Single sign-on

Connect your organization's identity provider — Microsoft Entra ID, Okta, Google Workspace, or any SAML or OIDC provider — so your people reach Goveda Pro with the account they already have. Once you enforce it, your directory decides who gets in, and Goveda Pro stops accepting passwords for your organization.

Who can do this — an organization Owner. You'll also need someone who can add a DNS record for your email domain, and the sign-in details from your identity provider. If that's two different people, line them up before you start: the middle of setup is an awkward place to wait.

What you'll do

Setup is four steps, and the page walks you through them in order. Only the first one takes real work.

Connect your identity provider

Press Start setup. A configuration assistant opens in a new tab, where you paste the details from your provider and prove you own your email domain by adding a DNS record.

Domain verification waits for DNS to propagate — usually about 30 minutes. You can close everything and come back; nothing is lost.

The assistant link is shown once and cannot be recreated. If you close that tab, use the link kept on the Goveda Pro page to get back in. If you lose it entirely, Revoke and create a new link starts over cleanly.

When the assistant is done, come back and press I'm done — check the configuration. One press is enough.

Choose how members join

Decide whether signing in through your identity provider is, by itself, enough to become a member of your organization. See How members join below — the default suits most organizations, and you can change it at any time, including later.

Test sign-in

Press Test sign-in with your identity provider. This signs you in end to end through your provider — not a password login — and confirms the connection really works before it applies to anyone else.

You can't enforce until this succeeds. That's deliberate: it's the difference between discovering a misconfiguration yourself and discovering it because nobody in your organization can sign in.

Enforce for the whole organization

Press Enforce. From this moment every member signs in through your identity provider, and password sign-in stops working for your organization.

You'll be signed in again through your provider straight away, so your own session satisfies the new policy.

How members join

Two options, and you can switch between them whenever you like.

Join automatically on first sign-in (default) — anyone who can authenticate at your identity provider becomes a member the first time they sign in. No invitation needed. This is what most organizations expect from SSO: your directory is the source of truth, and someone your company has already vouched for shouldn't need a second approval.

Invitation only — people must be invited before they can join, even if they can already authenticate at your identity provider. Choose this when your directory contains accounts you don't want in Goveda Pro — contractors, service accounts, shared mailboxes — or when you want a deliberate step before someone gets access to your projects.

New members can see every project in your organization. If that's broader than you want for everyone in your directory, use Invitation only.

What enforcement changes

  • Every member signs in through your identity provider.
  • Password sign-in stops being accepted for your organization, including for you.
  • People whose access you remove in your directory lose access to Goveda Pro.
  • Existing sessions that were established another way stop satisfying the policy.

Enforcement can't be undone from the settings page. It's the one step here that needs us to reverse it — contact Goveda support. Everything before it, including the configuration itself, you can redo yourself.

If something doesn't work

Someone can't sign in and sees a message about your organization requiring its identity provider. They authenticated, but they're not a member. Either invite them, or switch to Join automatically on first sign-in.

People are asked for a password instead of being sent to your provider. Your email domain needs to be recognised by the connection itself, not only verified for the organization. Contact support — this is on our side to check.

You've enforced SSO and can't get in. Contact support. Don't try password sign-in; it's refused by design once SSO is enforced, and the error you'll see won't say so clearly.