Single Sign On (with SAML)
David van de Maas from ngage explains: “As soon as the option became available, our organisation set up a federation with ClockWise using SAML.”

What is SAML?
“In short, it is web-based Single Sign-On across domains. The service provider ClockWise (SP) leaves authentication to the identity provider ngage (Identity Provider or IDP). SAML is based on trust, a trust between the IDP and the SP. The user experiences it as a true Single Sign-On: once logged in to our portal, you are no longer asked for a user name and password to use ClockWise.” “ngage specialises in Identity & Access Management. SAML is an important part of Access Management and we implement it frequently for our clients. From government services to publishers and from cloud applications to webshops.”
Why SAML?
“ClockWise is one of the business-critical (financial) applications. The time tracking and the invoices that are generated are an important part of running the business. Using a federation through SAML delivers a few important benefits.”
Security
“In our view, business-critical applications should be secured with more than just a user name and password. Multi Factor Authentication (MFA) is used for this, so a user name and password plus a token, SMS, Yubikey or smartcard. Implementing MFA on all the systems and applications you use can become a complex affair, though. There are many solutions, and not every application supports every method. By using one single source of authentication, namely our IDP, a password policy only has to be enforced in one place and an MFA solution only has to be used on that system. On top of that, SAML is extremely suitable for enforcing authorisations centrally.”
Ease for administrators
“The technical or functional administrators of an application such as ClockWise do not have to reset passwords, set up self-service for it or write procedures for it.”
Ease for users
“Not only will users not have to enter a password for every application, they also do not have to change their password in various systems.”
Implementing SAML
“Putting SAML into use can range from remarkably simple to extremely complex. That complexity is mainly caused when the message traffic contains very specific elements. The SAML (2.0) standard has been around since 2005, though, and is a widely used method, so it is fully matured.”
SAML and ClockWise
“The SAML integration with ClockWise falls into the remarkably simple category. In the ClockWise settings you can start a wizard to define an external authentication provider, which sets up the configuration on the ClockWise side. The next step is defining the service provider on the IDP side. In our case we use MicroFocus Access Manager, which meant that there too we only had to start a wizard. It worked straight away. An interesting option that ClockWise has built in is that, per type of user, you can let the user choose between providers.”
Are you already a customer, or would you like more information?
Then take a look at our knowledge centre. There you will find detailed manuals and all the settings for each integration.

Experience it yourself
We understand that implementing ClockWise straight away is a big step. That is why we offer ClockWise free for 4 weeks. During those 4 weeks you can use all the features, with the support of our service desk.
Frequently asked questions