Skip to main content
Turn on AWS IAM Identity Center (formerly AWS SSO) to manage user access across environments.

Prerequisites

🔗 Open the Identity Center Console
  1. Click Enable on the welcome screen Enable Identity Center Figure: Click the Enable button to begin Identity Center setup.
  2. Verify your region Check that the region is set to your intended deployment region (e.g. us-east-2). If not:
    • Click the Region Selector at the top right.
    • Choose the correct region.
    • Click Enable again to confirm. Enable Identity Center Figure: Validate and confirm your region.
Your region selection affects where Identity Center resources are created. Verify this before proceeding.
Using Google Workspace? The CLI can walk the whole enablement, SAML, and SCIM connection for you: fjall org identity setup-google.

Choose an identity source

Once Identity Center is enabled, decide who owns your user objects — this becomes the source of the identityCentre block in your organisation config: See Users and Permissions for the config shapes and day-to-day workflow.

Next Steps

Configure Deployment Credentials

Set up OIDC or SSO credentials for deploying infrastructure

Deploy Organisation

Create and deploy your AWS organisation