When a session expires
Tools log you out eventually. When that happens the tool is flagged, its runs wait, and you get an email. Log in again and they continue.
How it works
There is nothing to install in your tools and nothing to ask their sales teams for. SmashSSO uses the admin access you already have.
1
Google is your list of people. The moment you sign in, we read your directory and everyone shows up: name, email, title, and whether they are active or suspended.
Needs a Google Workspace admin account. We ask for read-only access to the user directory and nothing else.
2
Choose from the catalog or add your own. If you run two accounts of the same product, say a main GitHub organization and a demo one, add it twice.
Things with no member management, like a shared API key, can be tracked by hand so the picture is complete.
3
We open a real browser on our side and stream it to you. You log in with your own admin account, or with a dedicated one you created for SmashSSO, 2FA included. When you are in, you press Save.
We never see or store your password. We keep the session the tool gave you, encrypted. Tools with a member API take a token instead.
4
For each tool, a read-only pass collects its roles and its members, then matches members to your people by email. The access grid fills in tool by tool.
Accounts that match nobody, such as contractors and personal emails, are added and flagged for you to review.
5
Grant access, change a role, remove someone. Each change becomes a run: an API call where there is one, an agent in a browser where there is not.
Runs that would add a paid seat stop and wait for your approval. Every run keeps a step log and a final screenshot.
Two ways to act
Some tools let any paying customer manage members by API. For those we call the API: fast, exact, and nothing to watch. You give us a token with member permissions.
Most tools either have no member API or reserve it for Enterprise. For those, an AI agent opens the admin page in an isolated browser, signed in with the saved session, and works the screen: find the member list, press Invite, type the email, choose the role, confirm. It takes a minute or two.
A few things cannot be automated. You can still record who has them, so offboarding tells you what is left to do.
Tools log you out eventually. When that happens the tool is flagged, its runs wait, and you get an email. Log in again and they continue.
Screens change and agents sometimes fail. A failed run says so, shows you its last screenshot, and never pretends. You can retry or do that one by hand.
If an invite would add a paid seat or touch billing, the run pauses. Nothing is bought until you approve it.
Sign in with Google Workspace, connect your tools, and see who has access to what in minutes.