Hi @Thomas Plant ! Welcome to the Amplitude community and I’m happy to help!
It is the case that we do have an option to “Require SSO”. If this option is enabled then doing so will prevent users from signing in with their email and password - see documentation here.
The “Require SSO” option is org-wide and at the moment, there isn’t a functionality that will allow you to exempt any accounts for breakglass purposes. That said, I think this is great feedback to the Product team and I welcome you to share that feedback in the Product Feedback section! https://community.amplitude.com/ideas
And yes, all levels of access can use SSO if you implement it.