Single Sign-On (SSO)
Overview
Enterprise SSO lets your team sign in to AskElephant through your company's identity provider (IdP). Sign-in is driven by email: a user enters their work email, and AskElephant sends them to the right provider automatically. Your IdP handles passwords, MFA, and access policies, so your existing security controls apply to AskElephant too.
ℹ️ Add-on feature. Enterprise SSO is an add-on and isn't enabled for every workspace by default. To add it to your plan, contact your customer success manager (CSM).
How SSO Works
SSO is matched by email domain, so members never pick their provider from a list.
A user enters their work email on the login page.
AskElephant matches the email domain to a workspace.
If that workspace requires SSO and has an active connection, the user is redirected to their company's identity provider.
The provider handles credentials, MFA, and access policies.
AskElephant receives the verified identity and confirms the user has an active seat before granting access.
Supported Identity Providers
AskElephant connects through WorkOS, so you can use any provider WorkOS supports over SAML 2.0 or OpenID Connect (OIDC). Common providers include:
Microsoft Entra ID / Azure AD
Okta
Google Workspace
OneLogin
PingFederate / PingOne
JumpCloud
Keycloak
ADFS
Any generic SAML or OIDC provider
Enterprise SSO is separate from the standard Sign in with Google button. Google Workspace SSO applies your company's access policies, while the standard Google sign-in is a personal social login without those controls.
Signing In With SSO
When SSO is enabled for your workspace:
The login page asks for an email.
AskElephant checks the email against your workspace's primary and alternate domains.
If an active connection exists, the user goes straight to your identity provider.
After authentication, users with access to more than one workspace choose which to open.
Users without an active seat are blocked and told to contact a workspace Owner, who manages seats and roles.
ℹ️ First-time sign-in. If a member previously signed in with Google or email, their first SSO attempt asks them to link accounts: "Account linking required. Use your existing email sign-in once to link SSO to your account." After that one-time step, SSO works normally.
Enabling SSO
Each workspace needs its own active connection, set up with your AskElephant CSM and your IT team. Once the connection is confirmed, your team signs in through the email-first flow above. To get started, contact your CSM.
Need More Help?
Reach the AskElephant support team by:
clicking the Support tab on the right side of your screen,
emailing [email protected],
or using
@askelephant supportin your dedicated Slack channel.