Ship enterprise SSO (SAML) + SCIM provisioning
Ship SAML SSO (Okta, Azure AD, Google) + SCIM v1 (deprovisioning) within one quarter to unblock $1.4M in Q3–Q4 pipeline.E-01E-02
Five stages, in the order they ran: what Juno planned to find out, what it retrieved, what it concluded, what it checked before showing you anything, and only then the recommendation itself.
- Identify customer evidence
1 customer interviews retrieved and read.
- Review support trends
2 support tickets grouped by theme.
- Review sales feedback
1 deal notes checked for revenue exposure.
- Review engineering feasibility
No engineering estimate on file; technical risk is scored from comparable work.
- Compare against strategic goals
Moves the stated enterprise-readiness goal; leadership attention currently sits elsewhere.
- Name what is still unknown
2 gaps recorded with an owner and a discovery question.
- Check for conflicting stakeholder input
1 conflict(s) surfaced rather than averaged away.
- E-013 artifacts
Enterprise deals worth $1.4M ARR are explicitly blocked on missing SAML SSO.
- E-022 artifacts
SCIM provisioning is a recurring second ask alongside SSO for enterprise IT.
- E-131 artifact
At least one enterprise VP explicitly does not need on-prem, regional residency + SOC 2 is enough.
$1.4M ARR across 4 named accounts is explicitly contract-blocked.
Affects every enterprise buyer rolling out to more than 100 seats.
Moves the stated enterprise-readiness goal; leadership attention currently sits elsewhere.
- IdP scope creep: each additional provider in v1 pushes the date past the Q4 signature window.
- SCIM scoped to deprovisioning may not satisfy every compliance team, which would reopen the blocker.
- Leadership attention is on on-prem, so the work may compete for the same enterprise engineering capacity.
- Engineering estimate of 6–8 weeks holds after IdP scoping.
- Customers accept SCIM v1 scoped to deprovisioning.
Ranks first because it is the only opportunity with named, contract-blocking revenue corroborated across sales, support, and finance.
Four named enterprise deals ($1.4M ARR) are contract-blocked on SAML SSO, with SCIM provisioning as a recurring second ask. Competitor already ships both.
Highest priority-score. $1.4M ARR is the single largest documented blocker, evidence spans 4 artifacts across sales, IT tickets, and CFO rollup, no single-source dependency.
Recommendation quality
How well supported this recommendation is, measured against the evidence Juno could actually retrieve.
4 of 6 enterprise source types contributed at least one artifact.
Support Ticket, Sales Note, Executive Request, Customer Interview
Disagreements are shown in Risks rather than resolved by Juno.
Whether every section of the brief could be filled from retrieved evidence.
No recommendation advances to the roadmap without an explicit decision.
Findings resting on one artifact are held at lower strength rather than stated with certainty.
Supporting evidence
Evidence strength reflects how many independent artifacts support this recommendation and how varied they are, not how certain the model sounds.
| Finding | Artifact | Severity | Corroboration |
|---|---|---|---|
E-01Fact Enterprise deals worth $1.4M ARR are explicitly blocked on missing SAML SSO. | Support Ticket Ticket #48213: SSO/SAML required for procurement | High severity | High confidence 3 artifacts |
E-02Fact SCIM provisioning is a recurring second ask alongside SSO for enterprise IT. | Support Ticket Ticket #48213: SSO/SAML required for procurement | High severity | High confidence 2 artifacts |
| Finding | Artifact | Severity | Corroboration |
|---|---|---|---|
E-13Fact At least one enterprise VP explicitly does not need on-prem, regional residency + SOC 2 is enough. | Customer Interview Interview: Sam, VP Eng (enterprise) | High severity | Med confidence 1 artifact |
Transparent scoring model
Risks
- IdP scope creep: each additional provider in v1 pushes the date past the Q4 signature window.
- SCIM scoped to deprovisioning may not satisfy every compliance team, which would reopen the blocker.
- Leadership attention is on on-prem, so the work may compete for the same enterprise engineering capacity.
Est. 6–8 weeks; concern about SCIM edge cases.
Leadership is publicly prioritizing on-prem (E-11), but pipeline data (E-01) points to SSO as the actual revenue blocker.
Additional discovery recommended
Juno names what it does not know, who can answer it, and how to ask, so limited confidence turns into a discovery step rather than a dead end.
Why it matters: Determines whether Okta, Azure AD and Google cover v1 or whether a fourth provider is required to unblock the revenue.
Why it matters: A narrower v1 halves the build, but only if compliance teams accept it.
- Which IdPs must ship in v1 (Okta, Azure AD, Google, others)?
- Do we scope SCIM to deprovisioning only, or full lifecycle?
Recommended next step
Confirm IdP + SCIM scope with 3 enterprise IT contacts
Hypothesis: Okta + Azure AD + Google cover ≥80% of blocked deals; SCIM deprovisioning is acceptable as v1.
Juno proposes this step because it would close the largest gap listed above. You decide whether to run it.
Decision required. Juno recommends, you decide, and nothing reaches the roadmap without you.
Final prioritization decisions remain the responsibility of the Product Manager.
