This document discusses federated access management using SAML/Shibboleth single sign-on. It describes how federated access management allows users to securely access digital content and services from their home institution with a single credential. Federations like InCommon and OpenAthens allow institutions and publishers to connect once and then reuse the connection for multiple resources, lowering implementation costs. The document also notes some challenges with SAML/Shibboleth like age and network security, and suggests "user-managed access" as a potential next step beyond SAML.