Skip to content
Xavi Creus

Security & compliance

Single Sign-On (SSO)

Single sign-on (SSO) lets people log in once with one identity and access all their work applications, with access managed centrally by the company.

Definition

Single sign-on, SSO, is a system where a person authenticates once with a central identity provider and is then granted access to all the applications they are entitled to use, without separate passwords for each. The identity provider, such as Microsoft Entra ID, Google Workspace or Okta, vouches for the user to each application through standards like SAML and OpenID Connect. For the user it means one login; for the company it means one place to control access.

In a company, SSO is what makes onboarding and offboarding clean. A new hire receives one account and automatically gets the right tools for their role. When someone leaves, disabling that single account cuts their access to everything within minutes, instead of IT hunting through 40 separate SaaS admin panels for weeks. It also lets you enforce multi-factor authentication and password policies once, centrally, and gives you a single log of who accessed what.

The misconception is that SSO is an enterprise luxury. Companies with 20 people already have dozens of SaaS tools and a real offboarding problem, and identity providers are cheap at that scale. For companies that sell software, supporting SSO is a common requirement in enterprise deals and often the gate to larger contracts. One genuine trade-off: the identity provider becomes a critical dependency, so it must itself be protected with strong MFA and monitored closely.

In practice

A company with 100+ people discovered that a former contractor still had access to its analytics platform eight months after leaving, because the tool was never on the offboarding checklist. After moving all applications behind SSO, offboarding became one click that revokes everything.

Why it matters

SSO is how you answer the question "who has access to what" with a report instead of a guess. It shortens onboarding, closes the offboarding gap that most companies quietly have, and it is a prerequisite for selling to larger customers if you build software.

Frequently asked questions

What is the difference between SSO and MFA?
SSO reduces the number of logins by letting one identity open many applications. MFA strengthens each login by requiring a second proof of identity. They complement each other: a good setup uses SSO for convenience and central control, with MFA enforced on the single sign-on itself.
Do small businesses need single sign-on?
Once you have more than a handful of employees and a dozen SaaS tools, yes. SSO makes onboarding and offboarding reliable, lets you enforce security policies once, and identity providers bundled with Google Workspace or Microsoft 365 already cover most of it at little or no extra cost.

Need this explained for your company?

One hour with me is usually enough to turn the vocabulary into a decision.

Book a session