Skip to content

How it works

Set up in an afternoon. No vendor calls.

There is nothing to install in your tools and nothing to ask their sales teams for. SmashSSO uses the admin access you already have.

  1. 1

    Sign in with Google Workspace

    Google is your list of people. The moment you sign in, we read your directory and everyone shows up: name, email, title, and whether they are active or suspended.

    Needs a Google Workspace admin account. We ask for read-only access to the user directory and nothing else.

  2. 2

    Pick the tools you use

    Choose from the catalog or add your own. If you run two accounts of the same product, say a main GitHub organization and a demo one, add it twice.

    Things with no member management, like a shared API key, can be tracked by hand so the picture is complete.

  3. 3

    Log in to each tool, once

    We open a real browser on our side and stream it to you. You log in with your own admin account, or with a dedicated one you created for SmashSSO, 2FA included. When you are in, you press Save.

    We never see or store your password. We keep the session the tool gave you, encrypted. Tools with a member API take a token instead.

  4. 4

    We read what is already there

    For each tool, a read-only pass collects its roles and its members, then matches members to your people by email. The access grid fills in tool by tool.

    Accounts that match nobody, such as contractors and personal emails, are added and flagged for you to review.

  5. 5

    You run it from one screen

    Grant access, change a role, remove someone. Each change becomes a run: an API call where there is one, an agent in a browser where there is not.

    Runs that would add a paid seat stop and wait for your approval. Every run keeps a step log and a final screenshot.

Two ways to act

API when we can. Agent when we must.

API connectors

Some tools let any paying customer manage members by API. For those we call the API: fast, exact, and nothing to watch. You give us a token with member permissions.

UI agents

Most tools either have no member API or reserve it for Enterprise. For those, an AI agent opens the admin page in an isolated browser, signed in with the saved session, and works the screen: find the member list, press Invite, type the email, choose the role, confirm. It takes a minute or two.

By hand, on the record

A few things cannot be automated. You can still record who has them, so offboarding tells you what is left to do.

See which tools use which

When a session expires

Tools log you out eventually. When that happens the tool is flagged, its runs wait, and you get an email. Log in again and they continue.

When an agent gets stuck

Screens change and agents sometimes fail. A failed run says so, shows you its last screenshot, and never pretends. You can retry or do that one by hand.

When something costs money

If an invite would add a paid seat or touch billing, the run pauses. Nothing is bought until you approve it.

Connect your first tool today.

Sign in with Google Workspace, connect your tools, and see who has access to what in minutes.

Sign up with Google