Single Sign-On (SSO) allows your organization to securely access Spruce using your existing identity provider (Google Workspace), eliminating the need for teammates to manage separate Spruce passwords. SSO is only available on the Communicator Plan with the purchase of an add-on.
IN THIS ARTICLE
- Introduction to Single Sign-On (SSO)
- How to Enable SSO with Google Workspace (Web Browser Only)
-
Google Workspace SSO FAQs
Introduction to Single Sign-On (SSO)
Single Sign-On (SSO) helps organizations manage access more securely and efficiently by requiring that teammates sign in to Spruce with the same credentials as their organization’s SSO provider (ex. Google Workspace). SSO is only available on the Communicator Plan with the purchase of an add-on.
This article specifically covers how to enable Google Workspace SSO in Spruce. Learn more about Single Sign-On (SSO) management at Spruce.
How to Enable SSO with Google Workspace (Web Browser Only)
Step One: Purchase SSO Add-On
Single Sign-On (SSO) is available for customers on the Communicator plan with an add-on purchase of $300/month. Administrators must purchase the add-on before they can connect to an SSO provider in Spruce.
- Navigate to Settings > Organization Preferences > Single Sign-On (SSO) Authentication
- Click “Purchase SSO Add-On.” A dialog will appear on your screen.
- Check the checkbox to confirm you understand that your Spruce plan and monthly pricing will be adjusted.
- Click “Purchase Spruce Add-On” to complete your purchase. You will not be billed for the add-on until you enable SSO for your organization.
Step Two: Enable SSO for your organization
Once the add-on purchase is completed, administrators can enable Single Sign-On (SSO) for their organization using Spruce in a web browser by navigating to Settings > Organization Preferences > Single Sign-On (SSO) Authentication.
Enabling Google Workspace SSO
You must be an administrator in your Google Workspace in order to complete this process, and your Spruce account email must match the email from the Google Workspace that you’d like to connect to.
- In Spruce, go to Settings > Organization Preferences > Single Sign-On (SSO) Authentication. If you have not purchased the SSO add-on yet, please follow the steps above before proceeding.
- Tap Connect next to Google Workspace to be taken to the Google Workspace SSO page where you can begin the connection process.
3. Begin Step 1 > Authenticate With Google Workspace SSO
- Tap > Log in to Google. You must log in using the same email from the Google Workspace that you’d like to connect to Spruce.
- The domain of your Google Workspace must also be the same as the domain as your Spruce account email address. (Ex: @organization.com)
4. Begin Step 2 > Review Spruce Teammate Emails
- Note: In some cases, this step may be automatically completed and a green checkmark will be displayed. If so, you can move to Step 3.
- Tap > Check Spruce Teammate Emails. This will ensure that all existing Spruce teammates use the same Google Workspace domain on their Spruce account email addresses. Ex: If your organization uses @exampleclinic.com, all teammates in Spruce must use an @exampleclinic.com email address.
- If any account emails do not match, a dialog will display which teammates need to update their email address. Ask teammates to update their Spruce account email address by going to Settings > Account > Edit Email.
- SSO cannot be enabled for your organization until all Spruce teammate account emails match your Google Workspace domain.
5. Begin Step 3 > Enable SSO for Your Organization
- Check the checkbox to confirm you understand the implications of turning on SSO for your organization.
- Tap Enable SSO to complete the connection.
6. Once you enable Google Workspace SSO, the following actions will take place:
- You will be returned to the main SSO page and will see a “Connected SSO Provider” card with a green checkmark, indicating that the connection was successful.
- All Spruce teammates will immediately be logged out of their Spruce accounts across all devices, and can no longer log in using an email and password. Teammates will need to log in to Spruce again using their Google Workspace email, and will authenticate through Google.
- Password-based login and two-factor authentication will be disabled for your organization.
-
If teammates are on an active phone call, they will be able to finish their call before being logged out.
Spruce does not support automatic provisioning or de-provisioning with Google Workspace.
Administrators must still:
- Manually invite teammates in Spruce
- Manually remove teammates in Spruce. You will be charged for all teammates until they are removed.
Removing someone from Google Workspace does not remove them from Spruce. Learn more about managing teammates in Spruce.
Learn more about the following in the Single Sign-On SSO article:
- Inviting Teammates to Spruce with SSO
- Removing Teammates from Spruce with SSO
- Disabling SSO for your Organization
- Managing other SSO settings
Google Workspace SSO FAQs
Can teammates join automatically with our Google Workspace domain?
No, teammates must be manually invited through Spruce.
Does Spruce automatically create teammate accounts from Google Workspace?
No, Spruce does not support automatic provisioning with Google Workspace at this time.
Does removing someone from Google Workspace automatically remove them from Spruce?
No, Spruce does not support automatic de-provisioning with Google Workspace at this time. Admins will need to manually remove teammates in Spruce.
Will enabling Google Workspace SSO overwrite the name/title/display name of an existing Spruce account?
No. It will only pull this information from Google Workspace for new Spruce accounts.
If SSO is enabled, are admins able to sign in to Spruce using an email and password?
No. Once SSO is enabled, all teammates must sign in to Spruce with their authenticated Google Workspace email address.
How does changing/updating an email address in Google Workspace affect the same Spruce account using SSO?
If a Spruce teammate’s email address is changed in Google Workspace, they will not be able to log in. Contact Spruce support to have this information updated.