Single sign-on and provisioning
Potloc supports three ways for an organisation to sign in through an identity it already runs. None of them changes what an account can do on the platform. Access to a survey is still a role granted on that survey. Single sign-on only decides how a person proves who they are.
| Option | Works with | Set-up |
|---|---|---|
| Sign in with Google | Google Workspace | None |
| Sign in with Microsoft | Microsoft Entra ID | None |
| SAML single sign-on | Your SAML 2.0 identity provider | Configured with Potloc for your email domain |
Google and Microsoft sign-in are available to every account whose email address belongs to one of those directories. Nothing has to be enabled. SAML is set up per organisation, for the email domain your people sign in with.
What changes on the sign-in page
Section titled “What changes on the sign-in page”Everyone starts by entering their email address. With one of these in place for your domain, the password step no longer appears for your people:
- SAML. Once your domain is registered, anyone on it is sent to your identity provider as soon as they enter their email, and comes back signed in.
- Google or Microsoft required. Anyone on your domain is asked to continue with that provider instead of a password.
SAML takes effect as part of the set-up below. Requiring Google or Microsoft is a request to support@potloc.com.
SAML single sign-on
Section titled “SAML single sign-on”With SAML in place, everyone on your email domain signs in through your identity provider, so your provider’s policies (multi-factor authentication, device rules, who is allowed in at all) apply to Potloc as they do to your other applications.
Set-up is done together with Potloc. You share your provider’s SAML metadata (its entity ID, sign-on URL and signing certificate) for the email domain it covers, and Potloc gives you its service-provider details to register on your side. Potloc’s team is with you through the exchange and confirms when the domain is live.
Signing in through your provider is not the same as having access. A person who signs in this way for the first time gets an account with no surveys on it, and sees nothing until a colleague or Potloc grants them a role. Provisioning creates accounts ahead of that first sign-in and removes them when people leave.
Provisioning accounts
Section titled “Provisioning accounts”With SAML in place, Potloc can also take account management from your identity provider over SCIM 2.0, so joiners, leavers and renames flow from your directory without anyone touching the platform.
Potloc issues you a provisioning token to configure on your identity provider. From there your provider can:
- create an account on your domain, which a colleague can then invite to surveys;
- update a person’s first and last name;
- deactivate an account, which ends its access on every Potloc surface at once, and reactivate it later with the survey roles it held.
Provisioning reaches accounts on your email domain and no other. The email address identifies the account and cannot be changed by provisioning. To rename an address, write to support@potloc.com.
Provisioning manages accounts. It does not grant access. Roles on surveys are still given on the platform, so a newly provisioned person sees nothing until someone shares a survey with them.
Getting set up
Section titled “Getting set up”Write to support@potloc.com with the email domain and the identity provider you use, and say whether you want provisioning as well.