Skip to main content

Enterprise SSO

With Enterprise SSO, your people sign in to Wiselook with their work account, through your organisation's own identity provider. Admins set it up under the Settings gear → SSO, where each connection to an identity provider is called a federation.

Getting access​

Enterprise SSO is not enabled by default. Until it is, SSO doesn't appear in the Settings menu. To enable it for your organisation, contact us.

Adding a federation​

  1. Under the Settings gear → SSO, choose Add federation.
  2. Pick the protocol your identity provider uses, SAML 2.0 or OIDC. The form adapts to it.
  3. Give the federation a name and enter the Issuer (the entity ID) of your identity provider, and its Metadata URL if it publishes one.
  4. For OIDC, enter the Client ID and the Client secret of the app you registered for Wiselook in your identity provider. For SAML, enter the identity provider's SSO URL.
  5. Decide whether to turn on just-in-time provisioning, explained below.
  6. Wiselook then shows the URLs to register in your identity provider: the Redirect URI for OIDC, or the ACS URL and the SP metadata URL for SAML. They stay in the federation's details, each with a copy button.

The client secret is stored only in the sign-in service, and Wiselook never shows it again. To replace it, open the federation, choose Edit settings and enter the new secret. Leaving the field blank keeps the current one. The SAML SSO URL is used only when the federation is created.

A federation's protocol can't be changed. To switch, add a new federation and disable the old one.

Verifying your email domains​

A federation only receives sign-ins from the email domains you add to it, such as acme.com, and only once each domain is verified.

  1. Open the federation and add the domain under Email domains.
  2. Wiselook shows a TXT record to publish in your domain's DNS. Its name is _wiselook-challenge. followed by the domain, and its value starts with wiselook-domain-verification=. Copy both from the portal.
  3. Choose Verify next to the domain. Once it shows Verified, sign-ins from that domain go through your identity provider.

DNS changes can take a while to propagate. If verification fails right after you publish the record, try again in a few minutes.

Public email providers such as Gmail or Outlook can't be added, and a domain that another organisation has already verified can't be verified for yours. Removing a verified domain stops its sign-ins from going through the federation.

How people sign in​

On the login page, people choose Enterprise SSO and enter their work email. Wiselook takes them to your identity provider and brings them back signed in.

Invite links take the same route. When your organisation has an active federation with a verified domain, the invite page opens on the work email sign-in, and Continue with Google stays available.

Who can join​

  • With just-in-time provisioning on, someone who signs in through the federation for the first time, without an account in your organisation, joins it as a member. Admins can change their role from Members.
  • With it off, people join only through an invite, as they do without SSO.
  • People who already have an account keep it. Their first SSO sign-in links it by email address, with the same role and history. The address must be the one they used before. If it isn't, Wiselook treats them as a new person.
  • Deactivated members stay deactivated. Signing in through SSO never brings back someone you deactivated. To let them back in, reactivate them from Members.

Enterprise SSO adds a way in and never closes the others. Admins and managers can still invite anyone, on any email domain, and people keep the way they signed in before.

Turning a federation off​

Disable federation stops its sign-ins immediately, and Re-enable federation resumes them.