Skip to main content
Last Updated: 2026-05-29
Steps: Configure Single Sign-On (SSO) for Contract Management and Document Intelligence

Steps: Configure Single Sign-On (SSO) for Contract Management and Document Intelligence

  • Your Identity Provider (IdP) must support SAML 2.0.
  • Enable the owner, admin, or custom role with the
    Single Sign-On (SSO): Manage permission
    in Contract Management and Document Intelligence.
You can set up SSO to enable users to access Contract Management and Document Intelligence using their existing identity provider credentials. This simplifies the login process for users by eliminating the need to remember separate usernames and passwords. SSO enhances security by centralizing authentication through a trusted identity provider.
Depending on the identity provider you choose, specific configuration details and considerations may apply. Refer to the provider specific content for more information:
  1. In your Identity Provider (IdP), sign in as an administrator.
    1. Add a new SAML application.
    2. Select
      SAML 2.0
      .
    3. Enter these details:
    Option Description
    Application Name
    Contract Management and Document Intelligence
    (Optional)
    Application Logo
    You can link the Contract Management and Document Intelligence logo.
  2. In Contract Management and Document Intelligence, enable SSO.
    1. Click
      Admin
      .
    2. Click
      Single Sign-On
      .
    3. Click
      Add Configuration
      .
    4. Copy these values and paste them into the IdP SSO configuration:
      • Assertion consumer service (ACS) URL:
        The IdP uses the ACS URL to redirect authenticated users after signing in.
      • Service provider (SP) entity ID:
        Contract Management and Document Intelligence uses the SP identity ID as a unique identifier. Workday doesn’t support setting up SSO in multiple workspaces as the Entity ID is the same.
  3. In your IdP SSO configuration, find these details and enter them in Contract Management and Document Intelligence
    Option Description
    IdP name
    The name of your Identity Provider. This is for display purposes only on the Workday sign-in page.
    SSO URL (SAML 2.0 Endpoint)
    The URL where Contract Management and Document Intelligence redirects users to sign in to your IdP.
    IdP ID (Identity Provider Issuer or Entity ID)
    Your IdP unique identifier.
    (Optional)
    IdP metadata URL
    Enter this if your X.509 Certificate is variable or rotating. In some cases, providing this information may eliminate the need to enter the X.509 certificate directly, but this depends on your setup.
  4. In your IdP, open the metadata XML file, copy the X.509 certificate code and paste it into Contract Management and Document Intelligence.
    You can find the X.509 code between the
    Begin Certificate
    and
    End Certificate
    fields, but don’t copy the field names.
  5. In Contract Management and Document Intelligence, select
    Authentication context class
    .
  6. In your IdP, configure
    Attribute mappings
    .
    Copy these attribute names or URLs from your IdP and paste them into Contract Management and Document Intelligence:
    • Email
    • First name
    • Last name
    • Job title
    • Department
    • Role
    Attributes are typically plain text. However, if your IdP is a Microsoft self-hosted server or cloud server (Azure), the attributes might format as URLs. Because attribute field names can be customized or overwritten, verify the exact field names used in your specific setup.
    You can assign multiple departments to the same user. Create a new field designed to store a
    comma-separated string array
    of department names. Example: ["Department1", "Department 2", "Department 3"]. The departments must already exist in Contract Management and Document Intelligence for the user to successfully sign in.
  7. In Contract Management and Document Intelligence, select
    Enable SSO
    .
  8. Select which users must use SSO to sign in. If you select enforcing SSO for all users, the recommended method for user provisioning is to create or assign the user directly in the Identity Provider (IdP).
  9. Assign a default role to new users who sign in through SSO.