Glossary
Single sign on (SSO)
Letting staff reach a tool with the work login they already have, so access is granted and removed in one place rather than tool by tool.
In plain terms
People sign in to the tool with the same account they use for everything else at work. There is no separate password to create, and when somebody leaves, removing their main account removes this along with everything else. That last part is the reason organisations want it, more than the convenience of one fewer password.
Why it matters
Because removal is the half that actually matters and it is the half nobody demonstrates. Granting access is visible, somebody asks and somebody does it. Removing it depends on a person remembering a tool exists, at a moment when they are busy with a departure, and every tool outside this arrangement is one more thing to remember. The failure is silent and it accumulates.
How it works
It moves the decision to one place, which is the whole of the benefit. Who may reach the tool becomes a property of your existing account system rather than a separate list somebody maintains, so a change made once takes effect everywhere. That is why organisations with many tools want it far more than organisations with three.
The leaver case is the argument, and it is worth stating plainly rather than assuming it is understood. Without this arrangement a departure means somebody remembering every tool the person could reach, and the ones forgotten stay reachable indefinitely. With it, one action closes them all, which turns an act of memory into a consequence of the ordinary process.
It frequently sits behind a business tier, which is why it appears in purchasing conversations rather than in configuration. That is a commercial arrangement rather than a technical limitation, and it is one of the more defensible reasons to move tier, because the alternative is a growing list of separately managed accounts.
It is about who may enter rather than what they may do once inside. Two people signing in the same way can have entirely different permissions within a tool, and those permissions are usually managed by the tool rather than by your account system. Buyers sometimes expect the arrangement to carry roles across as well, and mostly it does not.
What is worth checking is how quickly removal actually takes effect. An account disabled centrally may still have a live session in the tool for some period, and how that is handled varies. It is a small question with a specific answer, and it is the one that determines whether the leaver argument holds in the first hour rather than the first day.
Somebody leaves on a Friday
Seen in the wild
Moving a team from individual assistant logins to the organisation's own account system, so departures close access automatically.
ChatGPTA search tool reaching across internal systems, where central sign-in matters more because the tool can surface material from everywhere.
GleanAn automation platform where access to the credentials it holds for other services follows the same central arrangement.
Make
Common misconceptions
People assume
It is about convenience.
In fact
Convenience is the visible benefit and removal is the valuable one. One fewer password is pleasant; a departure that closes every tool without anybody remembering to is the reason organisations pay for it, and that benefit grows with every additional tool in the estate.
People assume
It controls what people can do in the tool.
In fact
It controls who may enter. Permissions inside a tool are usually managed by that tool, so two people arriving the same way can have very different abilities once in. Some products can take roles from your account system as well, and it is worth asking rather than assuming.
Telling them apart
Single sign on vs Access review
Single sign on
Granting and removing access centrally, as it happens.
Periodically checking who still needs what, and removing the rest.
One handles departures automatically; the other catches everybody who stayed and no longer needs it.
Questions
- What is the real argument for it?
- Removal. Granting access is visible and gets done; removing it depends on somebody remembering a tool exists during a departure, and forgotten tools stay reachable indefinitely. This arrangement turns that act of memory into an automatic consequence of the ordinary leaver process.
- Does it manage permissions too?
- Usually not by itself. It governs who may enter, while what they can do inside is generally managed by the tool. Some products can take roles from your account system as well, which is worth asking about specifically rather than assuming, because buyers frequently expect it.
- Why is it on a higher tier?
- It is a commercial decision by vendors rather than a technical constraint, and it is common enough to expect. It is also among the more defensible reasons to move tier, since the alternative is an ever-growing set of separately managed accounts that somebody has to remember at exactly the wrong moment.
- What should we check before relying on it?
- How quickly a removal actually takes effect. A centrally disabled account may leave a live session in the tool for some period, and the handling varies between products. It is a small question with a specific answer, and it decides whether the leaver argument holds within the hour or within the day.
Key takeaways
- Removal is the argument; convenience is the visible part.
- It turns remembering a tool into an automatic consequence of the leaver process.
- It governs who may enter, not what they may do once inside.
- Check how quickly a removal actually ends an active session.
- It usually sits behind a business tier, which is a commercial rather than technical fact.
Last checked July 2026