SCIM Provisioning
SCIM provisions and deprovisions members automatically from your identity provider onboarding and offboarding, hands-free.
What SCIM gives you
Automatic onboarding
New members in your IdP are provisioned into Theneo with the right access, with no manual invites.
Instant offboarding
Deactivate someone in your IdP and their Theneo access is revoked automatically, a critical security control.
Group & role sync
Map IdP groups to Theneo teams and roles, so permissions stay consistent.
Less admin overhead
Your IdP stays the single source of truth, with no drift between systems.
Set up SCIM
1
Enable SCIM in Theneo
As a Workspace Admin, open Settings → Workspace and enable SCIM provisioning. Theneo issues a SCIM base URL and a secret token.
2
Configure your IdP
In your identity provider (Okta, Entra ID, and others), add Theneo's SCIM URL and token to the provisioning settings.
3
Map attributes and groups
Map user attributes and the groups that should sync to Theneo teams and roles.
4
Turn on sync
Enable provisioning. Members and groups now sync automatically as they change in your IdP.
Best paired with SSO + Teams. Use SSO for sign-in and Teams for group-based access SCIM keeps both in sync with your directory.
On this page
- SCIM Provisioning