What is Costpoint Single Sign-On?

Definition

Costpoint Single Sign-On is an authentication approach that allows authorized users to access Costpoint through a centralized identity provider rather than maintaining a separate login experience for the application. It connects Costpoint access with an organization's broader identity and access management framework.

For finance and operations teams, SSO can create a consistent authentication process for employees who work with project accounting, procurement, billing, general ledger, reporting, and other Costpoint functions. Access to Costpoint remains governed by assigned roles and permissions, while authentication is handled through the organization's approved identity infrastructure.

How Costpoint Single Sign-On Works

A typical SSO setup involves Costpoint, an identity provider, user accounts, authentication protocols, and authorization rules. When a user attempts to access Costpoint, the application can rely on the identity provider to authenticate that person's identity. After successful authentication, the user receives an authenticated session that permits access according to configured Costpoint permissions.

The distinction between authentication and authorization is important. Authentication confirms who the user is, while authorization determines which Costpoint functions, records, projects, or financial activities that user can access.

  • Identity provider: Maintains or federates user identities and handles authentication.
  • Authentication protocol: Establishes how identity information is exchanged between systems.
  • Costpoint roles: Determine the functions and data available after authentication.
  • Session controls: Govern authenticated access during the user's Costpoint session.

Costpoint Access and Finance Workflows

SSO is particularly useful when users move between Costpoint and other enterprise applications during finance processes. A finance professional may review invoices, validate accounting information, approve transactions, examine project costs, and prepare reports across connected systems while using centrally managed identity controls.

For example, invoice processing can involve capture, extraction, validation, matching, GL coding, approval, and posting. Users performing these activities need appropriate application permissions after authentication, including access to the relevant chart of accounts and transaction functions.

SSO can also support month-end workflows by making identity management consistent across the applications used for reconciliations, journal entries, close tasks, and reporting deadlines. Consistent access administration can contribute to faster close when authorized finance users can reach the systems and workflows required for close activities.

Role-Based Access and Segregation

Single sign-on does not replace Costpoint's authorization structure. After authentication, users still require appropriate roles and permissions for their responsibilities. A person responsible for invoice review should not automatically receive the same access as a system administrator or a finance manager.

Organizations should map business responsibilities to Costpoint roles and periodically review whether those permissions remain appropriate. Changes in employment, department, project assignment, or finance responsibilities should trigger corresponding access updates through the organization's identity and application-management processes.

Financial approval workflows can also benefit from clear identity attribution. For example, an Accrual Sign Off can identify the authorized person responsible for approving an accrual-related workflow, while Tax Sign Off can establish accountability for tax-related review and authorization.

SSO and ERP Integration

Costpoint environments often interact with other enterprise applications, making identity consistency important across the technology landscape. When organizations connect Costpoint with a named ERP or extend finance workflows around an ERP, identity and access requirements should be considered alongside integration architecture.

This is particularly relevant for organizations using deltek Costpoint alongside other systems. A well-defined identity model can help administrators maintain consistent user lifecycle processes while preserving application-specific authorization rules.

Organizations supporting procurement across multiple entities and ERP systems can also use Multi Entity Support to provide a single view of tasks, documents, and approvals while maintaining appropriate access for users working across organizational boundaries.

Security and User Lifecycle Management

A strong SSO design connects authentication with the organization's user lifecycle. When employees join, change roles, transfer departments, or leave the organization, their identity records and application access should be updated through controlled processes.

Centralized authentication can also make security administration more consistent because identity policies can be managed through an established access-management framework. Administrators should document authentication requirements, role mappings, session policies, account provisioning, and access-review procedures.

Audit records should associate financial activities with authenticated users and their authorized roles. During finance reviews, this helps establish who performed or approved specific activities and supports accountability across transaction and reporting workflows.

Best Practices for Costpoint Single Sign-On

  • Define a clear identity source and establish how Costpoint users are authenticated.
  • Map Costpoint roles to documented job responsibilities and financial approval duties.
  • Integrate user provisioning and deprovisioning with established identity lifecycle processes.
  • Review privileged access separately from ordinary finance and operational roles.
  • Monitor authentication and application activity to support security reviews and audit requirements.
  • Coordinate SSO changes with Costpoint upgrades, ERP integrations, and connected finance applications.

Close governance should also distinguish authentication from financial approval. A Close Sign Off records authorization for a close-related activity, while SSO establishes the identity through which the authorized user accesses the application.

Summary

Costpoint Single Sign-On connects Costpoint authentication with centralized identity management, giving organizations a consistent way to authenticate users while preserving application-specific authorization. Its value depends on appropriate role design, user lifecycle controls, integration planning, and auditability. When these elements work together, finance teams can maintain controlled access across accounting, procurement, project costing, and reporting workflows.