SSO go-live plan
Enabling SSO changes how everyone in your organisation signs in to CheckWorkRights. This article covers how to plan that switch.
CheckWorkRights lets you configure and test SSO before switching it on, you can do all the preparation first and pick your cut over moment.
Not set up yet? Start with Setting up SSO.
Before you go live
You should be at Connection Test Successful before working through this. Your configuration is proven, but SSO is still off and nothing has changed for your users.
Reconcile your user lists
This is the single highest-value thing you can do. Almost every "I can't log in" report after go-live traces back to it.
Compare your CheckWorkRights user list against your identity provider. For every active CheckWorkRights user, confirm:
- They exist in your identity provider.
- Their CheckWorkRights email matches their identity provider primary email (their UPN) exactly.
- They are assigned to the CheckWorkRights application in your identity provider.
Test with more than one account
The connection test only proves your own account works. Before you enable, have at least one other person test as well, ideally:
- A second Administrator, so you are not the only person who can get in and turn SSO off again if needed.
- A standard user on a different access profile, since permissions problems look very different to authentication problems.
Tell people beforehand
A short message a few days ahead is enough. Worth including:
- The date SSO goes live.
- That they will sign in with their work credentials from that date, and their CheckWorkRights password will stop working.
- That the login page does not change. They enter their email at the usual CheckWorkRights login page and are redirected automatically. They should keep using the CheckWorkRights URL or bookmark rather than looking for it in a company app dashboard.
- Who to contact if they cannot get in.
Know your fallback
An Administrator can disable SSO at any time, which returns everyone to password login immediately. Note that this also clears your saved configuration, so you would need to enter your provider details again to switch SSO back on.
If your administrators themselves cannot get in, contact the CheckWorkRights team and we can recover access.
On the day
- Enable SSO. Go to Admin > Integrations and click Enable.
- Sign in yourself. Confirm the live flow works, not just the test.
- Have someone watching for the first hour or two. Most issues surface immediately and are quick to resolve.
Go-live problems usually affect individual users rather than everyone, and are fixed by correcting an email address or an assignment in your identity provider rather than by turning SSO off.