Glossary
Single sign-on
Also called: SSO, OIDC, federated authentication
Single sign-on lets users authenticate to an application using an identity provider they already use. In a document system its primary value is not convenience but lifecycle: a leaver disabled in the directory can no longer authenticate, with no separate step to forget.
Single sign-on explained
The control it provides
The most common access-control failure in any organisation is a leaver who still has access to a system nobody remembered to update. Single sign-on removes the possibility: authentication depends on the directory account, so disabling the account disables access everywhere at once.
That is a stronger argument than the convenience of one fewer password, and it is the one worth making to a security team.
Group-to-role mapping
With OIDC, group membership can be carried in the token and mapped to application roles, so access rights follow directory membership. Adding someone to a group grants their access; removing them revokes it at their next sign-in.
The practical caveat is timing: roles are evaluated from the token, so a role change applies at next sign-in rather than immediately. For urgent revocation, disable the account rather than changing groups.
What it does not solve
Provisioning. Single sign-on governs authentication, not account creation, so a new starter may still need an account created before they can sign in. SCIM addresses that separately, and large tenants usually expect both.
It also does not reduce the need for role design. Mapping groups to badly designed roles produces badly designed access, faster — and at greater scale, because the mapping applies to everyone at once rather than to whoever an administrator remembered to update.
FAQ
Single sign-on: common questions
Is SAML or OIDC better?
OIDC is the more modern choice and is simpler to implement and debug. SAML remains widespread in enterprise estates. If both are available, prefer OIDC.
Does SSO remove the need for two-factor authentication?
It moves the requirement to the identity provider, where it should be enforced. It does not remove it — and roles with approval or administrative authority are worth requiring it for regardless.
Related terms
- Access reviewAn access review is a periodic check that the people who have access to something still need it.
- API keyAn API key authenticates a program rather than a person.
- Break-glass accessBreak-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
- Data residencyData residency is the commitment that data is stored and processed within a specified country or region.
- Encryption at restEncryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Permission inheritancePermission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
Última revisão: 28 de agosto de 2026. Browse the full glossary.