Skip to main content

Single sign-on (SSO)

CollegeVine supports two kinds of SSO. The first (admin SSO) is for university administrators accessing the CollegeVine platform. The second (constituent SSO) is for users engaging with the agent about sensitive data. This article provides an overview of each functionality, and how to set it up with your CollegeVine team.

Admin SSO

CollegeVine can support SSO with any IdP, to provide your users with a secure, auditable login experience. To set up SSO, let your CollegeVine team know, and you'll receive a link to a self-service ticket where you can upload your metadata, and which will contain CollegeVine's EntityID and Single Sign-On URL. For more details, check out this article!

Required Attributes

CollegeVine requires an email_verified attribute to be returned as true. During the handshake, this attribute ensures that the email being passed to us has been verified by your IdP, so that your team can trust only valid users are accessing the CollegeVine platform.

User Verification by CollegeVine

For an extra layer of security, after a user logs in using SSO for the first time, they will initially only have access to a generic landing page within the CollegeVine platform. Our operations team will confirm the user is a member of the team working on the CollegeVine project, and then assign them to your school instance, where they will be able to access your agents.

If you would like user sessions on the CollegeVine platform to time out after a certain amount of time (24 hours, for example), your team can also configure that for you. If no custom timeout is set, the default is two weeks.

Constituent SSO

To ensure your agents share sensitive information only with the correct user, CollegeVine allows you to mark data properties as sensitive. When the agent tries to retrieve one of these properties, it will be blocked from doing so until the user has authenticated using their institution credentials.

Configuration Steps

  1. This configuration also starts with a self-service ticket. Note that even if you have admin SSO set up, you will still need a new ticket, as constituent authentication is housed in a different tenant in CollegeVine's IdP

  2. After completing the ticket, inform your CollegeVine team which properties you would like to mark as sensitive. Fields that our partners commonly mark sensitive typically involve financial information, but any field can be selected!

    • Note: If you would prefer not to test with real data, we can set up a dummy field for you

  3. CollegeVine will provide you with the agent's email address and/or phone number so that you can test by asking the agent a question related to the sensitive field(s)

  4. When the agent receives the question, it will tell you that you must authenticate before it can answer. You will receive an authentication link, which will take you to your institution's SSO portal

  5. Once you have authenticated, the agent will respond to your question

  6. Like for admin SSO, your CollegeVine team can set a custom timeout on how long users will be authenticated for. During this authentication window, the agent will not trigger SSO before responding to questions about sensitive data

FAQs

Q: How does the agent know which constituent should be authenticating?
A: The agent matches the inbound communication channel (email address or phone number) to a constituent record that your team has uploaded. Following the handshake, the agent will match the email received from your IdP to the email contained in that constituent record.

Q: Can all users interacting with the agent authenticate using SSO?

A: No, users must have an institutional email in order to authenticate. This scope ensures maximum security around sensitive information, as users can only access this information if they have a record in your IdP. The agent will not share sensitive data with prospective students, or students who will be enrolling but haven't yet received a school email.

Q: Do you support other methods of authentication for users (MFA code, security questions, etc.)?

A: Not at this time.

Q: Do you support SSO during phone calls?
A: Not at this time. If a caller asks about a sensitive property, the agent will tell them it cannot access that information.

Did this answer your question?