SCIM directory sync
Connect Okta, Entra ID, or another IdP to InviziPoll with SCIM tokens, group-to-role mapping, and safe deprovisioning.
SCIM keeps InviziPoll membership aligned with your identity provider. Use it when IT already provisions users and groups in Okta, Microsoft Entra ID, or a similar IdP and you want hires and departures reflected without manual invites for every change.
Where it lives - Configure SCIM under Admin → SSO & Provisioning, on the Directory Sync (SCIM) and SCIM Role Mapping cards.
Who it’s for
IT and IdP owners running joiner/mover/leaver workflows, workspaces that need automated user lifecycle, and teams mapping IdP groups to InviziPoll roles.
Entitlement
SCIM is included with Business and Enterprise. On Pro, it is available as a SCIM add-on from Subscription when self-serve add-ons are offered. During a trial, owners may try the same surface via the Business features preview when that option appears. If you are not entitled, the page shows upgrade guidance instead of token controls.
Owner-only - Only the workspace owner can create SCIM tokens and edit group-to-role mappings.
Prerequisites
SCIM entitlement (Business/Enterprise or Pro with add-on), IdP admin access, the in-app SCIM base URL, and a plan for mapping IdP groups to admin vs member roles.
- Confirm entitlementOpen Subscription. Add the Pro SCIM add-on when offered, or upgrade to Business+. Return when Directory sync unlocks.
- Open SSO & ProvisioningGo to Admin → SSO & Provisioning → Directory Sync (SCIM).
- Generate a tokenCreate a named token, copy the secret immediately, and store it in the IdP or a password manager.
- Configure the IdPAdd a SCIM connection with the in-app base URL and bearer token. Enable the user and group operations your provider supports.
- Map groups to rolesOn SCIM Role Mapping, map IdP group IDs to InviziPoll roles.
- Test a pilot userProvision a test account, confirm they appear under Users, then deprovision and confirm deactivation.
Security behavior
Deprovisioning revokes sessions and deactivates accounts promptly. Treat SCIM tokens like passwords-rotate if leaked and revoke unused connectors.
Related docs
Enterprise SSO, SSO sign-in policy, Roles and permissions, and Billing.
FAQ
We are on Pro - can we use SCIM?
Yes with the SCIM add-on when offered on Subscription, or after upgrading to Business. If the UI only shows upgrade copy, enable the add-on when available or contact sales.
What if token create is disabled?
You are not entitled yet, or you are not signed in as owner. Check Subscription, then reopen SSO & Provisioning as the owner.
Does SCIM replace SSO?
No. SCIM provisions accounts; SSO authenticates them. Most enterprises run both. Vault unlock and recovery rules still apply after sign-in.
