Yes, enterprise sign-in is supported, so access to Heidi follows your identity provider: people join and leave Heidi when they join and leave your directory, and your existing access policies apply.
Identity is the anchor for everything else in Heidi: permissions on facts, visibility of answers, and approval authority all key off who is asking. Tying that to your identity provider keeps one source of truth.
Offboarding is the quiet win: when someone leaves your directory, their access to the brain goes with it, automatically, while everything they taught Heidi stays.