Agent Cake Now Signs In Through Google SSO
Auto-Provisioning Has Depended on Two Standards
Agent Cake, Cakewalk's AI provisioning agent, now signs in through Google SSO. Apps that enforce Google sign-in therefore stay inside auto-provisioning instead of going back to somebody creating accounts in them by hand.
We ask every new customer which apps their identity platform provisions today. The answer is usually a short list. That short list has a cause, which sits in the two standards auto-provisioning has depended on.
SCIM Covers a Fraction of the Apps a Company Runs
System for Cross-domain Identity Management (SCIM) is the API standard for creating, updating and deleting accounts. It works well where it exists, which is the problem. A Stitchflow analysis of 721 SaaS apps found that 42% put SCIM behind enterprise pricing, while 57% do not offer it at any price. That left nine apps in the sample including it on a base tier. A platform that provisions through SCIM alone therefore automates the apps a company already pays the most for.
Just-in-Time Provisioning Leaves the Departure Unhandled
Just-in-time provisioning takes another route. When somebody signs in through Security Assertion Markup Language (SAML), the app creates the account out of the login itself. That covers the account and little else, because the new user typically lands on a default role, so an admin still sets the real permission level by hand. And because a login is the trigger, nothing fires when somebody leaves. Those accounts therefore stay behind as dormant access with no owner, which is what an auditor finds in an access review.
Agent Cake Provisions the Apps That Never Offered an Interface
Agent Cake provisions an app in one of two ways, depending on what the app exposes. Where a provisioning API comes with the app's standard plans, Agent Cake uses it. Where that API exists only on an enterprise tier or not at all, Agent Cake signs in with a scoped service account and performs the change directly.
A grant then creates the account and assigns its permissions, while an offboarding suspends or removes it. Every run appears in the app's execution log.
Because Agent Cake asks the app for nothing, the app needs no SCIM support and the company needs no upgrade to its enterprise plan.
Apps Behind Google SSO Stay Automated
Enforcing single sign-on is good security, because it puts every login behind one identity provider, so access can be cut off in one place when somebody leaves and no app keeps a password of its own. It also removes the app's own password form, which leaves the admin account with Google as its only way in.
Before this release, that left two options. Re-enabling password login for a shared admin account puts a credential outside the company's identity provider, which puts it outside offboarding too. The alternative keeps that credential out while it hands the app back to a person, so every app the SSO policy covers becomes another app where somebody creates each account by hand and removes it by hand when that person leaves.
Agent Cake now signs in through Google instead. An app therefore stays automated after its SSO policy goes on, without any password staying alive outside the company's identity provider to keep it that way.
One Dedicated Google Account Covers Every Wired App
Agent Cake signs in with a dedicated Google Workspace account that an admin creates as a service account, never with a person's own login. That account needs no privileges in Google Workspace itself, because Agent Cake does no provisioning inside Google. Its permissions live in the target app instead, where it needs enough rights to create users and assign roles.
One account then covers every app wired for it, so an admin connects it once instead of creating a separate service account and password for each app Agent Cake provisions.
Admins can review the account, scope it, rotate it and switch it off. It also appears in an offboarding run like any other account. There is no OAuth consent screen and no token on the company's Google Workspace, so Cakewalk holds no standing permission to call Google's own APIs for mail, files or directory data.
The Sign in with Google guide has the setup steps and the account requirements.
The Credentials Stay Encrypted Until a Run Needs Them
The account keeps 2-Step Verification switched on. When Google asks for the second factor at sign-in, Agent Cake answers with a time-based one-time password, which is the rotating code an authenticator app generates. Some apps also enforce their own two-factor authentication on top of the Google sign-in, which takes a second code belonging to the app rather than to Google. The multi-factor authentication guide covers both.
Credentials are encrypted in the browser before they are sent, so they never travel in plaintext. Cakewalk then stores them in a database dedicated to that company and decrypts them in memory only at the moment a provisioning run uses them, through Amazon KMS, which logs every decryption event. Nothing is written or logged in plaintext. The decrypted values are discarded when the job finishes, as the security and data protection guide sets out in full.
Agent Cake Covers the Apps SCIM Prices Out
Agent Cake provisions apps that never shipped SCIM as well as apps whose vendor sells it on the enterprise tier, so a company covers its stack without buying an enterprise plan per app to turn provisioning on. IT and app owners therefore stop spending hours creating accounts by hand and removing them one at a time when somebody leaves.
Apps behind a Google SSO policy now belong in that set.
