Single Sign-On (SSO) Guide
Last updated: June 25, 2026
This guide is for organizations exploring or implementing Single Sign-On (SSO) with exacare ai. It is designed to help both operational stakeholders and IT teams understand what to expect and how to plan a successful setup.
What is SSO?
Single Sign-On allows your team to access exacare ai using your organization’s existing identity system, such as Microsoft Azure, Okta, or Google Workspace.
Instead of managing a separate password for exacare ai, users sign in through your company’s login system.
SSO is typically a good fit if:
Your organization already uses an identity provider (Azure, Okta, Google, etc.)
You want centralized control over user access
You manage a large or frequently changing team
Your organization has security or compliance requirements around access control
It may be less necessary if:
Your team is small and stable
You do not currently use an identity provider
You prefer to manage users directly within exacare ai
SSO can be very powerful, but it does introduce additional setup and coordination, particularly with your IT team.
What the login experience looks like
Once SSO is enabled, the login flow changes slightly.
For end users
Navigate to exacare ai
Enter your email address
Get redirected to your organization’s login page
Sign in using company credentials
Access exacare ai
Users will no longer use a separate exacare ai password.
Important behavior
SSO is configured at the email domain level
Any user with that domain will be routed through SSO
Password-based login is no longer available for those users
What happens to users
Existing users
Their accounts transition automatically to SSO
They can continue logging in using their company credentials
No additional setup is required on their end
New users (default behavior)
A new account is created when they first log in with their enterprise credentials
The account is placed in a pending state within the Admin Hub
They will need approval from an exacare ai Superadmin before accessing the system
This happens because exacare ai does not yet know what role or home facility to assign. The Superadmin will assign this during the approval process.
This can be streamlined using Group Mapping, described below.
Group Mapping (optional)
Group Mapping allows exacare ai to use information from your identity provider to automatically assign roles and access when a user logs in for the first time.
For example:
Users in “Admin” groups can be assigned Admin roles
Users associated with specific facilities can be given appropriate access
Benefits
Users can access exacare ai immediately on first login
Reduces or eliminates manual approval steps
Ensures consistent role and permission assignment
Important considerations
Group Mapping must be configured before users log in
Group membership is evaluated at first login only
Changes made later in your identity provider will not automatically update access in exacare ai
Your IT team will typically work with exacare ai to define how groups should map to roles and permissions.
What SSO does and does not do
SSO handles
Authentication (verifying user identity)
Automatic User Provisioning
Login experience
MFA enforcement through your identity provider
SSO does not automatically determine:
User roles and permissions within exacare ai
Facility access
These must be assigned either manually or through Group Mapping.
How implementation works
SSO setup involves coordination between your team and exacare ai.
Step 1. Prepare your organization
Your exacare ai organization is created
At least one Superadmin is configured
Step 2. IT completes SSO configuration
exacare ai provides a secure self-service onboarding form.
Your IT team will:
Connect your identity provider (Azure, Okta, etc.)
Configure authentication settings
Enable provisioning if relevant (e.g., SCIM)
This step typically requires familiarity with your identity provider.
Step 3. Define Group Mapping (optional)
If you choose to implement Group Mapping, your IT team and exacare ai will align on how identity provider groups map to:
Roles
Home Facilities and any Additional Facility access
Permissions
In-app exacare ai user groups
Step 4. Enable SSO
Once the configuration is complete:
SSO is activated for your domain
All users will log in via SSO going forward
It is helpful to coordinate timing for this step to ensure a smooth transition for users.
Timeline expectations:
Basic SSO setup is often completed within a few days
More advanced setups, including Group Mapping, may take longer depending on complexity
Timing often depends on coordination with your internal IT team
Common issues and how to address them
Difficulty completing setup
SSO configuration requires familiarity with your identity provider. Involving the right IT contact early can help avoid delays.
Users are blocked after login
This usually occurs when users are new and require admin approval. Superadmins must assign new users a role and home facility.
Login succeeds, but access is denied
In some cases, exacare ai may not yet be enabled as an application within your identity provider. Your IT team can review and update application access settings.
Transition timing challenges
If SSO is enabled before users are prepared, it can temporarily impact login access. Coordinating activation timing with your team helps ensure a smooth rollout.
Summary
SSO provides a secure and centralized way to manage access to exacare ai, especially for organizations already using an identity provider.
A smooth implementation typically includes:
Early involvement from your IT team
Clear planning around rollout timing
Consideration of Group Mapping for automated access
exacare ai will work with you throughout the process to help ensure a successful setup.
Frequently asked questions
Can we switch from password login to SSO?
Yes. Existing users will transition automatically the next time they log in.
Can users still log in with a password?
For domains configured with SSO, users will log in exclusively through your identity provider.
How is MFA handled?
MFA is managed entirely by your identity provider.
Can users be provisioned automatically?
Yes, users are automatically provisioned on their first login.
If a user’s group changes, will their access update?
At this time, access is determined at first login and does not automatically update based on later group changes.
Is Group Mapping required?
No. However, it can streamline onboarding and reduce manual steps for admins.