Single Sign-On SSO

One username and one password that open every system a member of staff is allowed to use, on the computer and on the phone.

Also known as SSO one login for everything unified login

Definition

Single sign-on means one login opens everything a member of staff is allowed to use. One username, one password. The system on the office computer, the app on the delivery driver's phone, the branch in the next city, the same account opens all of them. A person signs in once in the morning, and the software stops asking for the rest of the day.

The point is not comfort. It is control. A business running four separate systems keeps four lists of who works there. Someone leaves, three lists get corrected, and one is forgotten. That forgotten account still works months later, and nobody notices, because nobody is looking at it. With one login there is one list. You switch a person off on their last day and every screen and every phone closes to them in the same minute.

The bigger risk in most small companies is not a stranger on the internet. It is the shared account, one manager login that four people know, written on a card in a drawer. When the till is short, or a price changed overnight, the record says manager, and manager is everybody. Giving each person their own account costs nothing and answers the question. Linkysoft treats that as the first step of any security review, long before anything expensive is discussed.

One door also makes a second lock worth fitting. A two-factor code is six digits from an app on the phone, typed after the password. One password and one code is safer than five passwords and no code, and staff only do it once a day instead of five times. That trade is why the two ideas are usually sold together.

There is a fair objection to all of this. If one login opens everything, a stolen password opens everything. True, which is why the code matters, and why a screen on a shared counter should sign itself out after a few quiet minutes. Ask a supplier two questions before you sign. How many minutes does it take to remove one person completely? And does the mobile app use the same accounts as the website, or a second list nobody remembers to update? When Linkysoft builds a web application the answer is one list, because a second one is a list that will be wrong one day.

Questions about Single Sign-On

Is single sign-on safe if one password opens everything?
It is safer than what it replaces, which is usually the same weak password written down and reused in five places. Add a code from a phone app, and one strong door beats five weak ones.
Does it cover the mobile app as well as the website?
It should, but ask the supplier plainly. Some mobile apps keep their own separate list of users, and that hidden list is the one nobody cleans up when a person leaves.
What happens the day a member of staff leaves?
You switch off one account and the access ends everywhere at once: office computer, phone app, every branch. Done properly it takes a minute, not a week of chasing separate systems.
Can I still control who sees what?
Yes, and the two things are separate. The login says who you are. The permissions say what you may open. A cashier and an accountant sign in the same way and see completely different screens.
Do two-factor codes cost extra?
Usually not. A free app on the phone shows the six digits and the system checks them. The real cost is ten minutes of training per person, and a plan for the day someone loses their phone.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.