Single sign-on (SSO)
Single sign-on lets the people on your team sign in to leadmaps using the same company login they already use for everything else, instead of a separate leadmaps password or magic link. You connect leadmaps to your identity provider (the tool that manages your company logins, such as Okta, Microsoft Entra, or Google Workspace) once, and from then on your team signs in through it. When someone joins or leaves your company, you manage that in one place, and their leadmaps access follows automatically.
Think of it like a building pass. Instead of giving every room its own key, everyone carries one company badge, and each door simply checks the badge. SSO makes leadmaps one of those doors.
Single sign-on is part of the Business plan.
What you see
Section titled “What you see”The SSO settings live under Settings. From there you set up and manage the connection.
- A choice of connection type. leadmaps supports both of the common standards, SAML 2.0 and OIDC, so it works with whichever your identity provider uses. You pick the one your provider gives you.
- The details you exchange with your provider. Setting up SSO means giving leadmaps a few values from your identity provider, and giving your provider a few values from leadmaps in return. The page lays out exactly which values go where.
- A domain step. Before SSO can go live, you confirm that you own your company’s email domain (for example
yourcompany.com). This proves the domain is really yours, so no one else can claim your team’s logins. - An enforcement switch. Once SSO works, you can require it for everyone at your domain, which turns off the ordinary password and magic-link sign-in for those people so they can only get in through your identity provider.
How to read it
Section titled “How to read it”SSO setup is a one-time exchange of settings, not a daily number to read. The state that matters is simple: is the connection configured, is your domain confirmed, and is enforcement on or off.
Here is the shape of a setup. You choose SAML or OIDC to match your provider. You copy the values leadmaps shows you into your identity provider, and copy the values it gives back into leadmaps. You confirm your email domain so leadmaps knows the connection belongs to you. You test a sign-in. Once that works, you decide whether to leave both sign-in methods available or to enforce SSO so your team can only sign in through your provider.
Customize it
Section titled “Customize it”- Pick SAML or OIDC. Choose the standard your identity provider supports. Most enterprise providers offer both; use whichever your IT team prefers.
- Confirm your domain. Complete the domain step before going live. This is required, and it is what stops anyone else from attaching their own login to your team’s email addresses.
- Turn enforcement on or off. Leave it off while you are still testing, so your team can fall back to the normal sign-in if something is misconfigured. Turn it on once you are confident, so every person at your domain must use your identity provider. Enforcement is the setting that makes SSO a real security control rather than just a convenience.
Use cases
Section titled “Use cases”- Centralize access for a growing team. Connect leadmaps to the identity provider you already use, so new hires get access the moment IT adds them and lose it the moment they leave. Action: set up the connection, confirm your domain, and enforce SSO so access always matches your company directory.
- Meet a security requirement. Many companies require that every tool support SSO and enforce it. Action: configure the connection, confirm your domain, and turn enforcement on so leadmaps satisfies the policy.
- Remove shared or forgotten logins. Passwords and magic links scatter over time. Action: once SSO is enforced, those older paths are closed for your domain, so there is exactly one way in and one place to manage it.
- Confirm your domain first. SSO will not go live until you have proven you own the email domain, and this is deliberate: it is the step that keeps your team’s logins yours.
- Test before you enforce. Turn enforcement on only after a successful test sign-in, so a small mistake in the settings does not lock your team out.
- Keep at least one admin who can recover access. As with any single-door setup, make sure someone can still get in and fix the connection if your identity provider has an outage.
- SSO manages how people sign in, not what each person can do inside leadmaps. Roles still decide who can change billing, keys, and settings. Set both.