SCIM Provisioning
SCIM lets your identity provider manage organization membership directly. When you add, remove, or change someone's role in your identity provider, it's reflected in Observatory automatically, with no manual invites.
SCIM is configured per SSO connection, so set up your connection first.
- 1Open the connection's Provisioning tabOrganization settings → SSO → your connection → Provisioning.
- 2Turn on SCIMAnd set the user ID attribute your provider will send (usually email).
- 3Generate a bearer tokenCopy it now. It's shown once and is what your provider uses to authenticate.
- 4Finish setup in your identity providerPaste the SCIM endpoint URL and bearer token into your provider's SCIM app configuration.
From this point on, membership changes made in your identity provider take effect in Observatory within the usual sync interval your provider uses.