Single Sign-On for AV and Event Teams

How single sign-on helps AV and event teams: less password sprawl, faster freelancer onboarding, leavers locked out.

Cliqer Team

8 September 2026 · 6 min read

An event operations manager reviewing a team sign-in dashboard on a laptop backstage

AV and event teams have a staffing pattern most software was not designed around: a core crew, a rotating cast of freelancers for the big shows, and a client list that changes every quarter. Every one of those people needs to sign in to your tools, and every one of those accounts is a password someone has to remember, reset or, eventually, revoke. SSO for AV and event teams exists to take that whole problem off your plate.

If you have ever chased down a freelancer three shows after their last gig to ask them to change a shared password, this one is for you.

Key takeaways
  • SSO moves authentication to your identity provider, Okta, Microsoft Entra ID, Google Workspace or any other OpenID Connect provider.
  • Onboarding a freelancer is one IdP group change; offboarding is immediate and centralised.
  • SSO and SCIM provisioning are Enterprise plan features. Smaller teams can use passkeys for strong, password-free sign-in instead.

The password problem is worse in event work than most industries

Most SaaS tools are built assuming a stable employee roster: you hire someone, you provision an account, they stay for years, you deprovision when they leave. Event and AV teams do not work that way. A single festival season might bring on a dozen freelance operators for a week, each of whom needs access to the show tooling and none of whom should still have it in October.

Password-based access makes that turnover expensive to manage safely. Every account needs to be created, every departure needs to be caught and revoked, and every password reset request is a support ticket nobody has time for mid-event. Multiply that across the tools a modern event stack actually uses, scheduling, comms, show control, ticketing, and the admin overhead grows faster than the crew list does.

If your team cannot answer "who currently has access to our show tools" in under a minute, that is the signal you need SSO, not a training reminder about password hygiene.

What SSO actually changes

Single sign-on moves authentication out of the app and into your identity provider, whether that is Okta, Microsoft Entra ID, Google Workspace or another OpenID Connect provider. Instead of a separate password for every tool, your team signs in with the same identity they already use for email and everything else.

For an AV or event team, that has three concrete effects:

  • Onboarding a freelancer is one IdP group change, not a new account request per tool.
  • Offboarding is immediate and centralised. Remove someone from the identity provider and their access to every connected tool goes with it, the same day.
  • There is one password to protect, and it is the one your IT team already secures properly, with whatever multi-factor policy they already enforce.

How Cliqer's SSO works

Cliqer's self-service SSO uses OpenID Connect, so it works with any OIDC-compliant provider, including Okta, Microsoft Entra ID and Google Workspace. It is configured entirely from Dashboard → Team → Security, no support ticket required:

  1. Go to Team → Security → Single sign-on and click Add provider.
  2. Enter a display name, your provider's issuer URL, and the client ID and secret from the application you create in your IdP. Cliqer fetches the rest of the configuration automatically from the provider's discovery endpoint.
  3. Optionally restrict sign-in to specific email domains, and choose whether new accounts should be created automatically on first sign-in.
  4. Save. The provider now appears as a sign-in button on your team's login page.

You can add more than one provider, useful if your agency works with a client's IdP for a specific engagement alongside your own. Full setup detail, including the callback URL your IdP needs, is in the SSO FAQ.

Requiring SSO without locking yourself out

Once at least one provider is tested and working, you can turn on Require SSO, which rejects password and passkey sign-in for the whole team, server-side, not just hidden from the login form. That closes the gap where someone could keep using an old password after their IdP access was pulled.

The one deliberate exception is the team owner, who always keeps password sign-in as a break-glass account, so a misconfigured provider can never lock an entire organisation out of its own tools.

Test your SSO provider with a second account before switching on Require SSO. A typo in the issuer URL is much easier to fix before enforcement is live than during a show.

Pairing SSO with team roles

Identity is only half the access story. Once someone is signed in, team roles decide what they can actually do: invite other members, manage branding, touch security settings or API keys. Combining SSO with tightly scoped custom roles means a freelance operator can be given exactly the access a single show requires, no more.

For teams that also need automatic account creation and removal tied directly to HR or crew-management systems, SCIM provisioning goes a step further than SSO alone, syncing the member list itself rather than just the sign-in step. If you are building the case for either feature to your own leadership, our wider guide to getting AV software approved by IT covers how to frame that conversation, and the security checklist for presentation software covers the broader review it usually sits inside.

SSO versus the alternatives

ApproachOnboarding effortOffboarding riskBest for
Shared passwordLow upfront, high ongoingHigh, requires a manual reset everyone knows aboutNobody, honestly, avoid it
Individual passwordsMediumMedium, relies on someone remembering to revokeVery small teams, short term
Passkeys per personLowMedium, still needs manual removalSmall teams without an IdP
SSOLow, one IdP group changeLow, revoked centrally and immediatelyTeams already using an identity provider

If your team is not yet on a formal identity provider, passkeys are a strong middle step, phishing-resistant and password-free, without requiring an Enterprise plan or IdP setup. Identity is one part of a bigger access picture too: pair it with a look at presenting confidential content safely if your team handles sensitive material, and why corporate firewalls block presentation tools if your crew works from client sites with locked-down networks.

Passkeys explained

A phishing-resistant middle step for teams not yet on a formal identity provider.

SCIM FAQ

Syncing your crew list automatically instead of handling just the sign-in step.

Getting AV software approved by IT

Framing the case for SSO and SCIM to your own leadership.

Confidential board presentations

Locking down the content itself once identity is under control.

FAQ

Get started

If password sprawl across a rotating crew is costing you time every show, see how Enterprise covers SSO, SCIM and custom roles together, or read the full security overview for everything self-service on the Team → Security page.

SSOidentityevent teamsIT

Written by the Cliqer Team

We build Cliqer, the internet presentation clicker used on stages, in classrooms and in boardrooms around the world.

Run your next show with Cliqer

Any slides, any phone, anywhere. The desktop app hosts the room, presenters just open a link.

Keep reading

More security & it for your next show

An IT manager and an event producer reviewing a procurement form together at a desk
Security & IT

Getting AV Software Approved by IT: A Practical Guide

What an IT security review of AV software actually checks, and how to prepare so your tool gets approved first time.
A boardroom table with a laptop showing an abstract blurred chart, empty chairs waiting for a meeting to begin
Security & IT

Presenting Confidential Content: Data Protection for Board Meetings

Keep board presentations confidential: what should never leave your device and how to check where a tool sends data.
A person unlocking a laptop with a fingerprint sensor instead of typing a password
Security & IT

Passkeys Explained: Passwordless Sign-In for Busy Teams

Passkeys explained simply: how passwordless sign-in works, why it resists phishing and how to turn it on for your team.
Newsletter

Get the next guide before your next show

Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.