Single Sign-On SSO

Single sign-on is one username and password that opens every system a member of staff is allowed to use, on the computer and on the phone.

Also known as SSO one login for everything unified login

Definition

Single sign-on means one login opens everything a member of staff is allowed to use, with a single username and password behind all of it. The system on the office computer, the app on the delivery driver's phone and the branch in the next city all open from that account. So a person signs in once in the morning, and the software stops asking for the rest of the day.

The point is not comfort but control, because a business running four separate systems is really keeping four lists of who works there. Someone leaves, three lists get corrected and one is forgotten, so that account still works months later. Nobody notices that it is still open, because nobody is looking at it. With one login there is only one list, so you switch a person off on their last day and every screen and every phone closes to them in the same minute.

In most small companies the bigger risk is not a stranger on the internet. It is the shared account, one manager login four people know, written on a card in a drawer. When the till is short, or a price changed overnight, the record says manager, and manager is everybody. Giving each person their own account costs nothing and answers that question, which is why Linkysoft makes it the first step of any security review, long before anything expensive is discussed.

One door also makes a second lock worth fitting, and that lock is a two-factor code, six digits from an app on the phone typed after the password. One password with one code is safer than five passwords and no code at all. Staff also do it once a day instead of five times, and that trade is why the two ideas are usually sold together.

There is a fair objection to all of this, because if one login opens everything then a stolen password opens everything too. That is true, which is why the code matters. It is also why a screen on a shared counter should sign itself out after a few quiet minutes. So ask a supplier two questions before you sign. How many minutes does it take to remove one person completely, and does the mobile app use the same accounts as the website or a second list nobody remembers to update? When Linkysoft builds a web application the answer is one list, because a second one is a list that will be wrong one day.

Questions about Single Sign-On

Is single sign-on safe if one password opens everything?
It is safer than what it replaces, which is usually the same weak password written down and reused in five places. Add a code from a phone app, and one strong door beats five weak ones.
Does it cover the mobile app as well as the website?
It should, but ask the supplier plainly. Some mobile apps keep their own separate list of users, and that hidden list is the one nobody cleans up when a person leaves.
What happens the day a member of staff leaves?
You switch off one account and the access ends everywhere at once: office computer, phone app, every branch. Done properly it takes a minute, not a week of chasing separate systems.
Can I still control who sees what?
Yes, and the two things are separate. The login says who you are. The permissions say what you may open. A cashier and an accountant sign in the same way and see completely different screens.
Do two-factor codes cost extra?
Usually not. A free app on the phone shows the six digits and the system checks them. The real cost is ten minutes of training per person, and a plan for the day someone loses their phone.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.