HousingSurvey Pro Logo
HousingSurveyPRO

SSO end to end

Who can do thisPermission: settings ≥ 3Enterprise plan and above

Single sign-on connects HousingSurvey Pro to your organisation’s identity provider, so staff sign in with their existing corporate credentials instead of a separate password.

What it is

SSO applies to email/staff accounts — field surveyors without email continue to use tenant logins. Three connection types are supported: SAML (via your identity provider’s metadata), OIDC (for example Microsoft Entra ID), and Google Workspace domain sign-in. Home-realm discovery routes a signing-in user to the right connection based on their email domain, and each domain can be connected to exactly one organisation.

Before you start

Setting up SSO requires organisation-admin access to Settings, and is an Enterprise-plan feature.

How to do it

  1. Open Settings → SSO & provisioning.
  2. Choose your connection type — SAML metadata, OIDC (Entra ID), or Google Workspace — and provide the details the page asks for, along with the redirect URL it shows you.
  3. Register HousingSurvey Pro as an application in your own identity provider, using those same details.
  4. Assign the users or groups who should have access, on your identity provider’s side.
  5. Save the connection and test a sign-in. Keep at least one org admin able to sign in by another means while you set this up, so nobody is locked out mid-configuration.

How it integrates

Access follows your directory: when someone leaves and is disabled in your identity provider, their ability to sign in here goes with it. For automated joiner/mover/leaver provisioning rather than sign-in alone, see SCIM provisioning end to end, which runs alongside SSO under the same settings section. A person can belong to more than one HousingSurvey Pro organisation; SSO governs staff sign-in only for the organisations that enable it, and an admin can still revoke a user’s sessions directly from Members regardless of how they signed in.

Common problems

  • A user can’t sign in with SSO. Confirm they’re assigned to the application in your identity provider, and that their email domain matches the one connected to your organisation.
  • We’re locked out of Settings during setup. This is exactly why at least one admin should retain a non-SSO sign-in method while testing a new connection — use it to restore access and re-check the configuration.
  • The same email domain needs to reach two organisations. A domain can only be connected via home-realm discovery to one organisation at a time.