Password fatigue
IT tickets for forgotten ERP logins.
Google SSO lets institutions with Google Workspace sign staff (and optionally students) into ScholarERP without separate passwords to forget.
Teachers already live in Gmail; a second ERP password means resets every Monday.
IT tickets for forgotten ERP logins.
Staff create personal emails to “make it work”.
Google suspended but ERP still open.
Two emails for one teacher.
Operational depth your team will use every cycle — not a shallow feature list.
OAuth login for allowed domains.
Map Google groups to ScholarERP roles.
Create users on first login when policy allows.
Disable password login for staff domains.
Different domains per brand/campus.
Respect Workspace admin suspends on next login.
SSO success/failure logs.
Emergency break-glass admin accounts.
A clear path your staff and parents can follow without training manuals.
Register OAuth client & domains.
Link groups to roles.
Enable for IT + one department.
Roll out campus-wide.
The right people see the right slice of the pipeline.
Owns OAuth and domains.
Uses Google account.
When student Workspace exists.
Checks SSO logs.
Each module is an edge in the campus operating graph — not a silo.
Measurable ops wins institutions report once this module runs inside ScholarERP.
“Teacher login tickets dropped sharply after Workspace SSO went mandatory.”
Straight answers for setup, integrations, and day-two operations.
Usually not — parents often use phone OTP/email login. Staff/student Workspace is the primary SSO case.
Yes during pilots; many campuses later enforce SSO for staff.
Break-glass local admin accounts remain available.
SSO covers authentication. Classroom/Docs deep sync is handled by Google Docs / LMS connectors where enabled.
Connect a Workspace domain and map a teacher group to roles.