HR Software

What is single sign-on and why does it matter for HR software?

Single sign-on lets people access HR systems through your central identity provider instead of separate passwords. It matters because access is granted and revoked in one place, security policy such as multi-factor authentication applies consistently, and hiring managers face one less barrier. In many products it sits in a higher pricing tier, so check early.

How does single sign-on actually work?

Your organisation runs an identity provider that already knows who works there. When someone opens the HR system, the application redirects them to that provider, which confirms identity and returns a signed assertion granting access. The application never holds a password. Most business software supports this through standard protocols, so the setup is configuration rather than development, usually completed by IT in a short session. Many products also support automated provisioning, where accounts are created and deactivated based on directory membership. That second capability is separate from sign-on itself and worth asking about explicitly, because manual account cleanup is where access control quietly degrades over time as people join, change roles and leave.

Why does it matter more for recruiting than people expect?

Two reasons. The first is security: applicant tracking systems hold sensitive personal data, interview feedback and sometimes salary information, accessed by a rotating group of hiring managers and interviewers. Without central identity, revoking access when someone leaves depends on an administrator remembering to do it in each system. The second is adoption. Hiring managers use the system occasionally, which is exactly the pattern that produces forgotten passwords and abandoned reviews. Removing the login barrier measurably improves the odds that a manager completes a candidate review the same day. That connection between identity and adoption is underrated, and it is one of the practical reasons IT and recruiting should both be in the room when evaluating [applicant tracking software](/ats).

What should you check during evaluation?

Whether single sign-on is available at the tier you plan to buy or only above it, since this is a common cause of a quote changing after IT review. Which protocols and identity providers are supported. Whether automated provisioning and deprovisioning are included. Whether you can enforce sign-on for all users or whether local passwords remain possible as a fallback, which undermines the control. How role assignment works: whether groups in your directory can map to permission levels in the product, or whether roles must be managed separately. And how external users are handled, such as agency recruiters or interviewers outside your directory. Get the answers in writing during evaluation, because retrofitting identity configuration after rollout means touching every account.

What if single sign-on is not available to you?

It is not a reason to abandon an otherwise suitable product at small scale, but compensate deliberately. Require multi-factor authentication for every account, document a joiner and leaver process that includes the recruiting system explicitly, review the user list quarterly, and keep the number of accounts small by using view-only or link-based access for occasional interviewers where the product supports it. Also check whether the vendor offers sign-on at a higher tier and what it would cost to move, so the decision is informed rather than deferred. As the team grows, the manual process becomes the weak point, and most organisations reach a size where central identity stops being optional and becomes a requirement from their own security policy.

Want Pitch N Hire to handle this for your team?

Related glossary terms

Next step

FAQ

Frequently asked questions

Is single sign-on worth it for a team of five? +
It is less critical at that size, though still useful if your organisation already runs an identity provider, because it costs little to add and removes a category of access risk. The stronger argument at small scale is convenience for occasional users. Weigh it against tier pricing rather than treating it as mandatory.
Does single sign-on replace permissions inside the ATS? +
No. Sign-on establishes who someone is; permissions decide what they can see and do. You still need role design inside the product covering who views salary details, who reads interview feedback, and who can export data. Where directory groups can map to product roles, the two work together and reduce manual administration considerably.
How do interviewers outside our company get access? +
Usually through a limited external user account or a tokenised link that grants access to a specific candidate or feedback form without a full login. Check what the product supports, since agency partners and external panel members are common in recruiting and are precisely the accounts most likely to be forgotten during access reviews.
What is the difference between single sign-on and provisioning? +
Sign-on authenticates an existing user at the moment of access. Provisioning creates, updates and deactivates the account itself based on your directory. Many buyers assume sign-on handles both and later find that deactivated employees still hold active product accounts. Ask about the two capabilities separately during evaluation.
Built for recruiters & hiring teams

See how much faster your team could hire

Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo