Recruiting Basics

Single Sign-On (SSO)

Single Sign-On (SSO) is an authentication method that lets staff log in once with one central company identity, then reach every connected application, including the applicant tracking system, without a separate password for each. It centralizes who is allowed in, so granting access to a new hire or revoking it from a leaver becomes one administrative action.

What is single sign-on and how does it work?

Single sign-on moves the login step out of each individual tool and into one identity provider the company already runs, such as an enterprise directory or a dedicated identity platform. When a recruiter opens the [applicant tracking system](/ats), the tool hands the browser back to that provider, the provider confirms the person is who they claim to be, and returns a signed assertion the tool trusts. Two protocols carry most of this traffic. SAML is the older XML-based standard that many HR systems still default to, and OIDC is the newer JSON-based option built on top of OAuth 2.0. Both produce the same practical result: one credential, one place to enforce multi-factor authentication, and no recruiting password sitting inside the hiring tool at all.

Why do HR and IT teams ask for SSO on recruiting tools?

Offboarding speed is the honest answer. Hiring systems hold interview notes, compensation discussions, offer details and personal contact information for people who do not work at the company, which makes a stale login a real exposure rather than a theoretical one. Disable the central account and every connected tool closes at the same moment, instead of someone trying to remember which of a dozen systems still has a standing recruiter seat. The same mechanism runs forward through joiners and movers. A new coordinator gets access on day one from the same directory record that grants email, and a promotion updates group membership rather than triggering manual account edits in each system. Fewer passwords to remember is a welcome side effect, not the argument that wins budget.

Does SSO control what a user can see inside the ATS?

No, and treating the two as one thing is a costly mistake. SSO answers a single question: may this person log in? What they can do afterwards, which requisitions appear, whether salary bands are visible, who may export a candidate list, comes from the permission model configured inside the hiring platform. An organization can run a clean identity connection and still leave every interviewer able to read every offer in flight. Split the work between two owners. IT usually holds the identity integration, while recruiting operations holds permissions, because only they know which fields are sensitive and which roles genuinely need them. Auditors ask about both areas, and they ask about them separately. Buyers evaluating an [enterprise ATS](/enterprise-ats) should test the two capabilities independently during a trial.

What goes wrong during an SSO rollout?

Three failures repeat often enough to plan around. Account matching comes first: the identity provider sends an email address or a unique identifier, and if that value does not match what is already on the user record, people end up with duplicate profiles and orphaned interview feedback, so agree the matching attribute before switching anything on. The locked-out administrator is second. Teams enforce SSO, the connection breaks, and nobody can get in to repair it, which is why one break-glass local admin account with properly stored credentials matters. External users are third. Agency recruiters, contract sourcers and partner interviewers are not in your directory, so decide early whether they receive guest identities or keep local logins. Sequencing this alongside the wider [ATS implementation](/ats-implementation) plan avoids a scramble at go-live.

See how Pitch N Hire handles single sign-on (sso) on your roles

FAQ

Single Sign-On (SSO) — FAQs

Is SSO the same as multi-factor authentication? +
No. SSO decides where authentication happens; multi-factor authentication decides how strong that authentication is. Because SSO routes every login through one identity provider, it becomes the natural place to enforce a second factor once for all connected tools, which is why the two usually arrive together. You can run multi-factor authentication without SSO, and SSO without it, though the second combination is rarely a sensible choice.
Does SSO cost extra on most recruiting platforms? +
Often, yes. Many vendors package single sign-on with higher tiers rather than including it in entry plans, so confirm it during evaluation rather than after signature. Ask which protocols are supported, whether automated user provisioning is bundled or priced separately, and whether a test connection can be built in a sandbox before you commit production identities to it.
Can candidates use SSO too? +
Candidate-facing login is a different problem. Applicants are not employees, so they cannot sit in your corporate directory. Some career sites offer social sign-in through a consumer account, which shortens the application form but is not enterprise SSO and carries none of the same controls. Keep the two conversations apart: staff authentication is a security decision, candidate sign-in is a conversion decision.
What is SCIM and do we need it alongside SSO? +
SCIM is a provisioning standard that creates, updates and deactivates accounts automatically from the identity provider. Single sign-on handles the login itself; without provisioning, a human still adds and disables users by hand. Smaller teams cope with that comfortably. Once headcount grows, or once an auditor wants proof that departures were deactivated promptly, automated provisioning stops being optional.
Built for recruiters & hiring teams

See Single Sign-On (SSO) in action

Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo