Setting up single sign-on
Connect your identity provider so access follows your existing joiners and leavers process.
On this page
SSO is available on plans that include it. Check Settings → Billing or ask your account contact.
Why it is worth doing early
Not password hygiene — offboarding. Without SSO, removing someone's access is a separate task in a separate system that somebody has to remember on their last day. With it, disabling their directory account disables Hendl.
What you need
- Administrator in Hendl and in your identity provider.
- SAML 2.0 or OIDC. Entra ID, Okta and Google Workspace are all straightforward.
- A test account that is not yours. Locking yourself out of the tenant you are configuring is a genuinely bad afternoon.
Configure it
- Settings → Authentication → Single sign-on.
- Copy the ACS URL and entity ID into a new application in your provider.
- Map
emailas the identifier. Optionally map a group claim to Hendl roles. - Paste the provider's metadata URL or certificate back into Hendl.
- Test with the test account before enforcing. The test button signs in without changing anything.
- Enforce.
Break-glass access
One Administrator account keeps password access after enforcement. This is deliberate: an identity provider outage should not lock you out of your own casework. That account should have a long unique password, be held in your password manager, and be reviewed whenever you review Administrators.
Group mapping
If you map groups to roles, the mapping runs on every sign-in and overrides roles set in Hendl. Someone moved between groups in your directory changes role the next time they sign in, with the change recorded in the audit log.