Access Delegation (Delegated SSO): give external organizations access

Access Delegation (Delegated SSO): give external organizations access


Access Delegation allows your organisation to give external organisations — consultancies, auditors or subsidiaries, for example — access to your ContractHero account without creating their users as separate accounts in your own organisation. The external organisation signs in with its own corporate credentials, and ContractHero accepts that identity via single sign-on.


Your benefit


Anyone who works regularly with external stakeholders — the group internal audit function of a parent company, an external legal department or an audit firm, for example — knows the problem: creating temporary accounts, remembering to offboard them, rotating passwords, managing shadow identities. Access Delegation does away with all of that:


  • No shadow users in your organisation — external staff log in with their own IdP credentials.
  • Offboarding happens automatically — as soon as someone leaves the external organisation, they immediately lose their ContractHero access.
  • Clean separation — you can see clearly that the access is coming from an external organisation.
  • Compliance-friendly — external access can be controlled and audited through the external organisation's own identity management.


Requirements


  • Enterprise plan on your side (the delegating organisation).
  • Custom SSO via OpenID Connect (Microsoft Entra ID, Azure AD or Okta) must be set up in your organisation.
  • The external organisation you want to give access to should also have a compatible identity platform — we discuss the exact configuration with you individually.
  • Owner [Eigentümer] status in your ContractHero organisation.


How it works


Access Delegation is an operational feature that we set up together with you. The self-service configuration area is deliberately kept minimal, because a configuration spanning two IdPs requires careful coordination.


1. Submit a request


Get in touch via the ContractHero web chat or by email to support@contracthero.com. Please have the following information to hand:


  • Which external organisation should be given access? (name, domain, industry)
  • Which identity platform does that external organisation use? (Microsoft Entra ID, Okta, …)
  • What scope should the access have? (read-only, editing, the whole organisation or only certain teams/categories)
  • Who is the technical contact on each side?


2. Preparation by ContractHero


Our integration team coordinates with the IT administrators of both organisations and configures the trust relationship between the IdPs and ContractHero.


3. Setup call


In a call that typically lasts 20–30 minutes with the technical contacts of both organisations, we finalise the configuration — much like a normal Custom SSO setup, only with two IdPs involved.


4. Test with a pilot user


We test the delegation with a single person from the external organisation. As soon as the login works and the access rights apply correctly, the delegation goes live.


5. Roles and permissions as usual


Within your ContractHero organisation, the external users are given roles just like internal members — via the Standard or APC permission concept. This means you can control precisely which contract categories, teams or statuses the external users can see and edit.


Typical use cases


  • Group internal audit at the parent company views the subsidiary's contract data without a separate account.
  • An external legal department reviews NDAs and employment contracts — with their own logins, no shadow users.
  • Auditors during an audit — access until the cut-off date, then withdrawn automatically.
  • A holding structure with separate ContractHero accounts per subsidiary, but central group-wide access for the holding company's IT.
  • Joint venture partners with their own IT governance.


Frequently asked questions


Which plan includes Access Delegation?
Enterprise. Talk to us for an individual quote.


Do I need Custom SSO?
Yes, on your side. The delegating organisation must have Custom SSO set up. Ideally the external organisation does too — otherwise we have to review the login mechanism on a case-by-case basis.


Which identity platforms are supported?
Currently Microsoft Entra ID (formerly Azure AD), Azure AD and Okta via OpenID Connect. We review other IdPs on request.


Who manages the external users?
The external organisation manages its users in its own IdP. ContractHero follows that status — whoever loses access there also loses it in ContractHero.


Can external users see everything?
No. You assign roles to external users just as you do to internal ones — via Standard or APC permissions. That is how you control precisely which categories, teams or contract statuses are visible and editable.


How does Access Delegation differ from a simple user invitation?
With a normal invitation you create a ContractHero account for the external person — they log in with their own credentials, which you have to maintain. With Access Delegation there is no separate account — the external person logs in with the credentials of their own organisation, and ContractHero accepts that identity.


What happens if the external organisation no longer needs access?
Access is deactivated jointly. The external users lose access immediately. Your audit logs still show which actions took place during the delegation period.


How secure is Access Delegation?
The level of security depends on the external organisation's identity provider. We recommend that the external organisation has at least MFA enabled on its side. We discuss the minimum requirements in the setup call.


Do I need a separate setup call for every external organisation?
Yes. Each delegation is configured, tested and enabled individually.


Can external users change or delete contracts?
If you give them the corresponding roles, yes. You control this just as you do for internal users.


Good to know


  • Clear audit logs. All actions by external users appear in the change log [Änderungsprotokoll] just like those of your own staff — including identity, timestamp and the contract concerned. Auditable down to the last detail.
  • Plan for time-limited delegations. For audits or projects, the external organisation can have its IdP automatically deactivate individual users' access on a set date. That saves you follow-up tickets.
  • Grant external roles restrictively. Give external users only the permissions they genuinely need — read-only is often enough. APC with category or status conditions is particularly useful here.
  • MFA on both sides. Even if the external organisation requires MFA for its own IdP, enforcing MFA in your administration interface is a sensible additional layer of security.
  • Plan the migration in advance. If you currently manage external users via classic invitations and are switching to Access Delegation, plan a short transition phase — otherwise the external people will briefly lose access.
  • We support you with the setup. Access Delegation is one of the more complex features on our platform. Setting it up together with our team saves hours of trial and error later on.


Contact


If you have questions, or to request a delegation, you can reach us via the ContractHero web chat, by email to support@contracthero.com or by phone on 030 / 577 123 32.



  • How do I set up Custom Single Sign-On (SSO)?
  • SSO, SAML, OpenID Connect & SCIM — what is the difference?
  • Permission concepts compared: Standard and APC (incl. Dynamic)
  • Number of companies: representing multiple entities in one organisation
  • What information does the change log give me?

Updated on: 08/26/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!