Guides · Guide · September 14, 2026

SAML / SSO ACS login for managers

Copy ACS and Entity ID, paste identity-provider metadata, certificate, and issuer. ACS maps a signed assertion to a manager session.

Managers can sign in with SAML after Operations stores one SAML 2.0 connection per organization: metadata URL, issuer, signing certificate, and SSO URL, plus the ACS and Entity ID your provider needs. ACS validates a signed assertion, maps the email to a manager who already exists in that organization, and issues a session. Sample metadata is test mode when a live provider is not set. There is no OpenID Connect path and no passwordless or magic-link sign-in. The Windows tray does not change.

The public page is /features/sso. The click-through is the SSO tutorial. Ask VisibleHours “sso”, “saml”, “single sign-on”, “open sso”, or “configure sso” opens SSO. “how to set up sso”, “sso tutorial”, or “saml tutorial” opens Help. How managers actually reach a session is password or SAML — not OIDC. “Sign in with SAML” opens /login.

Copy ACS and Entity ID, then enable

  1. Sign in with email and password the first time. Open SSO / SAML.
  2. Copy Entity ID and ACS. Give them to the identity-provider admin.
  3. Paste a metadata URL, or issuer and certificate, or use the VisibleHours sample. Save.
  4. Press Test. VisibleHours fetches the document and copies issuer and certificate when they are present. That is not a provider certification.
  5. Enable the connection. Managers use Sign in with SAML and the organization slug on the login page.

The connection tip on SSO is a VisibleHours reading of your row, not a live language model. VisibleHours does not email your identity provider. Employees still install the Windows tray with an invite code — SSO is for managers. Ask “please set up SSO for my company” is refused. Ask “works with every IdP” or “passwordless magic link SSO” is refused. Public Search stays on /features/sso.

What this is not

  • Not an identity-provider certification or a named-vendor security badge.
  • Not OpenID Connect, passwordless, or magic-link sign-in.
  • Not every identity provider — the IdP must publish SAML 2.0 metadata with a signing certificate.
  • Not just-in-time provisioning. The assertion email must already be a manager.
  • Not a change to employee invite codes or the visible tray.
  • Not outreach. VisibleHours does not email the provider from this screen.
  • Sample metadata is a VisibleHours demo IdP, not a live directory.

Related VisibleHours guides

All thirty guides · Site search