Setting Up Single Sign-On (SSO) for Your Institution

Connecting Supervision Assist to your institution's Single Sign-On (SSO) system streamlines login for your faculty and students.

Because SSO configuration involves technical settings managed by your school's central IT team, setting up SSO is a coordinated process between you (the Coordinator), your Supervision Assist Account Manager, and your IT/Identity Administrator. Our support team performs all configuration inside Supervision Assist.


Before You Begin

  • Supervision Assist connects over SAML 2.0 and works with any SAML 2.0-compatible identity provider, including Microsoft Entra ID (Azure AD), Okta, Shibboleth, and Google Workspace.
  • Accounts are matched by email address. Each user's Supervision Assist email address must exactly match the email address in your institution's identity provider, and the user must already hold a position at your organization.
  • SSO applies to the roles you choose. During setup we agree on which roles must sign in through your identity provider, typically Coordinators, Faculty Supervisors, and Trainees. Users in roles not included (for example, off-site supervisors without institutional accounts) continue to sign in with their password.
  • SSO links existing Supervision Assist accounts. It does not create new accounts. Users must already have a Supervision Assist account (created through your normal invitation process). The first time a user signs in through your institution's SSO, their Supervision Assist and institutional accounts are linked automatically.
  • If your institution has more than one program or department in Supervision Assist (for example, separate organizations for School Counseling and MFT), each one is configured as its own SAML application. Your IT team will register a separate application in your identity provider for each, using a unique set of SP values we provide. The identity provider and metadata URL are the same for all of them, so Step 1 only needs to happen once.

Step 1: Email Your IT Administrator and CC Your Account Manager

Send the message below to your IT or Identity team and CC your Supervision Assist Account Manager or help desk. This lets our technical team coordinate directly with your IT department from the start.


Copy and paste template:

Subject: Request to configure SAML 2.0 SSO for Supervision Assist

Hi [IT / Identity Admin Name or Team],

We are setting up Single Sign-On (SSO) for Supervision Assist. I have copied our Supervision Assist account representative on this email so the two teams can coordinate directly.

Could you reply-all with the SAML 2.0 metadata URL for our identity provider? This is the address of the IdP's federation metadata document and usually looks something like https://login.example.com/federationmetadata/2007-06/federationmetadata.xml.

In your IdP's admin console it may be labeled "Metadata URL", "App Federation Metadata Url", or "Federation metadata document". Supervision Assist reads everything it needs from that URL, including the entity ID and signing certificate, so it is the only value required to get started.

Note: we have [number] programs set up in Supervision Assist, so you will be asked to register [number] separate SAML applications, all pointing to our same identity provider. (Remove this line if you have only one program.)

For reference: Supervision Assist connects over SAML 2.0, matches accounts by email address, and expects the identity provider to sign both the response and the assertion.

Thank you for your help, [Your Name]

Step 2: Your IT Team Configures the SAML Application

Once we have your metadata URL, our team sends your IT administrator the values they need to finish the setup on their end, again directly from Supervision Assist.

Each Supervision Assist organization has its own dedicated SP Entity ID, SP ACS (Reply) URL, and SP Metadata URL. If your institution has multiple departments in Supervision Assist, we will send your IT team one set of these values per department, and each set is registered as its own SAML application in your identity provider.

For reference, your IT team will be asked to:

  • Send the user's email address as a SAML attribute (standard attribute names are accepted).
  • Use a persistent NameID, meaning any stable identifier that won't change for the user.
  • Sign both the response and the assertion.

They will not need to configure single logout, assertion encryption, group attributes, or first/last name attributes. Supervision Assist doesn't use them.

Our team will provide your IT team everything they need to copy into the SAML application.


Step 3: Verification and Activation

Our technical team works with your IT department to complete and test the configuration. Most single-organization setups are finished within 2 business days of receiving the metadata URL. If your institution has multiple departments in Supervision Assist, each application is verified separately, so allow additional time depending on your IT team's process. Once everything is verified, we activate the connection for the agreed roles and send you a confirmation email letting you know SSO is active for your organization.


What Users Will Experience

After SSO is enabled, users in the included roles authenticate through your school's login portal when accessing Supervision Assist:

  1. The user enters their university email address on the Supervision Assist login page.
  2. The user is redirected straight to your university's SSO portal to sign in. No Supervision Assist password is requested.
  3. The first successful sign-in links their Supervision Assist and university accounts. After that, they sign in through your portal every time.

Note: A user's Supervision Assist email address must match the email address in your university's SSO system. If the addresses do not match, the user will see "Sorry, but the single sign-on account you supplied does not match any account on file." and will not be able to log in. Contact your Account Manager to correct a mismatched email address.

Still need help? Contact Us Contact Us