Single sign-on is not self-serve. There is no SSO section in your settings and nothing for you to configure. It is arranged for your email domain by us.
What the SSO page does
There is a single sign-on option on the sign-in page. Enter your work email address and it checks whether an identity provider has been configured for your domain.

- If one has, it sends you to your provider.
- If it has not, it tells you so and points you back at email sign-in links, which always work.
Most companies will see the second message, because domains are configured one at a time on request.
What you probably want instead
For most teams, connecting a Google or Microsoft work account does the job that SSO is usually asked for: staff sign in with the company account they already use, with one click, and nothing new to remember. It is available to every account today and takes a few seconds per person.
Set it up under my profile. Email sign-in links keep working alongside it.
Asking for SSO
Email support@testcandidates.com with:
- your email domain,
- which identity provider you use,
- who at your end can configure it.
We will tell you what is possible for your setup before you commit to anything. If your security review needs a written answer about what is and is not supported, ask and we will give you one rather than a marketing page.
What SSO does not do here
It does not add per-user roles or per-assessment permissions. Everyone on the account still sees everything, however they signed in. See what your team can see.
It also does not change how candidates get in. Candidates never use your identity provider; they use the link in their invitation.
Provisioning accounts
There is no automatic user provisioning or deprovisioning. Adding and removing colleagues is done on the team page, and it should be part of your leaver process. See add and remove team members.