The Just-in-Time (JIT) feature in Clarity allows for the automated creation and dynamic updating of user accounts during the SAML authentication process. By leveraging attributes passed in a SAML assertion, Clarity can create a new user "on the fly" with required details such as name and email, or synchronize an existing user's security permissions and profile attributes every time they log in. This ensures that user data in Clarity remains consistent with the organization’s central identity directory without requiring manual administrative overhead for every personnel change.
To facilitate this exchange, the Identity Providers (IdPs) use an Application Profile (often referred to as a Service Provider (SP) Configuration). The Application Profile is a dedicated "Clarity-specific" space within the IdP. While the IdP maintains a single central record for a user, the Application Profile specifies exactly which data points—known as Custom Claims or SAML Attributes—should be packaged and sent to Clarity. The Mandatory Attributes to Create a User and the Optional Attributes to Update User Records tables on this page include mappings between SAML attributes and Clarity attributes that IdP administrators can use when sending SAML requests to Clarity.