SSO / Enterprise login
The identity-provider path that lets an organisation authenticate its members without product-held passwords.
Onboarding & Auth · 7 checks · 1 resource
Before you ship
7- 01Email-first routing — a single email field that detects the domain and redirects to the correct identity provider automatically
- 02Explicit 'Sign in with SSO' entry point — for users whose domain is not auto-detected, accepting a workspace slug or company email
- 03Provider handoff state — a visible interstitial while redirecting to Okta, Entra, Google Workspace, or the customer's own IdP
- 04Just-in-time provisioning outcome — a clear result when a first-time SSO user is created, including which role they were assigned
- 05SSO-required enforcement — a clear message when password login is blocked by policy, naming the admin or domain that enforces it
- 06Failure messages that name the cause — unmapped user, expired assertion, misconfigured certificate, or domain not verified
- 07Break-glass path — a documented fallback for admins when the identity provider itself is unreachable