A Single Sign-On (SSO) system is a centralized authentication service that allows users to log in to multiple applications with a single set of credentials. This improves security by eliminating the need for users to manage multiple passwords and simplifies administration by reducing the number of logins to manage.
Insightful Admin, Manager, Client users and Personal Employee user have the ability to use Security Assertion Markup Language (SAML) Single Sign-On (SSO) to Sign In on the web platform using their existing SAML SSO account such as Okta, OneLogin, Azure, Ping Identity, Bitium, Centrify, Custom SAML 2.0, etc...
To be able to Sign In with SAML SSO - this feature must be enabled by your Admin within Insightful application's Settings. Click here to learn how to set it up.
Signing in with SSO
On https://app.insightful.io/ Sign In page there is a Sign in With SSO button.
To use this functionality, press on that button, enter your SSO account email and click on Sign in With SSO.
Newly added user
If a newly added Admin, Manager, Client user or Personal Employee user
wants to login to Insightful for the first time with SAML SSO, they will be redirected to their SAML SSO platform for further one time only authorization steps. Having successfully passed the authorization, the user will land onto the Insightful application.
Already existing user
When an already existing Insightful Admin, Manager, Client user or Personal Employee user Signs In with SSO for the first time, they will be informed that they will not be able to Sign In with their Insightful credentials again after connecting their SAML SSO account with Insightful.
Upon clicking on Yes, Link Account button, 6-digit code will be sent out to the user's email as a identity verification step. This can be resent by clicking on Resend Code button. By entering correct code, user is redirected to their Insightful platform.
Not yet invited user
If an Admin, Manager, or Client who hasn’t yet been invited to their organization’s Insightful account signs in using SAML SSO, after the successful authorization, they will be automatically added to the organization based on their email domain, and that same account will continue to log in using SSO by default.
Similarly, when an employee logs in through the Insightful Agent, their user profile will be automatically created in the system.
However, if an uninvited employee attempts to access the Dashboard directly through the provider link, access will be blocked until they receive an official invitation.
They will see a message advising them to reach out to their Insightful Admin as they have no permissions.
- Pending Personal employee accounts are automatically activated upon first SSO login. 
- Once SSO is enabled, username/password logins are no longer allowed. 
- If an employee who was added via SSO but hasn’t been invited to Insightful logs in through the SSO Agent for the first time, a new Personal employee account will be automatically created. 

