What is single sign-on?

Single sign-on
Single sign-on lets people use one set of credentials, held by a central identity provider, to access multiple applications instead of a separate login for each.

What single sign-on means in practice

Convenience is how it gets sold and it is the smaller half of the benefit.

The larger half is leaving. Disable one account and every connected tool closes at the same moment, which is the step small companies most often miss.

Password behavior improves as a side effect. One strong credential with a second factor beats a dozen reused ones by a wide margin.

The cost is concentration. That identity becomes the key to everything, which is why the second factor stops being optional.

What people get wrong

Offboarding on a Friday: 44 minutes or one click

Say your bookkeeper's last day is Friday and she had logins to 11 tools, including email, the phone system, the CRM, payroll and two bank portals. Without single sign-on, someone has to remember all 11 and remove her from each one as an admin. Allow four minutes per tool and that's 44 minutes, if the list in your head is complete. It usually isn't. Nobody's job includes remembering the design tool she set up herself in 2023.

With single sign-on through Google Workspace or Microsoft Entra ID, you suspend one account at 5:00 pm. Every app that trusts that identity provider refuses her next login. Your banks won't be connected, so the manual list shrinks from 11 to 2. You've turned a memory test into a checkbox, which counts most on the day somebody leaves unhappy.

The pricing catch, and when to wait

Here's what rarely makes the feature page. Many software companies keep SAML and OIDC sign-in, the two standard protocols, for their most expensive plan. IT people call this the SSO tax, and it can raise your price per seat sharply. Check which plan it appears on before you build a policy around it.

You have a cheaper middle step. A "Sign in with Google" or "Sign in with Microsoft" button gives you much of the offboarding benefit at no charge. The login still depends on an account you control. Ask each vendor whether that button can be made the only way in, since a leftover password login defeats the purpose.

With three people and five tools, a shared list of who has what and a password manager will do. Past ten people or so, or the first time you find an ex-employee still active somewhere, it's time.

How GreetKeeper handles it

GreetKeeper is a small product and we are not going to claim an enterprise identity integration we cannot point you at.

What you can do today is keep the number of accounts small and remove them promptly, which does most of the same work.

If single sign-on is a procurement requirement, say so on a demo rather than assuming, because it will shape whether we are the right fit.

Single sign-on questions

Is it more secure than passwords?

Usually yes, because it concentrates effort on one credential worth protecting properly. That only holds with a second factor on it.

What happens if the provider goes down?

Nobody logs in anywhere, which is the trade you accept. Break-glass accounts exist for exactly that morning.

Does a small business need it?

Need is strong. What every business needs is a reliable way to remove someone's access everywhere on their last day, and this is the cleanest one.

Hear it take one of your calls

Two minutes, your own scenario, no card.