> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.contracthero.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Access Delegation (Delegated SSO): give external organizations access

# Access Delegation (Delegated SSO): give external organizations access

**Access Delegation** allows your organisation to give external organisations — consultancies, auditors or subsidiaries, for example — access to your ContractHero account **without creating their users as separate accounts in your own organisation**. The external organisation signs in with its own corporate credentials, and ContractHero accepts that identity via single sign-on.

## Your benefit

Anyone who works regularly with external stakeholders — the group internal audit function of a parent company, an external legal department or an audit firm, for example — knows the problem: creating temporary accounts, remembering to offboard them, rotating passwords, managing shadow identities. Access Delegation does away with all of that:

* **No shadow users in your organisation** — external staff log in with their own IdP credentials.
* **Offboarding happens automatically** — as soon as someone leaves the external organisation, they immediately lose their ContractHero access.
* **Clean separation** — you can see clearly that the access is coming from an external organisation.
* **Compliance-friendly** — external access can be controlled and audited through the external organisation's own identity management.

## Requirements

* **Enterprise plan** on your side (the delegating organisation).
* **Custom SSO** via OpenID Connect (Microsoft Entra ID, Azure AD or Okta) must be set up in your organisation.
* The external organisation you want to give access to should also have a compatible identity platform — we discuss the exact configuration with you individually.
* **Owner [Eigentümer] status** in your ContractHero organisation.

## How it works

Access Delegation is an **operational feature** that we set up together with you. The self-service configuration area is deliberately kept minimal, because a configuration spanning two IdPs requires careful coordination.

**1. Submit a request**

Get in touch via the ContractHero web chat or by email to support@contracthero.com. Please have the following information to hand:

* Which **external organisation** should be given access? (name, domain, industry)
* Which **identity platform** does that external organisation use? (Microsoft Entra ID, Okta, …)
* What **scope** should the access have? (read-only, editing, the whole organisation or only certain teams/categories)
* Who is the **technical contact** on each side?

**2. Preparation by ContractHero**

Our integration team coordinates with the IT administrators of both organisations and configures the trust relationship between the IdPs and ContractHero.

**3. Setup call**

In a call that typically lasts 20–30 minutes with the technical contacts of both organisations, we finalise the configuration — much like a normal Custom SSO setup, only with two IdPs involved.

**4. Test with a pilot user**

We test the delegation with a single person from the external organisation. As soon as the login works and the access rights apply correctly, the delegation goes live.

**5. Roles and permissions as usual**

Within your ContractHero organisation, the external users are given **roles just like internal members** — via the Standard or APC permission concept. This means you can control precisely which contract categories, teams or statuses the external users can see and edit.

## Typical use cases

* **Group internal audit at the parent company** views the subsidiary's contract data without a separate account.
* **An external legal department** reviews NDAs and employment contracts — with their own logins, no shadow users.
* **Auditors** during an audit — access until the cut-off date, then withdrawn automatically.
* **A holding structure** with separate ContractHero accounts per subsidiary, but central group-wide access for the holding company's IT.
* **Joint venture partners** with their own IT governance.

## Frequently asked questions

**Which plan includes Access Delegation?**
**Enterprise.** Talk to us for an individual quote.

**Do I need Custom SSO?**
Yes, on your side. The delegating organisation must have Custom SSO set up. Ideally the external organisation does too — otherwise we have to review the login mechanism on a case-by-case basis.

**Which identity platforms are supported?**
Currently **Microsoft Entra ID** (formerly Azure AD), **Azure AD** and **Okta** via OpenID Connect. We review other IdPs on request.

**Who manages the external users?**
The **external organisation** manages its users in its own IdP. ContractHero follows that status — whoever loses access there also loses it in ContractHero.

**Can external users see everything?**
No. You assign roles to external users just as you do to internal ones — via Standard or APC permissions. That is how you control precisely which categories, teams or contract statuses are visible and editable.

**How does Access Delegation differ from a simple user invitation?**
With a normal invitation you create a ContractHero account for the external person — they log in with their own credentials, which you have to maintain. With Access Delegation **there is no separate account** — the external person logs in with the credentials of their own organisation, and ContractHero accepts that identity.

**What happens if the external organisation no longer needs access?**
Access is deactivated jointly. The external users lose access immediately. Your audit logs still show which actions took place during the delegation period.

**How secure is Access Delegation?**
The level of security depends on the external organisation's identity provider. We recommend that the external organisation has at least **MFA** enabled on its side. We discuss the minimum requirements in the setup call.

**Do I need a separate setup call for every external organisation?**
Yes. Each delegation is configured, tested and enabled individually.

**Can external users change or delete contracts?**
If you give them the corresponding roles, yes. You control this just as you do for internal users.

## Good to know

* **Clear audit logs.** All actions by external users appear in the change log [Änderungsprotokoll] just like those of your own staff — including identity, timestamp and the contract concerned. Auditable down to the last detail.
* **Plan for time-limited delegations.** For audits or projects, the external organisation can have its IdP automatically deactivate individual users' access on a set date. That saves you follow-up tickets.
* **Grant external roles restrictively.** Give external users only the permissions they genuinely need — read-only is often enough. APC with category or status conditions is particularly useful here.
* **MFA on both sides.** Even if the external organisation requires MFA for its own IdP, enforcing MFA in your administration interface is a sensible additional layer of security.
* **Plan the migration in advance.** If you currently manage external users via classic invitations and are switching to Access Delegation, plan a short transition phase — otherwise the external people will briefly lose access.
* **We support you with the setup.** Access Delegation is one of the more complex features on our platform. Setting it up together with our team saves hours of trial and error later on.

## Contact

If you have questions, or to request a delegation, you can reach us via the ContractHero web chat, by email to support@contracthero.com or by phone on **030 / 577 123 32**.

## Related articles

* How do I set up Custom Single Sign-On (SSO)?
* SSO, SAML, OpenID Connect & SCIM — what is the difference?
* Permission concepts compared: Standard and APC (incl. Dynamic)
* Number of companies: representing multiple entities in one organisation
* What information does the change log give me?