Are you sure it is not something relating browser cookie configuration or a SSO misconfiguration in the CAS server or the CASified applications?
I would double check all the environment or get a colleague assess it in a peer review.
What you describe (SSO lost if I understand correctly) happens intermittently to some users of a CAS 3 service /me administer, which by the way its SSO can be de-configured at several levels, including even tables at the data base connected with a JpaTicketRegistry and supporting the service, for that particular 3.6 schema.
I still have not found a permanent solution, but almost always can be worked around in the final customer side clearing cookies or flip flopping 3rd party cookies allowance.
Regards,
Sent from my iPhone