Skip to main content
Admin & enterpriseIdP owners, IT admins

SCIM directory sync

Connect Okta, Entra ID, or another IdP to InviziPoll with SCIM tokens, group-to-role mapping, and safe deprovisioning. Gated by entitlement, not by plan name.

3 MIN READUPDATED SEP 10, 2026
On this page

SCIM keeps InviziPoll membership aligned with your identity provider. Use it when IT already provisions users and groups in Okta, Microsoft Entra ID, or a similar IdP and you want hires and departures reflected without manual invites for every change.

Who it’s for

IT and IdP owners running joiner/mover/leaver workflows, workspaces that need automated user lifecycle, and teams mapping IdP groups to InviziPoll roles.

Entitlement

The gate is your entitlement, not your plan name. SCIM is on when any one of these holds:

  • Your workspace is on Business or Enterprise.
  • Your workspace carries an active SCIM add-on, on any plan tier. The add-on is offered from Subscription when self-serve add-ons are available.
  • You're on a trial or an exempt workspace with the Business features preview switched on.

The add-on is what makes SCIM different from the rest of the compliance bundle: SSO, verified domains and SIEM come together at Business, and SCIM can be added below that on its own. If you're not entitled, the page shows upgrade guidance instead of token controls.

Prerequisites

SCIM entitlement (see above), IdP admin access, the in-app SCIM base URL, and a plan for mapping IdP groups to admin vs member roles.

  1. Confirm entitlementOpen Subscription. Add the SCIM add-on when offered, or upgrade to Business. Return when Directory sync is available.
  2. Open SSO & ProvisioningGo to AdminSSO & ProvisioningDirectory Sync (SCIM).
  3. Generate a tokenCreate a named token, copy the secret immediately, and store it in the IdP or a password manager.
  4. Configure the IdPAdd a SCIM connection with the in-app base URL and bearer token. Enable the user and group operations your provider supports.
  5. Map groups to rolesOn SCIM Role Mapping, map IdP group IDs to InviziPoll roles.
  6. Test a pilot userProvision a test account, confirm they appear under Users, then deprovision and confirm deactivation.

Security behavior

Deprovisioning revokes sessions and deactivates accounts promptly. Treat SCIM tokens like passwords-rotate if leaked and revoke unused connectors.

SCIM reads and deletes keep working after a plan lapses; only creates and updates are gated. If your plan ends you can still remove a departing employee. A billing problem must never become a security problem.

Enterprise SSO, SSO sign-in policy, Roles and permissions, and Billing.

FAQ

We are on Pro - can we use SCIM?

Yes, with the SCIM add-on when offered on Subscription, or after upgrading to Business. If the UI only shows upgrade copy, enable the add-on when available or contact sales.

Is SCIM Enterprise-only?

No. It's on Business and Enterprise, and on any tier with the add-on. The gate is the entitlement your workspace carries, not the tier's name.

What if token create is disabled?

You are not entitled yet, or you are not signed in as owner. Check Subscription, then reopen SSO & Provisioning as the owner.

Does SCIM replace SSO?

No. SCIM provisions accounts; SSO authenticates them. Most enterprises run both. Vault unlock and recovery rules still apply after sign-in.