Google SSOIdentity and Access
One Google Account Covers Staff And The Public
A school district on Google Workspace has issued an account to every teacher and administrator, and outside the district a Google account is what most of the population carries anyway. This record covers both, on Nexus positioned as the Enterprise Video Platform. Staff reach the internal library with their Workspace account, and a parent reaches a public portal with an ordinary personal account. Google authenticates both and keeps the password.
What you can do together
One account for the whole staff
Teachers and administrators open the library on Nexus with the Workspace account they use for mail, under whatever second step the district enforces at Google.
No registration form for families
A parent or a former student signs in to a public portal with the account they have had for years, with nothing created in advance and no password for the help desk to reset.
Entitlement set once per door
The SSO app carries a default Client Access License, so staff arrive with the right features and public visitors get what the portal grants them.
Two audiences that never meet
Social sign-in is licensed and enabled separately from the corporate SSO app, so opening a public portal changes nothing for staff.
How it connects
Two apps, each configured per portal under Admin, Portal Settings, Apps. The first is the corporate SSO app, given Google's metadata address or a client id and secret. Google authenticates the user under Workspace policy and returns claims, which attribute mapping writes into profile fields. A first-time user is created at that moment on the app's default Client Access License, the portal's bundle of features and permissions. Force login makes Google the only way in, leaving password policy and the second step where the Workspace administrator already manages them.
The second is social sign-in, licensed as its own feature and enabled per portal for public viewers rather than staff. A visitor picks Google on the sign-in page, authenticates there and reaches shared content. A personal account sits outside the Workspace directory and brings no groups, so what that visitor may open is decided by the portal's settings rather than by directory membership.
Nothing is written back to Google either way. A suspended Workspace account stops at Google, so the next sign-in fails there. A personal account is the visitor's own property, so the portal is where their access ends.
Google SSOIdentity and Access
A scenario
- August, ITThe systems administrator adds a corporate SSO app to the staff portal, maps name and email, sets the default Client Access License and turns on force login. On the public portal she enables Google social sign-in instead, and sets what a signed-in visitor may open.
- First week of term, 07:40A principal opens the staff library, signs in at Google with her district account and its second step, and the recording plays with her profile filled in.
- SeptemberA new teacher signs in for the first time, and Nexus creates his account at that moment on the default Client Access License. Nobody in IT typed his name.
- Board night, 20:15A parent opens the public portal, picks Sign in with Google and uses her personal account. She is watching the meeting seconds later, and the district issued her nothing.
- JuneA teacher leaves and the district suspends his Workspace account, so his next sign-in stops at Google. The parent's account still works, because it was never the district's to suspend.
What stays where
Google remains the identity provider
Workspace governs the password, the second step and the state of every staff account. Nexus is a service provider and never becomes an identity provider, for either kind of account.
Sign-in reads and writes nothing back
Claims arrive at sign-in and fill profile fields. Nothing is sent to Google, and no Workspace setting changes because a portal joined the list.
The portal decides what a visitor may see
A personal account carries no directory groups, which is the trade for admitting people the district does not employ. Entitlement for those visitors is set in the portal rather than inherited from Workspace.
Where you deploy is where it runs
Shared SaaS, a dedicated cloud or the district's own datacenter.
Products and solutions
Next step
See it on your own Google SSO instance.
We will show the connection made, the data moving and the output, then size it for your deployment.
Contact VIDIZMO
sales@vidizmo.ai
+1 571-969-2180
vidizmo.ai