Skip to main content

SSO (Single-Sign-On) in caralegal

SSO, Single-Sign-On, Login

Updated over a month ago

Single Sign-On (SSO) in caralegal

Single Sign-On (SSO) is included in the Enterprise package.
For other packages, SSO can be requested as an additional feature and may involve additional costs.


What is SSO?

Single Sign-On allows users to log in once and access multiple applications.

After authenticating through the central user management system, users can access caralegal without logging in again.


Requirements

To use SSO, your user management system must support the OpenID standard.


SSO Options

Standard SSO

When a user enters an email address with an approved domain (whitelist), a button such as “Login with [Company]” appears.

The user is redirected to the login page of the company’s user management system and, after successful authentication, gains access to caralegal.

Important notes:

  • A user account with the corresponding email must already exist in caralegal.

  • Deleting a user in the external user management system does not automatically delete the user in caralegal.

  • SSO access is controlled via email domains (e.g. caralegal.eu).


SSO-Only

With this option, users can only log in via SSO.

For users with a whitelisted domain, the password field disappears.
Users without a whitelisted domain can still log in using email and password if an account exists.


SSO with IAM (“Light”)

With this option, users are created automatically the first time they log in.

New users are automatically assigned:

  • a default organizational unit

  • a default role

A common best practice is to create a separate unit such as “Welcome Area”, where new users can explore the system without accessing existing documentation.


SSO with IAM

With a full Identity and Access Management (IAM) integration, user management can be automated.

The Group ID from the identity management system is mapped to organizational units in caralegal. Users are then automatically assigned to the correct organizational units.

In this setup, the external user management system is the leading system, and its settings may overwrite manual changes in caralegal.

Did this answer your question?