If you've ever sat on a call between your training platform and your city's IT department, you know how it goes. IT asks about single sign-on. They ask how accounts get provisioned. They ask about MFA and how they'd pull data out. And the vendor says some version of "that's available on our enterprise plan, let me connect you with your account executive."
We just shipped four features aimed at that call: self-service SAML single sign-on, a public API, automated user provisioning over FTP, and organization-wide two-factor authentication. All of it is live now, and all of it is included for every Prodigy organization. No enterprise tier, no add-on pricing, nothing to unlock.
Here's what each one does.
Single sign-on you can set up yourself
Your EMS Clinicians already sign in to everything else through your identity provider, and now Prodigy can be one of those apps. We support any SAML 2.0 identity provider, and we wrote step-by-step setup guides for Google Workspace, Okta, and Microsoft Entra ID, plus a general guide for everything else, ADFS, PingOne, Auth0, you name it. The whole thing is a wizard under Settings, and most setups take about 15 minutes.
The part we're most proud of is what happens on first sign-in: nothing. No invitation emails, no roster uploads, no "I never got the link." The first time someone signs in through your identity provider, Prodigy creates their account automatically with the right name and puts them in the right department. Add someone to the app in Okta and they have a working Prodigy account the moment they click it.

A public API for your training data
Your training records shouldn't be trapped in your training platform. The new Prodigy public API gives you programmatic access to your users, classes, assignments, transcripts, and certificates. It also lets you create and update assignments, which means your scheduling software or records management system can drive training automatically instead of someone re-keying it every month.
A few things departments have already asked us about that this makes possible: pulling completion data into a compliance dashboard alongside the rest of your agency stats, syncing training records into your RMS, and auto-assigning remediation when your QA process flags a call.
Getting access takes about a minute. A Training Officer generates an access token under Settings, and every token is scoped to your organization only, your data and nothing else. Tokens can be named, and revoked instantly if one is ever compromised. Check the API documentation.

User provisioning over FTP
Not every agency runs an identity provider. Plenty run on an HR or scheduling system whose superpower is exporting a file on a schedule. FTP User Sync, in beta now, is for you: drop a user file on a secure FTP endpoint and Prodigy handles provisioning from there. If your system can schedule an export, you can stop managing Prodigy accounts by hand.
Require two-factor authentication for everyone
This one is a single toggle under Settings. Flip it on and every member of your organization has to set up an authenticator app before they can sign in. If your cyber insurance questionnaire asks whether MFA is enforced across your systems, this is now a yes for your training platform, and it took you four seconds.

The enterprise part, without the enterprise tier
Features like these usually live behind a pricing wall, and we get why, they're mostly requested by big organizations with formal IT departments. But we don't think a 12-person fire department deserves weaker security than a 3,000-person hospital system. So everything above ships to every Prodigy organization, included.
If you're already on Prodigy, all four features are waiting in the new Settings tab in Organization View, and the help docs walk through each setup. If something doesn't work the way you expect, email support@prodigyems.com, these features are new and we genuinely want the feedback.
And if you're not on Prodigy yet, and your IT team has been the reason, this update is for them. Book a demo and bring them along. We're happy to talk SAML assertions.

Post a Comment