SCIM Provisioning

SCIM Provisioning — Sync Users, Roles, and Teams From Your Directory

Provision accounts, map roles, and assign Teams automatically from your identity provider—eliminating manual user administration, closing offboarding gaps, and keeping access aligned with your directory.

What Is SCIM Provisioning?

SCIM Provisioning is SmartSuite's implementation of the System for Cross-domain Identity Management standard, automatically synchronizing user accounts, Team assignments, and roles between an organization's identity provider and the workspace. It helps IT teams onboard, update, and deprovision Members without manual administration—access mirrors the corporate directory at all times. SCIM Provisioning is available on the Enterprise plan and pairs with Single Sign-On (SSO).

Identity Sync

Provision and Deprovision Members Automatically

Connect Okta, Microsoft Entra (Azure AD), or Ping Federate and SmartSuite accounts follow your directory: new employees get provisioned from the IdP, and users who leave the organization are disabled or removed the moment they are offboarded upstream.

No stale accounts, no forgotten seats, no manual deactivation checklist—the directory is the single source of truth for who has access.

Roles & Teams

Map Roles and Assign Teams From Directory Attributes

SCIM Provisioning carries structure, not just accounts. Directory attributes assign each user to the right SmartSuite Teams, and a roles attribute in the SCIM payload maps users to the admin, solution manager, or general role—defaulting to general when no role is sent.

Each user carries one SmartSuite role per workspace, so role assignment stays deliberate and reviewable rather than accumulating over time.

Setup & Oversight

Set Up SCIM With a Token—and Monitor Every Change

Setup is a standards-based configuration, not a custom integration project: generate a Provisioning Authorization Token in Workspace Administration, map SCIM attributes to SmartSuite fields, and point your IdP at the SmartSuite SCIM endpoint.

Built-in audit logging and monitoring records provisioning activity, so administrators can verify exactly which accounts were created, changed, or removed—and when.

Platform Context
How GRC Teams Use

SCIM Provisioning

Manual user administration is where access control quietly breaks down--accounts outlive employment and permissions drift from org charts. SCIM Provisioning keeps SmartSuite access mirrored to the directory your organization already governs.

Offboarding Without Orphaned Access

The moment an employee is deactivated in Okta, their SmartSuite account is deprovisioned—no waiting period, no orphaned access to registers and evidence, and no leaver finding at the next access review.

Joiners Mapped to Governed Access

New hires land in the right SmartSuite Teams based on their department attribute in Microsoft Entra, inheriting exactly the access your governance model assigns—nothing granted ad hoc.

Access Reviews Without Spreadsheets

Because SmartSuite membership, roles, and Teams mirror the directory, quarterly user-access reviews reference one authoritative system—and SCIM's provisioning log evidences every change.

Governed Role Assignment

Map an IT security group to the admin role via the SCIM roles attribute so privileged access is granted through directory group membership—controlled, approved, and reversible in one place.

Complete Identity Lifecycle With SSO

Pair SCIM Provisioning with Single Sign-On (SSO): the same identity provider that authenticates each login also creates, updates, and removes the account behind it.

Works Better Together
Related Features

Manual user administration is where access control quietly breaks down--accounts outlive employment and permissions drift from org charts. SCIM Provisioning keeps SmartSuite access mirrored to the directory your organization already governs.

Features FAQ’s
Frequently Asked Questions About
SCIM Provisioning
What is SCIM Provisioning in SmartSuite?

SCIM Provisioning automatically synchronizes user accounts, Team assignments, and roles between your identity provider and SmartSuite using the SCIM standard. IT no longer adds or removes SmartSuite users by hand—the directory drives access.

Which identity providers does SmartSuite SCIM support?

SmartSuite documents SCIM configuration for Okta, Microsoft Entra (Azure AD), and Ping Federate. Setup uses a Provisioning Authorization Token generated in Workspace Administration and SmartSuite's standard SCIM endpoint.

What does SCIM Provisioning automate?

Four things: creating user accounts from the IdP, disabling or removing users who leave the organization, assigning users to SmartSuite Teams based on directory attributes, and mapping SmartSuite roles. Provisioning activity is logged for administrator review.

How does SCIM role mapping work?

The SCIM payload's roles attribute accepts one of three values—admin, solution_manager, or general. Users provisioned without a role default to general. One role applies per user, and role assignment is per-workspace.

Does SCIM work across multiple workspaces?

No. SCIM Provisioning is configured per workspace, and cross-workspace role assignment is not supported. Each workspace maintains its own provisioning connection and token.

What plan includes SCIM Provisioning?

SCIM User Provisioning and SCIM-Synced User Groups are Enterprise plan features, per the SmartSuite pricing page.

How does SCIM Provisioning support audit readiness?

Automated deprovisioning closes the offboarding gaps auditors look for first, and directory-driven roles and Teams make user-access reviews verifiable against one source. SCIM's own audit logging documents every provisioning event.

Retire Manual User Administration

Connect your identity provider once—and let joiners, movers, and leavers flow through SmartSuite automatically.