Skip to main content

Single sign-on (SSO)

CollegeVine supports two kinds of SSO. The first (admin SSO) is for university administrators accessing the CollegeVine platform. The second (constituent SSO) is for users engaging with the agent about sensitive data. The article below provides an overview of each functionality, and how to set it up with your CollegeVine team.

Admin SSO

CollegeVine can support SSO with any IdP, to provide your users with a secure, auditable login experience. To set up SSO, let your CollegeVine team know, and you'll receive a link to a self-service ticket where you can upload your metadata, and which will contain CollegeVine's EntityID and Single Sign-On URL. For more details, check out this article!

Admin SSO login flow

When admin SSO is enabled for an institution, SEM users who visit platform.collegevine.com and click Log In are redirected to the institution's SSO provider to authenticate. Once credentials are verified, users are redirected back to platform.collegevine.com with access to the platform.

Even when SSO is enabled, users who are accessing the platform for the first time must still be verified as SEM users through the standard verification process — see the User verification by CollegeVine section below for details.

Note that constituent SSO — used for constituent-facing properties such as the agent — is a separate configuration that may also be enabled alongside admin SSO. Having admin SSO set up does not automatically apply to constituent-facing experiences.

Required attributes

CollegeVine requires an email_verified attribute to be returned as true. During the handshake, this attribute ensures that the email being passed to us has been verified by your IdP, so that your team can trust only valid users are accessing the CollegeVine platform.

User verification by CollegeVine

For an extra layer of security, after a user logs in using SSO for the first time, they will initially only have access to a generic landing page within the CollegeVine platform. Our operations team will confirm the user is a member of the team working on the CollegeVine project, and then assign them to your school instance, where they will be able to access your agents.

If you would like user sessions on the CollegeVine platform to time out after a certain amount of time (24 hours, for example), your team can also configure that for you. If no custom timeout is set, the default is two weeks.

Constituent SSO

To ensure your agents share sensitive information only with the correct user, CollegeVine allows you to mark data properties as sensitive. When the agent tries to retrieve one of these properties, it will be blocked from doing so until the user has authenticated using their institution credentials.

Configuration steps

  1. Configuration starts with a self-service ticket. Note that even if you have admin SSO set up, you will still need a separate ticket, as constituent authentication is housed in a different tenant in CollegeVine's IdP

  2. After completing the ticket, inform your CollegeVine team which properties you would like to mark as sensitive. Fields that our partners commonly mark sensitive typically involve financial information, but any field can be selected!

    • Note: If you would prefer not to test with real data, we can set up a dummy field for you

  3. CollegeVine will provide you with the agent's email address and/or phone number so that you can test by asking the agent a question related to the sensitive field(s)

  4. When the agent receives the question, it will tell you that you must authenticate before it can answer. You will receive an authentication link, which will take you to your institution's SSO portal

  5. Once you have authenticated, the agent will respond to your question

  6. Like for admin SSO, your CollegeVine team can set a custom timeout on how long users will be authenticated for. During this authentication window, the agent will not trigger SSO before responding to questions about sensitive data

FAQs

Q: How does the agent know which constituent should be authenticating?
A: The agent matches the inbound communication channel (email address or phone number) to a constituent record that your team has uploaded. Following the handshake, the agent will match the email received from your IdP to the email contained in that constituent record.

Q: Can all users interacting with the agent authenticate using SSO?

A: No, users must have an institutional email in order to authenticate. The scope of authentication ensures maximum security around sensitive information, as users can only access this information if they have a record in your IdP. The agent will not share sensitive data with prospective students, or students who will be enrolling but haven't yet received a school email.

Q: Do you support other methods of authentication for users (MFA code, security questions, etc.)?

A: Not at this time.

Q: Do you support SSO during phone calls?
A: Not at this time. If a caller asks about a sensitive property, the agent will tell them it cannot access that information.

Did this answer your question?