Skip to main content

Granting a Single Sign-On User Access

Single Sign-On (SSO) lets your team log in using the credentials they already use for your company's identity system, removing the need for separate usernames and passwords. This article explains wha…

Jack Putt
Updated by Jack Putt

This article follows on from setting up Single Sign-On (SSO) for your account. Once SSO has been configured with your Identity Provider, you'll need to know what happens the first time a new user tries to sign in, and how to review and grant them access to the platform.

If you haven't yet configured SSO for your account, see the main Single Sign-On article for setup instructions before continuing.

What happens when a new user signs in via SSO

When someone signs in using your organisation's Identity Provider for the first time, the platform checks whether a matching user account already exists. If it doesn't, the user isn't signed in automatically - instead, they're held on a holding page at /saml/pending-access until an admin grants them access.

This ensures that simply having valid Identity Provider credentials isn't enough to gain access on its own - someone with the right permissions in the platform still needs to confirm the user should be added and decide what access they should have.

Reviewing and granting access

As soon as a user is held at the pending-access page, a Privacy Operations Ticket is automatically created to flag that access has been requested. This ticket contains workflow steps to guide you through granting the user access. The user requesting access will receive an email of the ticket that has been created, equally, any platform admins and privacy team members will also receive an email notification.

Locate the Privacy Operations Ticket

Check your ticket queue for a new ticket flagging the pending SSO access request. The ticket identifies the user's name and email address as provided by your Identity Provider.

Confirm the user should be granted access

Verify that the requesting user is a legitimate member of your organisation before proceeding. The ticket workflow will not let you continue without assigning a role.

Assign a role

Follow the workflow step in the ticket to assign the user a role. This determines the level of access and permissions the user will have once logged in.

Assign a business unit

Follow the workflow step in the ticket to assign the user a business unit. This will determine what level of data the user will have access to.

Resolve Ticker & User gains access

Once a role and business unit has been assigned, the user will then be able to access the platform. Head back to the ticket to mark it as resolved and then the user will receive a notification to say they have been granted access.

Until a role is assigned, the user cannot access the platform.
You can review or change a user's role and business unit at any time after access is granted from the Organisation and Users pages within the Configuration menu.
Only users with the appropriate permissions to manage Privacy Operations Tickets and platform admin permissions will be able to complete this workflow and grant access.

How did we do?

Setting up Single Sign-On

Contact