SCIM (User provisioning)
SCIM is a standard that lets a customer's identity system automatically create, update and remove user accounts in your product.
SCIM stands for System for Cross-domain Identity Management. It is the standard way for a company's identity provider (Okta, Microsoft Entra, OneLogin) to push user changes into the apps the company uses. Hire someone and they appear in your product with the right group. Fire someone and their access disappears the same day, with no ticket to IT.
RFC 7644, the protocol specification, describes SCIM as an HTTP-based protocol that makes managing identities in multi-domain scenarios easier through a standardized service.
How it works
You expose a set of endpoints that follow the spec. The core ones are /Users and /Groups. The identity provider calls them with normal HTTP methods: POST to create a user, PATCH to change one, DELETE to remove, GET to read. Data travels as JSON. The customer's admin pastes your SCIM URL and a token into their identity provider and switches it on.
SSO vs SCIM
SSO answers "how does this person log in?" SCIM answers "does this person's account exist, and what is it?" With SSO alone, an ex-employee's account stays in your product until someone removes it by hand, even though they can no longer log in. SCIM is what closes that gap, which is why security teams treat deprovisioning as the main reason to ask for it.
Why customers ask for it
- Offboarding without manual work in every app.
- Seat counts that match their directory, which also keeps per-seat billing honest on both sides.
- Group-to-role mapping, so membership in a directory group sets the role inside your app.
- Audit and compliance evidence, for example when they hold a SOC 2 report of their own.
What it costs
SCIM is simpler than SAML on the wire but fiddly in practice. Identity providers interpret the spec slightly differently, so you test against each. Decide what "delete" means (deactivate, or erase data), how to handle a user who already exists, and how to avoid orphaned content. Budget a few weeks of engineering, or buy it through a vendor that bundles directory sync with SSO.
When a small SaaS should care
Later than SSO. Customers usually ask for SCIM once they have 100 or more users on your product and an IT team that audits access. If you sell mostly to teams of 5 to 30, a manual remove button and an audit log are enough. When you do add it, keep it in the same plan as SSO so the enterprise tier stays coherent.
Related terms
Sources
- RFC 7644: System for Cross-domain Identity Management: Protocol, IETF
- Single sign-on, EnterpriseReady
- Role-based access control, EnterpriseReady