keySSO — Agents

Enable brand-managed SSO for agent access to Reach Central via your Identity Provider (IdP).

Overview

Agent SSO lets internal users log in to Reach Central using credentials managed by your organization.

Reach delegates authentication to your Identity Provider (IdP). Reach does not store agent passwords.

circle-info

This covers agent access to Reach Central only. Customer SSO is handled separately.

  • What it is: Brand-managed SSO for Reach Central users.

  • What problem it addresses: Centralizes access control, MFA, and deprovisioning in your IdP.

  • Who it is intended for: Brand care, sales, operations, and admin users of Reach Central.

Typical use cases

  • Use existing corporate login for Reach Central.

  • Enforce brand MFA policies for agent access.

  • Simplify onboarding and offboarding of agents.

Scope

  • What is included:

    • SSO integration for Reach Central agent login.

    • Basic identity attribute mapping for user matching and display.

    • Session creation and agent attribution in audit logs.

  • What is excluded:

    • Customer SSO (end-customer login)

    • Authorization decisions made by your IdP.

    • Automatic permissioning in Reach Central based on IdP groups (unless scoped).

Brand inputs

  • Which IdP will be used and who owns it.

  • Which identity fields Reach Central should use (for example email and name).

  • A small set of test users for validation.

  • An approval owner for go-live.

Requesting this bolt-on

For the standard process, commercial notes, and support, see Bolt-ons catalog.

Technical details

For the implementation-specific setup details, visit: SSO technical detailsarrow-up-right

circle-info

Questions or clarification? Reach out to your respective account manager or email at [email protected]

Last updated