Offboarding SAML viewers from a private status page

To prevent new sign-ins, end existing sessions and stop notifications, revoke the person's access in your identity provider and delete their corresponding subscriber record in Sorry.

This article covers people who view a private status page using SAML. For colleagues who manage your pages, see team-member SSO.

Does revoking access in the identity provider end access automatically?

Once your identity provider refuses authentication, the person cannot start a new SAML session. Existing Sorry sessions are not ended automatically, and their subscriber record is not automatically removed.

For standard employee accounts using Microsoft Entra group-based access, the application must require assignment and the user must have no other direct or group assignment remaining. The change takes effect when Entra enforces it. Global Administrators are exempt from the assignment requirement. See Microsoft's application assignment guidance.

What record does signing in create?

SAML sign-in creates a subscriber record associated with the viewer's email address.

Revoking Entra access does not delete, deactivate or unsubscribe that record. The subscriber and their notification preferences remain until separately changed or removed in Sorry.

How long can an existing session remain active?

There is no fixed maximum lifetime for a session kept active through continued use. Sessions are cleaned up after 30 days of inactivity. This is not a guarantee that access ends within 30 days of offboarding.

How do I end existing access and notifications?

  1. Revoke the person's access to the application in your identity provider so they cannot sign in again.
  2. In Sorry's interface, delete the corresponding subscriber. This immediately ends all their existing sessions and stops further notifications.

Both actions matter. Revoking identity-provider access alone leaves existing sessions in place. Deleting the subscriber alone does not prevent a new sign-in if the identity provider still grants access.

Can I automate subscriber cleanup?

Yes. You can delete subscribers directly in Sorry's interface, or use the Subscribers API to automate record removal as part of your own offboarding workflow.

Revoking Entra access does not automatically trigger subscriber deletion in Sorry. Your workflow needs to perform that step separately.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us