SCIM
System for Cross-domain Identity Management
What it is
SCIM is a standard API that lets a customer's identity provider create, update and remove users in your product automatically. When IT adds someone to the right group in Okta or Entra ID, they appear in your app. When that person leaves the company, their access goes with them, and nobody has to file a ticket.
Removing access is a security control. Auditors check that departed employees lose access quickly, and doing it by hand doesn't pass.
What it takes
About 3–6 engineer-weeks to build in-house, or 1–2 using WorkOS, Stytch or Merge.
Answer these first
- Product: When someone is deprovisioned, do we suspend them or delete them?
- Product: Who owns content created by a user who has been removed?
- Engineering: How do directory groups map to roles in our product?
- Engineering: What happens when a sync replays or arrives out of order?
- Security: How fast must access be removed after someone is offboarded?
- Sales: Is SCIM a hard requirement in current deals, or a nice-to-have?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.