The SSO Tax Is a Small Team Tax
- BY
- ROOT TEAM
- PUBLISHED
- SEPTEMBER 4, 2026
- READING TIME
- 6 MIN READ
The cheapest security control a product can ship is gated behind the enterprise plan at almost every SaaS company you depend on. You pay the difference in shared passwords and skipped steps. Here is what that costs, and what fair pricing for safety looks like.
A founder we know runs six people on four tools. When the team crossed five seats, the admin console lit up with a button for single sign on. Clicking it opened a pricing page. The plan that included it cost more per month than they paid for all four tools together. So they closed the tab, set up a shared password vault, and got back to work. Ten tools later, the pattern was impossible to miss. An entire class of security is only for sale to companies that already employ a security team.
We call it the small team tax. It never appears on an invoice. It appears as the way a growing company actually handles identity. One shared credential per tool, held together by trust and a browser extension, waiting for the week somebody borrows it and the month somebody forgets to rotate it. The tax is not the price you skip. It is the debt you carry instead.
What single sign on really is
Single sign on is not a premium feature. It is identity hygiene. A person leaves and their access dies. A device goes missing and one account gets reset. An audit asks who touched what and there is an answer. None of this is remarkable for a company with a security team. It is the floor. It matters exactly as much for a team of five, and the pricing page says otherwise.
The strange part is that the technology costs almost nothing to provide. Once a product speaks an identity protocol, the marginal cost of letting a small customer turn it on is a rounding error. The gate is not engineering. The gate is billing. The same button that costs an enterprise buyer nothing meaningful to flip is treated as a luxury because a small team wanted it.
How the tax actually gets paid
The behaviors show up fast, and they all look like team failure. They are not.
- The shared password. The most efficient thing a small team can do, and the most dangerous. One borrowed credential opens the whole product.
- The skipped rotation. Passwords change twice a year, on renewal day, when somebody remembers.
- The admin sandwich. One person holds every key because distribution never got solved.
- The personal phone. MFA lands on private devices because the work account does not enforce anything.
Give the same five people single sign on and every one of these behaviors disappears without a policy change. Take it away and no workshop brings them back. The behavior was never the problem. The plan boundary was.
Why the gate became the business
Look at any enterprise tier and you find the same trick. The features that genuinely cost money are hard to package into a marketing slide. But security basics are easy to point at. "This is what you get when you pay." So the cheapest and most important controls in the product became the mascot of the most expensive plan. Safety got strapped to buying power because selling safety is easier than selling scale.
The root cause is not greed, and calling it greed does not help anybody. The root cause is that pricing pages are built around what the largest buyers will pay, not around what a feature costs to ship. Big companies have procurement lines and a different budget. Small ones buy with a credit card and flinch. So the plan shapes itself around the wallet that can afford it, and the controls a small team needs most become the line between them and the wallet they do not have.
What fair pricing looks like
The honest version of a pricing page puts safety in the base tier and stops selling it back. You do not sell a customer the ability to not be hacked. You sell them volume, speed, and support. The split is embarrassingly simple.
Base tier, included for everyone:
- Single sign on with the provider they already use
- Enforced MFA as the default, not the negotiation
- Encryption everywhere the data rests
- Audit basics that show recent activity
- A seat price a small team can afford to pay
Scale tier, paid because it scales:
- More seats and volume pricing
- Compliance exports and archives
- Support with a human and an uptime commitment
Notice what moved. The expensive tier no longer contains safety. It contains the things that genuinely cost more when you get bigger. That is the whole argument, and it fits on one card.
What we do about it
We build the products we actually want to use, so the baseline is not negotiable. Every ROOT product ships the identity and privacy basics in the first tier. If a team of two cannot turn on the protections that keep them honest, the product has failed them before they ever pay us. We start from privacy as the default, because that is the product we would want to depend on.
The test that never lies
Find the cheapest tier of whatever tool you are about to adopt. If the safety basics live on the far side of a plan boundary, your identity is a line item. That may be acceptable. Just do not pretend it is neutral. Tools that treat safety as the default get our money, and after enough invoices, our respect.
Try it
Make the list. Every product you depend on, and what its cheapest tier actually includes. Then count the shared passwords you manage by hand. That number is your tax. The moment you feel it, you understand why we keep talking about the difference between treating a symptom and fixing the cause. The pricing page is just the symptom. The cause is a pricing model that bills safety back to the people who need it most.
Finding the cause is our daily work.
Related reading: Your Pricing Page Is a Symptom and Root Cause Thinking.