Guides · Guide · September 14, 2026
SAML / SSO ACS login for managers
Copy ACS and Entity ID, paste identity-provider metadata, certificate, and issuer. ACS maps a signed assertion to a manager session.
Managers can sign in with SAML after Operations stores one SAML 2.0 connection per organization: metadata URL, issuer, signing certificate, and SSO URL, plus the ACS and Entity ID your provider needs. ACS validates a signed assertion, maps the email to a manager who already exists in that organization, and issues a session. Sample metadata is test mode when a live provider is not set. There is no OpenID Connect path and no passwordless or magic-link sign-in. The Windows tray does not change.
The public page is /features/sso. The click-through is the SSO tutorial. Ask VisibleHours “sso”, “saml”, “single sign-on”, “open sso”, or “configure sso” opens SSO. “how to set up sso”, “sso tutorial”, or “saml tutorial” opens Help. How managers actually reach a session is password or SAML — not OIDC. “Sign in with SAML” opens /login.
Copy ACS and Entity ID, then enable
- Sign in with email and password the first time. Open SSO / SAML.
- Copy Entity ID and ACS. Give them to the identity-provider admin.
- Paste a metadata URL, or issuer and certificate, or use the VisibleHours sample. Save.
- Press Test. VisibleHours fetches the document and copies issuer and certificate when they are present. That is not a provider certification.
- Enable the connection. Managers use Sign in with SAML and the organization slug on the login page.
The connection tip on SSO is a VisibleHours reading of your row, not a live language model. VisibleHours does not email your identity provider. Employees still install the Windows tray with an invite code — SSO is for managers. Ask “please set up SSO for my company” is refused. Ask “works with every IdP” or “passwordless magic link SSO” is refused. Public Search stays on /features/sso.
What this is not
- Not an identity-provider certification or a named-vendor security badge.
- Not OpenID Connect, passwordless, or magic-link sign-in.
- Not every identity provider — the IdP must publish SAML 2.0 metadata with a signing certificate.
- Not just-in-time provisioning. The assertion email must already be a manager.
- Not a change to employee invite codes or the visible tray.
- Not outreach. VisibleHours does not email the provider from this screen.
- Sample metadata is a VisibleHours demo IdP, not a live directory.
Open a real VisibleHours page
Related VisibleHours guides
- Slack, Jira, Asana OAuth and signed outbound webhooks — Ask “integrations guide”
- $7 per seat without live checkout on this page — Ask “pricing guide”
- Invite codes and /join links that do not send email — Ask “invite guide”