Enterprise SSO begins with a clear tenant and identity model. Decide whether one person can belong to several organizations and how existing password accounts link to an enterprise identity.
Authentication does not replace authorization. Roles, scopes, policy ownership, and audit records still need an explicit design.
Operational flows matter as much as the happy path: certificate rotation, domain changes, locked administrators, and emergency access all need owners.