One front door, and one place access ends.
Single sign-on lets people authenticate once against the identity provider and reach the applications they are entitled to, without a separate password per system. Our work is federating the whole estate so offboarding actually closes every path.
Single sign-on moves authentication to the directory, so removing someone from the directory actually removes their access rather than most of it.
What it is
Single sign-on lets people authenticate once against the identity provider and reach the applications they are entitled to, without a separate password per system.
It is the control most organizations already have in part, and the gap is usually the applications that were never brought in.
What it does
Authentication in one place
One decision about who someone is, made where it can be enforced.
Offboarding that works
Removing someone from the directory removes access, provided every application is actually federated.
Where it fits
L1, identity and access. This is the front door. Every layer above resolves through it, which is why an application left outside it is not a small exception: it is a path that offboarding does not close.
What we do with it
Federating the whole estate
Bringing Atlassian and the applications around it under one authentication decision, including the ones that were skipped.
Policy by population
Employees, external vendors, and service accounts held to different rules rather than one compromise.
Running it
Access requests, exceptions, and reviews handled as an operation rather than a project.
Where it earns its place
An estate with applications outside single sign-on
The exceptions are the risk, and they are usually undocumented.
An organization after an acquisition
Two directories, and a decision about which one is authoritative.
A carrier standing up new squads
New projects need to be federated from day one or the exceptions start immediately.
Proof
Organizations that had a successful identity-related breach in the last twelve months.
Palo Alto Networks, 2026 Identity Security Landscape, 2,930 respondents.