WorkOS Signup Enrichment: Turning SSO and Directory Sync Into Growth Signal
How PLG teams using WorkOS for enterprise SSO and SCIM can enrich signups, treat directory sync as instant teammate discovery, and score accounts before sales ever gets involved.
The WorkOS signup isn't really a signup
Most PLG enrichment advice assumes the same shape of event: someone lands on your site, fills in an email, and becomes a user. WorkOS breaks that assumption in a useful way. When a company connects WorkOS to your product, the person doing it is often an IT admin or security lead setting up single sign-on for a team that already pays you. The "signup" you're enriching isn't a curious individual. It's a company telling you, in plain terms, that it's serious enough about your product to put it behind its identity provider.
That's a stronger buying signal than almost anything else in a PLG funnel, and most teams don't treat it that way. They enrich the admin's email, maybe log the organization name, and move on. Meanwhile WorkOS is sitting on connection metadata, domain verification, and, if the customer uses it, a full SCIM-synced roster of every employee in that workspace. Ignoring that is like getting a company's org chart handed to you and filing it under "miscellaneous."
I've seen teams spend months building lookalike models to guess which accounts might expand, while an SSO connection event sitting in their WorkOS webhook log already told them the account was enterprise-track. The signal was there. Nobody wired it up.
What WorkOS actually gives you
Three event types matter for enrichment, and they arrive at different points in the account's life:
- Organization created: a workspace exists in your product and has been linked to a WorkOS organization ID. This can happen before any identity provider is connected.
- SSO connection initiated or activated: an admin has started or finished configuring SAML or OIDC with their identity provider (Okta, Azure AD, Google Workspace, OneLogin, and so on).
- Directory sync event: if the customer enables SCIM, WorkOS starts sending you user and group records as they change in the customer's identity provider.
Each of these is a different confidence level and a different action. An organization ID with no SSO connection is a weak signal. Could be a trial, could be someone testing the integration. An active SSO connection is a strong signal that a real IT function is involved and the account plans to stick around. A directory sync feed is the strongest signal available anywhere in your funnel, because it's not inferred. It's the customer's own identity system telling you who works there, what department they're in, and often their title.
Directory sync is teammate discovery you don't have to build
Most of the PLG enrichment industry is built around resolving uncertainty: does this personal email belong to a real company, is this LinkedIn profile actually the same person, does this teammate match the account. WorkOS directory sync erases most of that uncertainty for any customer who turns it on. You get a live feed of employee records straight from the source of truth.
That changes what teammate discovery means for these accounts. You're no longer inferring who else might work there from a fuzzy match. You have the actual roster. The job shifts from discovery to scoring: given this real employee list, who on it looks like a product-qualified user, who's already logged in, and who has never touched the product at all.
A useful pattern here is to compare the SCIM roster against your existing user table for that organization on a schedule (daily is usually enough):
- Pull the current directory sync roster for the organization.
- Match records against known users by email.
- Flag roster members with no matching product account as "provisioned, not activated."
- Score each matched user's activation against your usual PLG metrics.
- Surface the gap (provisioned employees who've never logged in) to whoever owns onboarding or customer success for that account.
That gap list is one of the more underrated growth assets available to a PLG team selling into mid-market and enterprise accounts. It's a company that already pays you, already trusts you enough to provision the whole team, and has people sitting on licenses they haven't used. That's an activation problem with a name and an email address attached to it, not a cold lead.
Scoring an account when the "user" is IT, not the buyer
The person configuring WorkOS is almost never the person who felt the pain your product solves. That means the usual ICP model (score the individual, then infer the account) runs backwards here. You should score the account first, based on what WorkOS tells you, and treat the individual admin as an operational contact rather than the primary persona.
Useful account-level signals from WorkOS events:
- Verified domain and whether it matches an existing paying customer or a self-serve trial.
- Identity provider type (Okta and Azure AD skew toward larger, more security-mature companies than a generic Google Workspace connection).
- Time from organization creation to SSO connection request: a fast turnaround usually means a security review is already underway, which itself suggests procurement momentum.
- Whether directory sync was enabled at all, and how many employee records it returned.
- Growth or shrinkage in the synced roster over time.
