User management in Fable
Last updated: February 23, 2026
Overview
Fable uses your identity provider (IdP) and directory integrations to automatically manage employee access. In most cases, user creation and deactivation happen automatically, with minimal manual intervention required from administrators.
Access in Fable is all-or-nothing: users either have access to the platform and content, or they do not.
Creating users
1. Automatic user creation (recommended)
By default, users are created automatically through your identity provider using Just-in-time (JIT) provisioning.
When an employee signs in via SSO for the first time, they are automatically created in Fable.
New users are assigned the Employee role by default.
Supported identity providers include:
Google
Microsoft
Okta
If you have multiple integrations installed (for example, Okta + Google), Fable resolves users based on your configured source of truth. See Source of truth below for details.
2. User creation via identity integration (without SSO)
If SSO is not enabled, Fable can still create users using your configured identity source of truth (for example, Google, Workday or another directory integration).
Users are automatically created based on the identity integration.
Users authenticate using a password-based login.
User activation and deactivation are driven by the connected identity system.
Note: Fable does not require users to sign in unless they are accessing the Fable platform directly. Trainings are delivered via email or messaging platforms using secure magic links.
3. Manual user creation
Admins can also manually create users:
Go to User management.
Click Add new user.
Enter the employee’s information
Select the employee's role in Fable and save.
Note: Manual creation is typically only recommended for edge cases or temporary access needs. Most customers rely on automated provisioning.
Deactivating users
Automatic deactivation
Fable automatically deactivates users based on your integrations:
If you use SSO
User deactivation is managed by your identity provider. When a user is disabled in your IdP, their access to Fable is removed automatically.If you do not use SSO
Fable listens to your connected directory or HR system (such as Google or another source of truth). When a user is marked as deactivated there, they are removed from the active user list in Fable.
Manual deactivation
At this time:
Users cannot be manually removed from Fable.
User lifecycle is fully controlled by your connected identity or directory systems.
Contact your Fable account manager to have users removed manually.
Source of truth for users
If multiple integrations are installed (for example, Okta + Google, or Workday + Google):
Fable uses a single source of truth to resolve employee identity and status.
The source of truth determines:
Whether a user is active or deactivated
Which user record is authoritative
If you’re unsure which system is acting as your source of truth, contact Fable support for confirmation.