Backend work
Back to gallery

SSO and service catalog for contractors

My scope combined technical consulting and development of the first custom contractor account on Symfony/Vue.js: SSO path, service catalog, contractor onboarding flow, and integration with the existing identity setup.

Abstract 3D illustration of a single user profile connected to corporate services.
Role
Developer and technical consultant
Context
Employee and contractor access to services
Timeline
2 months for SSO MVP; 3 weeks for catalog
Stack
Keycloak, Active Directory, PHP/Symfony, Vue.js
The team launched an SSO MVP: Keycloak as Identity Provider, Active Directory as the identity source, SSO for the first corporate service, and the first custom contractor account on PHP/Symfony and Vue.js.
03

Business task

Employees and contractors had a fragmented path to services: separate links, passwords, instructions, and manual access steps. Support time was spent on navigation and passwords instead of the actual services.

04

MVP boundary

The first release did not try to cover every access scenario. It needed one entry point, integration with the existing identity infrastructure, and an extensible contractor path that could grow after the first services were connected.

05

Architecture choice

Keycloak was used as the Identity Provider, while Active Directory remained the identity source for the first stage. This avoided a custom authorization layer and kept the existing user base intact.

06

Service catalog

The catalog solved a practical user problem: where to find the right service, which access rules apply, and what to do next. It was released in 3 weeks while the SSO work was being finalized.

07

Contractor account

A boxed platform was too heavy for the first scope. The contractor account was built with PHP/Symfony and Vue.js to validate the real onboarding scenario faster and avoid unnecessary platform overhead.

08

Launch

In 2 months, the team set up the development infrastructure, agreed the SSO structure, configured Keycloak, connected Active Directory identification, and enabled SSO for the first corporate service.

09

Operational effect

After launch, the contractor path became easier to explain, link and password questions had one entry point, and the service catalog removed part of the navigation burden for employees and support.

Working through something similar?

Discuss a similar task