SSO as a selection criterion for startup ELNs is a join-and-leave control, not a padlock badge. Prefer an ELN that joins from the company directory and revokes on leave. Prefer a manual password only while no directory exists. Reject a shared lab login and reject “it has SSO, so it is secure enough.”
ELN quote scope still owns whether an identity add-on sits outside the seat price. External collaborator permissions still own sharing outside the company. ELN replacement after eLabJournal still owns export and review parity. This page only scores identity join and leave. Enterprise pages may list SSO as an IT line. That is a dimension, not this decision. Software alone does not complete 21 CFR Part 11. This page does not invent a Zetta SSO product feature.
SSO Is a Join-and-Leave Control Not a Security Badge
The search names an ELN with SSO for a biotech startup. The object to score is not a logo. It is whether a new hire becomes a named notebook user from the same directory that already owns email, and whether a departure removes that notebook user without a leftover password. If ops still opens a spreadsheet of app passwords after someone is off payroll, SSO was never implemented as a control. It was implemented as a login convenience.

Startups fail this test in a predictable way. The first five people share a notebook account because it is faster. The next ten each get a local password. A contractor leaves and the password remains. Six months later no one can say which records that person could still open. A padlock icon on a marketing page does not reconstruct that trail. Enterprise ELN language treats directory integration as the first IT requirement for a reason: join and leave have to propagate. A startup is smaller. The control is the same. The badge is not.
Four Labels That Change the Identity Score
Four labels decide whether identity is a real ELN criterion. They are not a vendor podium.
| Label | What to ask | Fail signal |
| Join from the company directory | Does hire in the IdP create a named notebook user without a second shared password? | Ops still mails a starter password from a personal inbox. |
| Leave revokes the notebook | Does offboarding remove notebook access the same day payroll ends? | A departed account can still open last week’s records. |
| Shared-password residue | Is there any login the whole lab still knows? | One “eln-team” password in a chat pin. |
| What SSO does not complete | Does anyone treat SSO as 21 CFR Part 11 or as IP insurance? | A slide that says “SSO = compliant.” |
Weight join when headcount is growing every month and account creation is already late. Weight leave when contractors and rotating students are common. Weight shared-password residue when the lab still has a communal login “just for instruments.” Weight “what SSO does not complete” when a vendor demo uses compliance language. Single sign-on can support an identity control. It does not write an audit procedure, does not retain records for a stated period by itself, and does not make the laboratory compliant.
Three Identity Postures Same Labels
The options are identity setups a startup already runs. Score all three on the same four labels.
| Dimension | Directory SSO | Per-app passwords | One shared account |
| Join from the company directory | Yes | Manual | No person |
| Leave revokes the notebook | Yes if the IdP is the source of truth | Manual and late | Cannot revoke one person |
| Shared-password residue | Should be gone | High if leftovers stay | The whole residue |
| What SSO does not complete | Not Part 11 | Not Part 11 | Not Part 11 and not attributable |
| When it fits | Startups that already have a company IdP | Tiny teams before an IdP exists | Never for IP-bearing work |
Prefer directory SSO when the company already joins people through one identity provider. Prefer per-app passwords only as a temporary posture, and write the leave checklist as someone’s job. Reject one shared account for any notebook that holds unpublished constructs, patient-linked notes, or partner data. A shared account cannot attribute a signature and cannot revoke a person. That is not a small-team shortcut. It is a missing control.
Ask the vendor a concrete leave question, not a logo question. If a person is disabled in the directory today, which notebook sessions die, and what remains in export? If the answer is a ticket to support, you are still on the manual posture. Quote scope is the place to ask whether SSO is inside the seat price. This page only asks whether the control exists.
Record After Join and Leave Are Named
Name join and leave before anyone treats a padlock as a criterion. After those sentences exist, an ELN is a place that can hold dated, attributable records. ZettaNote is one electronic lab notebook in that category. This page does not claim that ZettaNote ships a particular SSO connector. Official product language does not authorize a Part 11 completion claim. Use ZettaNote after identity criteria are scored, as a record surface for signed entries, not as a security badge and not as the selection subject.
If the startup still cannot say who is added on day one and who is removed on the last day, you do not have an SSO decision. You have a password pile. Write the join path. Write the leave path. Then pick the ELN that can follow those paths. A logo is not a path.
A worked leave test is more useful than a logo slide. A contractor finishes on Friday. The identity provider disables that account at 17:00. The notebook either ends that session and blocks a new login, or it still accepts a leftover local password. If the second thing happens, the control you bought is a sign-in convenience, not a leave control. Write that result in the evaluation note. Do not treat an SSO checkbox as the close. A second refusal: a five-person team sharing one mailbox login cannot later say who signed a deviation. That is not a later Part 11 problem only. It is an attribution gap on day one.
Frequently Asked Questions
Is an SSO logo enough to pick a startup ELN?
No. Score join from the directory and revoke on leave. A logo does not remove a leftover password.
Does turning on SSO finish 21 CFR Part 11?
No. Software features can support controls. Software alone does not make the lab compliant. Identity join and leave are one control among others.