the first-party proof.

Mode
Capability / vendor
Compare
Up to 3
How do you want to start?
1 · Choose one capability
2 · Choose up to three vendors

3 of 3 selected — deselect one to swap.

Enterprise SSO

3 vendors

1Password

1Password Business

IncludedOIDCSelf-serve
Min. route
Business

"Unlock with SSO" is OIDC only (Authorization Code + PKCE), not SAML, and is authentication-only. Available on 1Password Business with IdPs including Entra ID, Okta, Google, OneLogin, Duo, JumpCloud, Ping, and Auth0.

Official sources

Atlassian

Atlassian Cloud + Atlassian Guard

Paid add-onSAMLSelf-serve
Min. route
Atlassian Guard Standard
Add-on
Atlassian Guard Standard

"Enforce single sign-on (SSO) for all managed users" is delivered by the Atlassian Guard Standard add-on (on top of Cloud Standard/Premium), not a base app tier. SAML; Google Workspace SSO is also supported.

Official sources

Figma

Figma

IncludedSAMLSelf-serve
Min. route
Organization

SAML SSO is available on Organization and Enterprise plans and is configured by organization admins.

Official sources

Related discovery

Open a full vendor profile

Each vendor page carries all three controls, the plan and add-on map, protocol, caveats, and official sources with checked dates.

Method / Publication

How the checker works

One normalized evidence shape turns fragmented vendor documentation into a stable plan-and-control answer.

  1. 01Each control is written from official first-party sources — vendor pricing, plan-comparison, and admin help pages. Third-party pricing databases and SSO/SCIM directories are never used as evidence.
  2. 02Every result is human-verified against its source and shows the source link and a checked date. A control with no clear first-party answer is marked unclear, never guessed.
  3. 03Availability is normalized to included, enterprise-only, or a paid add-on, kept separate from whether the purchase is self-serve or sales-led. Enterprise SSO also records its protocol.
  4. 04No numeric prices are stored or shown — plans and packaging change, so the checker maps to plan and add-on names and links you to the vendor for the current price.
  5. 05Profiles are re-checked on a 90-day cadence and drop out of the tool automatically after 120 days without re-verification.

Reference / FAQ

Frequently asked questions

What does the SaaS License & Feature Checker do?

For a set of common admin controls — enterprise SSO, SCIM / automated provisioning, and administrative audit logs — it shows the lowest plan or paid add-on that documents the control on each vendor, the caveat that matters, and a link to the official source. It is built for a security review, renewal, or purchase decision.

Which capabilities does it cover?

Exactly three: enterprise SSO (with the documented protocol — SAML or OIDC), SCIM / automated provisioning, and administrative audit logs. These are the controls that are consistently documented and plan-gated across vendors. It is not a generic feature comparison.

Does it show prices?

No. Prices vary by country, term, seat count, and negotiation, and enterprise and add-on pricing is often contact-sales. The checker shows the documented plan or add-on name and whether it is self-serve or sales-led, then links you to the vendor's own page for the current price.

Why does it distinguish SAML from OIDC?

Because "single sign-on" is not always SAML. 1Password's "Unlock with SSO", for example, is OIDC only — reporting it as SAML would be wrong. Each SSO result records the protocol the vendor actually documents.

How is an add-on like Atlassian Guard handled?

Honestly, as an add-on. Atlassian's SSO, SCIM, and organization audit log come from the paid Atlassian Guard add-on layered on a base Cloud plan — not a Jira or Confluence tier. The checker labels that as a paid add-on and names it, rather than inventing a fake plan.

Where does the data come from, and how current is it?

Every result is written from an official first-party vendor source — pricing, plan-comparison, and admin help pages — and shows when it was last checked. Plans change, so each vendor is reviewed on a 90-day cadence and drops out of the tool if its sources go more than 120 days without re-verification.

Is this a recommendation or a tenant check?

No. It summarizes public vendor documentation. It does not recommend a vendor, score security, read your tenant, or confirm your specific entitlement — always confirm the current plan with the vendor before you buy or upgrade.

From capability to evidence

Want this personalized to your own IT stack?

CertPilot keeps registers of the vendors, systems, and access your team actually manages — and turns checks and registers into management-ready evidence reports. Tell us which vendors you would want a plan-and-control map for.

← View all free tools