Installation & Administration

CardIQ Identity Administrator Setup Guide

A practical CardIQ Identity administrator checklist for company identity, employees, integrations, lifecycle and security.

Company foundation

Company foundation

1. Create or configure the company. 2. Apply the approved company name, public profile and branding. 3. Verify the company domain where used. 4. Configure Trusted Domains. 5. Create the Company Admin with only the necessary role. 6. Review plan entitlements before enabling workflows.

Employee identity rollout

Employee identity rollout

7. Define employee identity and contact rules. 8. Add employees or use an entitled bulk/directory workflow. 9. Review activation and invitation state. 10. Configure the Public Company Profile and directory. 11. Configure approved signatures and meeting identity features where available. 12. Generate and test employee QR/NFC destinations against the canonical public profile.

Enterprise integrations

Enterprise integrations

13. Configure Microsoft Entra only for entitled companies and required Microsoft permissions. Use scoped preview and controlled sync before lifecycle automation. 14. Configure enterprise sign-in using Microsoft Entra or SAML 2.0 where approved. For SAML, enter the identity-provider details, configure the IdP with the CardIQ SP metadata/entity ID and ACS URL, validate the runtime configuration, then complete a real pilot sign-in before enabling enforcement. 15. SAML signs in existing active CardIQ users only: do not expect JIT account creation or IdP-driven CardIQ role assignment. CardIQ supports SP-initiated SAML; IdP-initiated/unsolicited SAML and SAML Single Logout are not supported. 16. If SCIM Users provisioning is enabled, validate tenant token handling and interoperability in the target environment before enablement; SCIM Groups/Bulk remain unsupported. 17. Create scoped API keys and signed webhooks only for authorized integrators.

Governance and launch validation

Governance and launch validation

18. Review MFA availability, role boundaries, security alerts, audit records and private logs. 19. Exercise lifecycle outcomes with test identities and validate offboarding across login, public profile, QR/NFC, mobile and API surfaces. 20. For enforced enterprise SSO, verify the approved tenant flow before relying on it and retain the controlled Super Admin break-glass path. 21. Review analytics access and data scope. 22. Complete the operational health checklist in the troubleshooting guide before launch.

Change control

Change control

Document the approving owner for branding, domains, administrators, integrations and lifecycle actions. Use staging where practical, avoid sharing credentials in tickets or screenshots, and repeat validation after material configuration changes.

Control how employees represent your company externally

Explore the CardIQ Identity platform or review the workflow from verification through identity deactivation.

See how CardIQ Identity works View pricing