SSO end to end
Single sign-on connects HousingSurvey Pro to your organisation’s identity provider, so staff sign in with their existing corporate credentials instead of a separate password.
What it is
SSO applies to email/staff accounts — field surveyors without email continue to use tenant logins. Three connection types are supported: SAML (via your identity provider’s metadata), OIDC (for example Microsoft Entra ID), and Google Workspace domain sign-in. Home-realm discovery routes a signing-in user to the right connection based on their email domain, and each domain can be connected to exactly one organisation.
Before you start
Setting up SSO requires organisation-admin access to Settings, and is an Enterprise-plan feature.
How to do it
- Open Settings → SSO & provisioning.
- Choose your connection type — SAML metadata, OIDC (Entra ID), or Google Workspace — and provide the details the page asks for, along with the redirect URL it shows you.
- Register HousingSurvey Pro as an application in your own identity provider, using those same details.
- Assign the users or groups who should have access, on your identity provider’s side.
- Save the connection and test a sign-in. Keep at least one org admin able to sign in by another means while you set this up, so nobody is locked out mid-configuration.
How it integrates
Access follows your directory: when someone leaves and is disabled in your identity provider, their ability to sign in here goes with it. For automated joiner/mover/leaver provisioning rather than sign-in alone, see SCIM provisioning end to end, which runs alongside SSO under the same settings section. A person can belong to more than one HousingSurvey Pro organisation; SSO governs staff sign-in only for the organisations that enable it, and an admin can still revoke a user’s sessions directly from Members regardless of how they signed in.
Common problems
- A user can’t sign in with SSO. Confirm they’re assigned to the application in your identity provider, and that their email domain matches the one connected to your organisation.
- We’re locked out of Settings during setup. This is exactly why at least one admin should retain a non-SSO sign-in method while testing a new connection — use it to restore access and re-check the configuration.
- The same email domain needs to reach two organisations. A domain can only be connected via home-realm discovery to one organisation at a time.