Identity provider · SSO

One identity provider, every access your team needs

Vigilioo's IdP gives your team a single login for every system — and gives the company control over when, from where and for how long that access holds. Identity, workday and device under one policy.

1 login

For every system

MFA

Second factor on access

Per shift

Window it holds for

In seconds

To revoke access

The concept

What is an identity provider (IdP)?

An identity provider — IdP — is the service that holds who each person in the company is and vouches for them when a system asks whether that access can be granted. Instead of one password per tool, the person authenticates once and the IdP opens the rest: that is what the market calls SSO, the single login.

At Vigilioo the IdP does not stop at the front door. Because the same platform manages the device, access can also depend on the shift, on idle time and on the state of the machine — and be cut off in the very place it was granted.

Single sign-on (SSO)

One authentication opens the systems the company released for that role.

Second factor

MFA on login and on sensitive actions, with a password policy the company sets.

Access by workday

The session holds inside the shift; outside it, access simply does not open.

Immediate revocation

On offboarding, one click ends the session across systems and on the device.

In practice

What Vigilioo delivers as an identity provider

From a person's first login to their offboarding — with their device in the same conversation.

SSO across company systems

People sign in once and open whatever their role allows, without repeating a password in every tool.

MFA and password policy

Mandatory second factor, expiry and minimum complexity set by the company, not by whoever is using it.

Role-based permissions (RBAC)

Who sees what in the console and what they can run — including who is allowed to lock a device.

Shift control

Working hours, workload and overtime rules per device, measured by the agent itself.

Idle lock

No keyboard or mouse for as long as the policy defines and the session drops, with the screen locking on its own.

Precautionary device lock

On suspicion of an incident, the machine is locked remotely and the person's access is suspended in the same action.

Workday

Access follows the workday, not the other way around

The identity is the same all day; what changes is what it can do at each point of the shift.

Today's workdayAccess granted
Check-in 08:57Check-out 18:12
Working hoursIdle · screen lockedOvertimeAccess ended
Shift

Shift control

Check-in and check-out measured by the agent. Outside the shift window access does not open — and whatever happens outside it is recorded.

Idle

Idle lock

Once the defined time passes with no keyboard or mouse, the screen locks and the session expires. A device left open stops being a risk.

Overtime

Overtime with a rule

Work beyond the workload becomes a balance, with an alert for the manager and a policy cap — instead of showing up only at month-end.

Incident

Precautionary lock

On suspicion of a leak or misuse, one click takes the device offline and ends that person's access across every system.

Life cycle

From onboarding to offboarding, with no orphan access

The four stages in which an identity is born, works, changes and dies inside the company.

1

Onboard

The person joins with a defined role and gets only the access that role carries.

2

Authenticate

Single login with a second factor, on a device the company recognises.

3

Follow

Shift, idle time and sensitive actions stay on the access trail.

4

Revoke

On offboarding, session and access fall together — the device included.

Questions

Frequently asked questions about IdP and SSO

What IT, security and HR usually ask before signing.

Want to see single sign-on running in your operation?

We walk through SSO, the second factor and end-to-end access cut-off, using the systems and devices your company already runs.

Book a demo

Ready to monitor your team with precision?

Start for free today. No credit card required. Set up in less than 5 minutes.

7-day free trial
No credit card
Cancel anytime
Real-time screen monitoringUSB and Bluetooth port lockdownShift control with automatic time trackingSites and programs allowed by policyLocation and geographic boundariesPrecautionary device lockTeam productivity reportsEnd-to-end AES-256 encryptionReal-time screen monitoringUSB and Bluetooth port lockdownShift control with automatic time trackingSites and programs allowed by policyLocation and geographic boundariesPrecautionary device lockTeam productivity reportsEnd-to-end AES-256 encryption