Single sign-on lets people access HR systems through your central identity provider instead of separate passwords. It matters because access is granted and revoked in one place, security policy such as multi-factor authentication applies consistently, and hiring managers face one less barrier. In many products it sits in a higher pricing tier, so check early.
Your organisation runs an identity provider that already knows who works there. When someone opens the HR system, the application redirects them to that provider, which confirms identity and returns a signed assertion granting access. The application never holds a password. Most business software supports this through standard protocols, so the setup is configuration rather than development, usually completed by IT in a short session. Many products also support automated provisioning, where accounts are created and deactivated based on directory membership. That second capability is separate from sign-on itself and worth asking about explicitly, because manual account cleanup is where access control quietly degrades over time as people join, change roles and leave.
Two reasons. The first is security: applicant tracking systems hold sensitive personal data, interview feedback and sometimes salary information, accessed by a rotating group of hiring managers and interviewers. Without central identity, revoking access when someone leaves depends on an administrator remembering to do it in each system. The second is adoption. Hiring managers use the system occasionally, which is exactly the pattern that produces forgotten passwords and abandoned reviews. Removing the login barrier measurably improves the odds that a manager completes a candidate review the same day. That connection between identity and adoption is underrated, and it is one of the practical reasons IT and recruiting should both be in the room when evaluating [applicant tracking software](/ats).
Whether single sign-on is available at the tier you plan to buy or only above it, since this is a common cause of a quote changing after IT review. Which protocols and identity providers are supported. Whether automated provisioning and deprovisioning are included. Whether you can enforce sign-on for all users or whether local passwords remain possible as a fallback, which undermines the control. How role assignment works: whether groups in your directory can map to permission levels in the product, or whether roles must be managed separately. And how external users are handled, such as agency recruiters or interviewers outside your directory. Get the answers in writing during evaluation, because retrofitting identity configuration after rollout means touching every account.
It is not a reason to abandon an otherwise suitable product at small scale, but compensate deliberately. Require multi-factor authentication for every account, document a joiner and leaver process that includes the recruiting system explicitly, review the user list quarterly, and keep the number of accounts small by using view-only or link-based access for occasional interviewers where the product supports it. Also check whether the vendor offers sign-on at a higher tier and what it would cost to move, so the decision is informed rather than deferred. As the team grows, the manual process becomes the weak point, and most organisations reach a size where central identity stops being optional and becomes a requirement from their own security policy.
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert