Single sign-on
Let staff sign in with their Google or Microsoft work account, or your SAML identity provider, and keep accounts in step with SCIM.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
Single sign-on (SSO) lets your staff sign in to the console and the Workspace app with the work account they already have. When someone leaves and IT disables their account, they lose access to Agoo too.
| Plan | Single sign-on |
|---|---|
| Free | Not included |
| Starter | Not included |
| Growth | Sign in with Google or Microsoft |
| Pro | + SAML single sign-on and SCIM provisioning |
| Enterprise | + Custom identity provider set-up |
Google and Microsoft sign-in arrives with the console (P3). SAML and SCIM arrive in P9.
Google or Microsoft sign-in (Growth and above)
Open Console → Settings → Single sign-on
You need to be an Owner or Admin.
Turn on Google, Microsoft or both
Enter your organisation's email domains, such as voltabank.example, so only work accounts on those domains can sign in this way.
Test with a second account
Sign in from a private browser window as a colleague before you tell everyone. Keep your own session open until the test works.
Tell your staff
On the sign-in screen, staff choose Continue with Google or Continue with Microsoft.
SAML and SCIM (Pro and Enterprise)
SAML connects Agoo to your identity provider, such as Microsoft Entra ID, Okta or Google Workspace, so sign-in follows your own policies, including multi-factor authentication. SCIM lets your identity provider create, update and deactivate people in Agoo automatically, so you don't manage two directories.
Start in Console → Settings → Single sign-on
Choose Add SAML connection. Agoo shows the details your IT team needs to register Agoo in your identity provider.
Register Agoo in your identity provider
Your IT team creates the application, enters Agoo's details and gives you back your provider's details. The technical steps are in SSO and SCIM.
Test, then require SSO
Test sign-in with a few people first. When it works, you can require SSO for everyone on your domains, so password sign-in is switched off for them.
Turn on SCIM (optional)
Create a SCIM token in Console → Settings → Single sign-on and give it to your IT team. From then on, people added to the Agoo group in your directory appear in Console → People, and people removed are deactivated.
Keep a way back in
Before you require SSO, make sure at least one Owner can still sign in another way if your identity provider is unavailable or misconfigured. Changes to sign-in settings are recorded in the audit trail.
Roles still come from Agoo: SSO proves who someone is, and their role in Console → People decides what they can do. See Roles and permissions.
Account recovery
What happens when someone loses the phone with their authenticator app, how Owners and Admins approve a reset safely, and how an organisation gets a new Owner when its Owner has gone.
Branding
Put your logo, colours and welcome on the kiosk, passes, emails, booking pages and badges, and use your own domain.