Skip to content
English
  • There are no suggestions because the search field is empty.

Set up automatic user provisioning with SCIM

Synchronise directory users and groups with Simana using SCIM 2.0 and configure optional access rules.

SCIM 2.0 provisioning sends directory user and group changes to Simana. Configure it when you want to manage users through your directory. SAML handles sign-in; SCIM handles provisioning.

For SAML configuration, see Set up single sign-on (SSO) with SAML.

Before you begin

  • You need administrator access to your organisation in Simana and permission to configure automatic provisioning and assign users in your identity provider.
  • Your directory must support SCIM 2.0.
  • Use the provider’s SCIM provisioning section in Simana and the corresponding application in your identity provider. Follow the SSO setup article to add the SAML identity provider and configure sign-in.
  • Keep the organisation’s Identity providers switch enabled. Turning it off stops SAML sign-in and SCIM provisioning while retaining settings, tokens and templates.

This guide uses generic identity-provider terminology. Menu names vary between providers; look for the equivalent application and provisioning settings.

Important: creating a provisioning token changes login eligibility for the organisation. Once provisioning is configured, users need an active SCIM mapping to sign in through SAML, including users who already have Simana accounts. Revoking or allowing tokens to expire does not remove that requirement. Plan and provision the pilot users before rolling provisioning out.

1. Connect SCIM provisioning

  1. Open the provider’s SCIM provisioning section in Simana.
  2. Copy Tenant URL exactly as displayed. This is the SCIM base endpoint generated by Simana.
  3. Select Create provisioning token.
  4. Copy the one-time secret directly into your identity provider’s provisioning credentials. If you need to retain it, use your approved secret store. Closing the dialog discards the displayed secret.
  5. In the identity provider’s application, open automatic provisioning and select SCIM 2.0.
  6. Paste the Tenant URL into the directory’s Tenant URL, SCIM base URL or provisioning endpoint field. Paste the secret into its Secret token, API token or bearer-token setting. The token comes from Simana, not the identity provider.
  7. Configure the user and optional group mappings described below.
  8. Limit the initial provisioning scope to the pilot users and groups.
  9. Run the directory’s connection test if available, then start provisioning or trigger a provision-on-demand operation.
  10. Confirm provisioning succeeds and the pilot user can complete the SAML sign-in test in the SSO setup article.

User mappings

SCIM field Directory value to send
userName The user’s email address. Use the same email as their Simana account and their SAML email claim.
externalId A stable directory user identifier. Simana requires externalId for reliable user lifecycle updates.
active The user’s enabled status.

Group mappings, if synchronising groups

SCIM field Directory value to send
externalId A stable directory group identifier.
displayName The group’s name.
members The group’s members.

Simana requires both the identifier and name for group creation. SCIM defines externalId as an identifier supplied by the provisioning client; map it to a durable directory identifier. See the SCIM core schema.

2. Configure optional provisioning access rules

Invite templates specify the memberships and follows to grant. Provisioning rules select which provisioned users receive a template.

  1. In the organisation’s Identity providers panel, select Create invite template.
  2. Open its configuration and choose the memberships and follows the intended users should receive. Give it a recognisable name.
  3. Open the provider’s configuration and select Add provisioning rule.
  4. Select the invite template and enable the rule.
  5. Choose Apply to every provisioned user, or add conditions for a narrower group.
  6. For a group condition, open that group in the directory, obtain its stable identifier and confirm the provisioning mapping sends it as the group’s externalId. Enter Attribute groups, Match Equals, and that identifier as Value.
  7. Select Publish to save the rule.
  8. Trigger the next directory update for the pilot user or group. Confirm the intended memberships and follows appear in Simana.
  9. Test a user outside the matching group to confirm the rule does not grant them access.

Provisioning rule fields

Field What to enter or choose
Rule enabled Turn on to use the rule. Disabling it revokes access granted by that rule.
Invite template Select an organisation invite template created in Simana.
Apply to every provisioned user Enable to apply the template to every active user provisioned through this provider without conditions.
Attribute The provisioned metadata key to match. For synchronised group membership, use groups. This is separate from the SAML Group attribute field.
Match Equals matches a complete value; Contains matches a substring. Comparisons are case-insensitive. Prefer Equals with a stable group identifier.
Value The directory value to match. For a group rule, use the stable external identifier sent as SCIM Group externalId.
Publish Saves the rule. All conditions must match unless Apply to every provisioned user is enabled.

Simana’s group matching includes synchronised group identifiers and names. Prefer identifiers because names can change. Creating or editing a rule takes effect on the next directory update; disabling or removing a rule immediately revokes access attributable to it.

The SAML Group attribute field is separate from SCIM group synchronisation and provisioning rules. It does not grant memberships by itself. See the attribute configuration in Set up single sign-on (SSO) with SAML.

3. Test before wider rollout

Before wider rollout, verify sign-in, intended access, group removal and user deactivation with pilot accounts.

To test sign-in, first provision the pilot user through SCIM and confirm they are active. Open a separate browser session, go to the normal Simana login page, enter their email and select Continue. Complete authentication in the identity provider, confirm the user returns to Simana signed in, then reload and verify the session remains active. See the SSO setup article for the full SAML configuration and sign-in troubleshooting.

Directory deactivation blocks that organisation’s SAML login and revokes its attributed SSO sessions. It retains the Simana account, content and audit history.

Manage provisioning tokens

Field or control Meaning
Tenant URL The generated SCIM base endpoint. Copy it exactly into the directory’s provisioning endpoint field.
Create provisioning token Creates a credential for this provider’s provisioning connection.
Provisioning token The secret shown once when created or rotated. Copy it into the directory’s token or bearer-credential setting.
Token name An editable label to help administrators recognise the credential. Renaming does not change the secret.
Status Shows whether the token is active, revoked or expired.
Last used Indicates when the credential was last used, or Never.
Expires Displays an expiry when one is set. This panel does not provide an expiry editor.
Token history Lists historical revoked or expired tokens.

Rotating a token invalidates its previous secret immediately. Copy the replacement into the directory promptly and retest. Revoking a token stops provisioning through that credential; it does not remove existing provisioning configuration or the requirement for an active SCIM mapping to sign in through SAML.

Troubleshooting

Symptom What to check
Provisioning authentication fails Check the exact Tenant URL, an active token, the correct bearer credential and that the organisation’s Identity providers switch is enabled.
Provisioned user receives no template access Check that the rule is enabled, the correct template is selected, all conditions match, the group identifier is synchronised and a directory update occurred after publishing the rule.
Provider does not appear after entering an email Check for an active SCIM mapping, both identity-provider switches enabled and complete SAML configuration. Simana discovers providers from the user’s account and eligible organisation or identity links; an email-domain match alone is insufficient. See the SSO setup article for other sign-in checks.