
AV and event teams have a staffing pattern most software was not designed around: a core crew, a rotating cast of freelancers for the big shows, and a client list that changes every quarter. Every one of those people needs to sign in to your tools, and every one of those accounts is a password someone has to remember, reset or, eventually, revoke. SSO for AV and event teams exists to take that whole problem off your plate.
If you have ever chased down a freelancer three shows after their last gig to ask them to change a shared password, this one is for you.
- SSO moves authentication to your identity provider, Okta, Microsoft Entra ID, Google Workspace or any other OpenID Connect provider.
- Onboarding a freelancer is one IdP group change; offboarding is immediate and centralised.
- SSO and SCIM provisioning are Enterprise plan features. Smaller teams can use passkeys for strong, password-free sign-in instead.
The password problem is worse in event work than most industries
Most SaaS tools are built assuming a stable employee roster: you hire someone, you provision an account, they stay for years, you deprovision when they leave. Event and AV teams do not work that way. A single festival season might bring on a dozen freelance operators for a week, each of whom needs access to the show tooling and none of whom should still have it in October.
Password-based access makes that turnover expensive to manage safely. Every account needs to be created, every departure needs to be caught and revoked, and every password reset request is a support ticket nobody has time for mid-event. Multiply that across the tools a modern event stack actually uses, scheduling, comms, show control, ticketing, and the admin overhead grows faster than the crew list does.
What SSO actually changes
Single sign-on moves authentication out of the app and into your identity provider, whether that is Okta, Microsoft Entra ID, Google Workspace or another OpenID Connect provider. Instead of a separate password for every tool, your team signs in with the same identity they already use for email and everything else.
For an AV or event team, that has three concrete effects:
- Onboarding a freelancer is one IdP group change, not a new account request per tool.
- Offboarding is immediate and centralised. Remove someone from the identity provider and their access to every connected tool goes with it, the same day.
- There is one password to protect, and it is the one your IT team already secures properly, with whatever multi-factor policy they already enforce.
How Cliqer's SSO works
Cliqer's self-service SSO uses OpenID Connect, so it works with any OIDC-compliant provider, including Okta, Microsoft Entra ID and Google Workspace. It is configured entirely from Dashboard → Team → Security, no support ticket required:
- Go to Team → Security → Single sign-on and click Add provider.
- Enter a display name, your provider's issuer URL, and the client ID and secret from the application you create in your IdP. Cliqer fetches the rest of the configuration automatically from the provider's discovery endpoint.
- Optionally restrict sign-in to specific email domains, and choose whether new accounts should be created automatically on first sign-in.
- Save. The provider now appears as a sign-in button on your team's login page.
You can add more than one provider, useful if your agency works with a client's IdP for a specific engagement alongside your own. Full setup detail, including the callback URL your IdP needs, is in the SSO FAQ.

Requiring SSO without locking yourself out
Once at least one provider is tested and working, you can turn on Require SSO, which rejects password and passkey sign-in for the whole team, server-side, not just hidden from the login form. That closes the gap where someone could keep using an old password after their IdP access was pulled.
The one deliberate exception is the team owner, who always keeps password sign-in as a break-glass account, so a misconfigured provider can never lock an entire organisation out of its own tools.
Pairing SSO with team roles
Identity is only half the access story. Once someone is signed in, team roles decide what they can actually do: invite other members, manage branding, touch security settings or API keys. Combining SSO with tightly scoped custom roles means a freelance operator can be given exactly the access a single show requires, no more.
For teams that also need automatic account creation and removal tied directly to HR or crew-management systems, SCIM provisioning goes a step further than SSO alone, syncing the member list itself rather than just the sign-in step. If you are building the case for either feature to your own leadership, our wider guide to getting AV software approved by IT covers how to frame that conversation, and the security checklist for presentation software covers the broader review it usually sits inside.

SSO versus the alternatives
| Approach | Onboarding effort | Offboarding risk | Best for |
|---|---|---|---|
| Shared password | Low upfront, high ongoing | High, requires a manual reset everyone knows about | Nobody, honestly, avoid it |
| Individual passwords | Medium | Medium, relies on someone remembering to revoke | Very small teams, short term |
| Passkeys per person | Low | Medium, still needs manual removal | Small teams without an IdP |
| SSO | Low, one IdP group change | Low, revoked centrally and immediately | Teams already using an identity provider |
If your team is not yet on a formal identity provider, passkeys are a strong middle step, phishing-resistant and password-free, without requiring an Enterprise plan or IdP setup. Identity is one part of a bigger access picture too: pair it with a look at presenting confidential content safely if your team handles sensitive material, and why corporate firewalls block presentation tools if your crew works from client sites with locked-down networks.
FAQ
Not necessarily. SSO authenticates against your identity provider, while passkeys are a sign-in method for accounts without an IdP behind them, or for the team owner's break-glass access even after SSO is enforced.
Yes, SSO and SCIM provisioning are Enterprise plan features, configured self-service once you are on that plan. Smaller teams can still use passkeys for strong, password-free sign-in.
Existing accounts are matched to their SSO identity by an identifier claim, email by default, and keep their existing data and settings. Nothing is lost in the switch.
Only if they have an account in your IdP or one of the providers you have connected. For freelancers outside your identity system, use scoped custom team roles with a passkey or password sign-in instead.
Get started
If password sprawl across a rotating crew is costing you time every show, see how Enterprise covers SSO, SCIM and custom roles together, or read the full security overview for everything self-service on the Team → Security page.
Why Your USB Clicker Fails in Big Venues (and What to Use Instead)
USB and Bluetooth clickers reach 15 to 30 metres at best. Why they fail in big venues and how internet clickers fix it.
Webinar Slide Control: Keep Your Presenter in Charge
Give webinar presenters direct slide control instead of relaying clicks through the host, so they set their own pace.
Run your next show with Cliqer
Keep reading
More security & it for your next show


Presenting Confidential Content: Data Protection for Board Meetings

Passkeys Explained: Passwordless Sign-In for Busy Teams
Get the next guide before your next show
Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.
