Skip to main content

Configure Single Sign-On (SSO)

Single Sign-On (SSO) is available for customers to access the app through a single authentication source.

Written by Mari

⭐️ This is available only for workspaces on the Enterprise plan. Find out more about Pitch plans and pricing. ⭐️

Set up SSO for your team

Please note the SSO settings are not automatically turned on when you upgrade to Enterprise. Interest must be registered with the Pitch team to enable it for your workspace before you may begin the connection.

After SSO has been enabled by the Pitch team, an admin in your workspace will need to connect your account with WorkOS (the external SSO provider we use).

  1. To get started, visit the Workspace settings page where you'll now find a field to Manage single sign-on (SSO).

  2. Ensure you are the General section of your workspace settings.

  3. Click the Manage SSO button to open WorkOS in a new window and begin your setup.

Once connected, you will enter self-service configuration on WorkOS. Select your identity provider (IdP), follow the on-page instructions and once completed, SSO will be activated for your workspace. All users in your Pitch workspace will only be able to use SSO as their login method from now on.

Connect your identity provider using WorkOS

In order to complete the SSO sign-up process, a member of your IT team will need to connect your identity provider (IdP) using WorkOS. After opening the admin portal, you will be asked to select your IdP. Based on your selection, you'll see a set of instructions to complete your setup.

You can review configuration guides for Azure, Google, Okta, and other IdPs in the WorkOS guides. If you have any specific questions about WorkOS, you can contact their team at support@workos.com.

Making adjustments to your configuration

After your connection has been activated, you may want to make the following changes:

  • Add multiple domains to one configuration

  • Connect multiple Pitch workspaces per configuration

  • Add individual workspaces to multiple configurations

If you have questions about this, or want to add additional domains or workspaces to your SSO set up, please reach out to the Pitch support team using the in-app messenger or by emailing support@pitch.com.

SCIM

Pitch offers System for Cross-domain Identity Management for customers on our Enterprise plan. SCIM in Pitch can do the following:

  • Provision and de-provision users

  • Sync user profile changes (Name, Email, etc.)

We don't support role assignment currently. All provisioned users will be provisioned as workspace creators.

SCIM setup should be actioned through an IT admin as it requires technical setup through our SSO provider, WorkOS. If you are setting up SCIM for your workspace, please refer to their guides for Okta, Azure, or other IDPs.

If you are on an Enterprise subscription, reach out to your customer success manager to begin the process of enabling SCIM.

If you aren't sure about what subscription you have, please go to your Billing page to confirm.

Frequently asked questions

How do I purchase SSO for my team?


SSO is part of our Enterprise plan. Please get in touch with our team to discuss pricing and enablement options. You can contact us through the Contact us option on our pricing page, or email the team at support@pitch.com.

Can I use other sign-in methods after SSO has been enabled?

Once SSO is enabled, users will only be able to sign into new or existing accounts through SSO. All previous sign-in methods (e.g, email and password) will not work going forward. SSO is configured on a domain — not a workspace — level, so users will need to sign in with SSO in order to access any workspace, even ones on the Starter plan or not affiliated with your company.

What happens to our data after enabling SSO?


All data is preserved and no data is modified except for adding the SSO configuration information. Once any user logs into a newly SSO-enabled workspace, they will have the same experience as before.

Can two SSO setups share the same domain?

A configuration (SSO setup via your IdP) can have multiple domains associated with it, and manage multiple Pitch workspaces. Additionally, one Pitch workspace can be a part of two or more SSO setups. However, it is not possible for the same domain to be associated with more than one SSO setup.

How do we modify our SSO setup?


You can configure and maintain your IdP connection using the admin panel in WorkOS. You can open the admin panel by navigating to your Workspace settings in Pitch and clicking on Manage SSO. It's not possible to manage your SSO connection directly in Pitch.

If you would like to add additional domains or workspaces to your setup, please reach out to us.

What if we want to disconnect SSO?


If you're interested in disconnecting SSO for your workspace, please contact our support team through the messenger in the app, or by emailing support@pitch.com.

Did this answer your question?