Single Sign-On (SSO) Guide

Last updated: June 25, 2026

This guide is for organizations exploring or implementing Single Sign-On (SSO) with exacare ai. It is designed to help both operational stakeholders and IT teams understand what to expect and how to plan a successful setup.

What is SSO?

Single Sign-On allows your team to access exacare ai using your organization’s existing identity system, such as Microsoft Azure, Okta, or Google Workspace.

Instead of managing a separate password for exacare ai, users sign in through your company’s login system.

SSO is typically a good fit if:

  • Your organization already uses an identity provider (Azure, Okta, Google, etc.)

  • You want centralized control over user access

  • You manage a large or frequently changing team

  • Your organization has security or compliance requirements around access control

It may be less necessary if: 

  • Your team is small and stable 

  • You do not currently use an identity provider 

  • You prefer to manage users directly within exacare ai

SSO can be very powerful, but it does introduce additional setup and coordination, particularly with your IT team.


What the login experience looks like

Once SSO is enabled, the login flow changes slightly. 

For end users 

  1. Navigate to exacare ai

  2. Enter your email address 

  3. Get redirected to your organization’s login page 

  4. Sign in using company credentials 

  5. Access exacare ai 

Users will no longer use a separate exacare ai password. 

Important behavior 

  • SSO is configured at the email domain level 

  • Any user with that domain will be routed through SSO 

  • Password-based login is no longer available for those users 

What happens to users

Existing users  

  • Their accounts transition automatically to SSO 

  • They can continue logging in using their company credentials 

  • No additional setup is required on their end 

New users (default behavior) 

  • A new account is created when they first log in with their enterprise credentials 

  • The account is placed in a pending state within the Admin Hub 

  • They will need approval from an exacare ai Superadmin before accessing the system 

This happens because exacare ai does not yet know what role or home facility to assign. The Superadmin will assign this during the approval process. 

This can be streamlined using Group Mapping, described below.

Group Mapping (optional) 

Group Mapping allows exacare ai to use information from your identity provider to automatically assign roles and access when a user logs in for the first time. 

For example: 

  • Users in “Admin” groups can be assigned Admin roles 

  • Users associated with specific facilities can be given appropriate access 

Benefits 

  • Users can access exacare ai immediately on first login 

  • Reduces or eliminates manual approval steps 

  • Ensures consistent role and permission assignment 

Important considerations 

  • Group Mapping must be configured before users log in 

  • Group membership is evaluated at first login only 

  • Changes made later in your identity provider will not automatically update access in exacare ai

Your IT team will typically work with exacare ai to define how groups should map to roles and permissions. 


What SSO does and does not do 

SSO handles 

  • Authentication (verifying user identity) 

  • Automatic User Provisioning 

  • Login experience 

  • MFA enforcement through your identity provider 

SSO does not automatically determine: 

  • User roles and permissions within exacare ai

  • Facility access 

These must be assigned either manually or through Group Mapping.


How implementation works

SSO setup involves coordination between your team and exacare ai. 

Step 1. Prepare your organization 

  • Your exacare ai organization is created 

  • At least one Superadmin is configured 

Step 2. IT completes SSO configuration 

exacare ai provides a secure self-service onboarding form. 

Your IT team will: 

  • Connect your identity provider (Azure, Okta, etc.) 

  • Configure authentication settings 

  • Enable provisioning if relevant (e.g., SCIM) 

This step typically requires familiarity with your identity provider. 

Step 3. Define Group Mapping (optional) 

If you choose to implement Group Mapping, your IT team and exacare ai will align on how identity provider groups map to: 

  • Roles 

  • Home Facilities and any Additional Facility access 

  • Permissions 

  • In-app exacare ai user groups 

Step 4. Enable SSO 

Once the configuration is complete: 

  • SSO is activated for your domain 

  • All users will log in via SSO going forward 

It is helpful to coordinate timing for this step to ensure a smooth transition for users.

Timeline expectations:

  • Basic SSO setup is often completed within a few days 

  • More advanced setups, including Group Mapping, may take longer depending on complexity 

  • Timing often depends on coordination with your internal IT team 

Common issues and how to address them 

  1. Difficulty completing setup 

    1. SSO configuration requires familiarity with your identity provider. Involving the right IT contact early can help avoid delays. 

  2. Users are blocked after login 

    1. This usually occurs when users are new and require admin approval. Superadmins must assign new users a role and home facility. 

  3. Login succeeds, but access is denied 

    1. In some cases, exacare ai may not yet be enabled as an application within your identity provider. Your IT team can review and update application access settings. 

  4. Transition timing challenges 

    1. If SSO is enabled before users are prepared, it can temporarily impact login access. Coordinating activation timing with your team helps ensure a smooth rollout.

Summary 

SSO provides a secure and centralized way to manage access to exacare ai, especially for organizations already using an identity provider. 

A smooth implementation typically includes: 

  • Early involvement from your IT team 

  • Clear planning around rollout timing 

  • Consideration of Group Mapping for automated access 

exacare ai will work with you throughout the process to help ensure a successful setup.


Frequently asked questions 

Can we switch from password login to SSO? 

Yes. Existing users will transition automatically the next time they log in. 

Can users still log in with a password? 

For domains configured with SSO, users will log in exclusively through your identity provider. 

How is MFA handled? 

MFA is managed entirely by your identity provider. 

Can users be provisioned automatically? 

Yes, users are automatically provisioned on their first login. 

If a user’s group changes, will their access update? 

At this time, access is determined at first login and does not automatically update based on later group changes. 

Is Group Mapping required? 

No. However, it can streamline onboarding and reduce manual steps for admins.