What Single Sign-On Actually Gives You
-
One identity, inherited controls
Users sign in with corporate credentials; password policy, MFA enforcement and conditional access come from your identity provider. No second control set to maintain or let drift, which is the actual benefit rather than convenience. -
Provisioning that keeps up
Users added to the right identity provider group get the appropriate role and workspace access automatically. No manual creation, and no gap between starting and having access. -
Deprovisioning that does not depend on memory
Removal from the identity provider removes access. Accounts outliving employment is the most common real exposure in any organisation with turnover, and this closes it without anyone having to remember. -
Group-based access that matches your structure
Identity provider groups map to workspaces and roles, so access follows the org chart rather than a separate list somebody maintains. -
MFA where you already manage it
Enforceable for all users, admins or specific groups, at login regardless of access method. With SSO it is typically enforced at the identity provider, which is where you want it.
Why One Retention Policy Cannot Cover Fifty States
The product documentation offers an example of a workspace retaining records for a set number of years for employment law reasons. The number is not reproduced here, and the reason is worth stating: record retention obligations differ by state and by record type, and a single policy cannot satisfy all of them.
- Too short destroys records you were required to keep
- Too long keeps records that become discoverable
- Record types and contract terms both cut across it
- Whoever picks the number should not be guessing
What the Audit Log Records About You
One thing about single sign-on belongs in front of employees as well as administrators. Audit logs capture login events, with timestamp and actor, and that is by design and appropriate. It also means the record of who used the system, when, and from where exists independently of whether anyone can read the conversations.
- Content privacy and access privacy are different. Conversation content can be private to you while the fact and timing of your login is visible to your employer's security function. That distinction catches people out because the first reassurance sounds like it covers both.
- The timing itself can be informative. A login the evening before a resignation, or the day a disciplinary meeting was scheduled, is a data point regardless of what was discussed. Nothing needs to be read for that to be true.
- For a matter concerning your employer, use a personal account. On a device your employer does not manage, with an email address they do not administer. That removes the trail rather than protecting the content within it.
- Administrators should say this plainly. Employees using an SSO-provisioned account should be told what the audit log records. An organisation that logs login events without saying so has created an expectation problem for itself as well as for its people.
Login events are logged on the employer's identity system regardless of which state you live in. For a cross-border employment question, a personal account keeps it off both.
Frequently Asked Questions
Talk to the business team about a security review for an organisation based in New Hampshire.
Are you a Lawyer? Connect with our Users!