Single sign-on
Login through an identity provider with the role granted automatically - hiring and leaving are managed from one place.
Login is solved, permission is not
Single sign-on usually answers only "who is this person". The question "what may they do in the system" is left open - so an administrator assigns a role by hand for every new employee.
The consequence is familiar: the account of someone who has left stays open for months, because closing it is a separate step that is written down nowhere.
The role comes from the HR system
The group name returned by the identity provider is mapped to an ERPONA role. The change is made at the provider, and the system applies it at the next login.
That makes the HR system the single source of truth: when a person moves department or leaves, their ERPONA permissions follow on their own.
Related modules
Core
The foundation every module stands on: targets, signals, the metric store and permission groups - with no industry baked in.
Branding
The interface in your brand: name, logo, colours, email footer and login screen.
Language and terminology
Three languages - Azerbaijani, English, Russian - and the customer's own terms written into the interface.
Most often asked
Which providers are supported?
Providers that support the OpenID Connect standard, corporate directories included.
Does it work without SSO?
Yes. Single sign-on is optional; ordinary username-and-password login always remains.
See this module with your own data
The demo database is full of real documents - not a mock-up. Send a request and we will walk through your scenario.