None of this replaces knowing who your actual product champions are. It complements it. A growth manager or RevOps team can combine WorkOS account signals with the ICP score already assigned to the individual users inside that account, using something closer to Groful's ICP scoring model than a single flat lead score.
A routing model that doesn't treat every WorkOS event as a sales trigger
Not every SSO connection deserves a Slack alert to sales. Most don't. Build routing around what the signal actually means:
- Organization created, no SSO yet: log it, do nothing urgent. Many of these never go further.
- SSO connection activated, account already paying: this is an expansion and retention signal, not a new-logo signal. Route to customer success with the roster gap analysis above.
- SSO connection activated, account still on trial or free plan: this is close to the strongest upgrade signal a self-serve product can get. An unpaid account investing in enterprise auth setup is telling you it expects to keep using the product at scale. Route to sales-assist review.
- Directory sync enabled with a large roster and low product activation: flag for customer success outreach before renewal conversations, not for a generic upsell email.
- Directory sync roster shrinking: treat as an early churn signal, especially if it lines up with reduced product usage.
This is the same discipline as any other enrichment source: separate confidence from fit from urgency, and only escalate to a human when more than one of those lines up.
Mistakes teams make with WorkOS data
The most common one is enriching the admin and stopping there. The admin's job title and seniority tell you almost nothing about whether the account fits your ICP. They're often in IT or security, not in the buying committee for your actual product. Score the account and the eventual product users; treat the WorkOS admin contact as plumbing.
The second mistake is letting directory sync data sit unused because it looks like an HR feed rather than a growth signal. Nobody on the growth team owns it, so it quietly accumulates in a database table nobody queries. If you enable SCIM support, someone needs to own turning that roster into activation and expansion work, the same way someone owns your product analytics.
The third mistake is over-alerting. Sending sales a notification every time any account touches SSO settings trains the team to ignore WorkOS alerts entirely within a few weeks. Reserve escalation for the combinations above, not the raw event.
What to measure
Track these once the pipeline is live:
- Time from organization creation to SSO connection, segmented by eventual plan tier.
- Percentage of SSO-connected accounts that upgrade within 90 days, compared to accounts without SSO.
- Roster coverage: synced directory size versus active product users, per account.
- Expansion revenue traced back to a directory-sync gap analysis outreach.
- Churn rate for accounts with shrinking synced rosters versus stable ones.
If SSO-connected trial accounts convert at a meaningfully higher rate than the general trial population, and in most B2B SaaS products they do, that's your evidence to formalize this as a routing rule rather than a one-off observation.
Where this fits into a broader enrichment stack
WorkOS enrichment isn't a replacement for the rest of your signup enrichment pipeline; it's a high-confidence layer on top of it. Most of your signups will never touch SSO or SCIM, and for those, you're still resolving personal emails, scoring individual fit, and running PLG signup enrichment the way you would for any self-serve product. WorkOS events matter specifically for the subset of accounts moving toward procurement, and they deserve their own routing lane rather than getting mixed into the general signup queue.
If you're running WorkOS alongside a broader identity setup, say Clerk for your consumer-facing signup and WorkOS for enterprise SSO, enrich both paths but keep the scoring logic separate. A Clerk signup is a person; a WorkOS SSO event is usually an account decision made on behalf of people who haven't logged in yet.
Groful can wire this into your existing onboarding personalization and product-led sales workflows, so a WorkOS SSO event or a directory sync gap turns into a specific action instead of a row in a table nobody reads. Check the blog for related integration playbooks, review pricing, or get in touch if you want help mapping your WorkOS events into account scoring and routing.
Turn this playbook into workflow
Enrich signups, score ICP fit, and surface expansion opportunities with Groful.
Published
Sep 3, 2026
Reading Time
8 min read
Tags
Workos-signup-enrichment, Sso-enrichment, Directory-sync, Icp-scoring, Teammate-discovery
Sections
- The WorkOS signup isn't really a signup
- What WorkOS actually gives you
- Directory sync is teammate discovery you don't have to build
- Scoring an account when the "user" is IT, not the buyer
- A routing model that doesn't treat every WorkOS event as a sales trigger
- Mistakes teams make with WorkOS data
- What to measure
- Where this fits into a broader enrichment stack
