Skip to main content

SCIM Support

We manage privileges via Okta (and Opal). This makes it so that we have to logout/login again to get updated permissions. Recently, during an outage, a new engineer on the team got bit by this “tribal knowledge” and it extended the outage. Having SCIM or at least faster role update times would be amazing!

Workaround
Status: 🔭 Discovery2 comments

This request was merged into another request

Comments2

  • Purple Mustard

    •

    Aug 22, 2025

    Having a SCIM provisioning is an absolute need to have for any tool deployed to employee.
    It allow us to have a proper and accurate lifecycle management. Access granted and revoke automatically without issues with potential ghost account or else.

  • Black Breeze

    •

    May 10, 2025

    Thanks for surfacing this—and especially for calling out that we “extended the outage.” That stings a bit, which probably means it matters. It suggests we didn’t meet expectations when access control was most critical.

    You mentioned that logging out and back in was the workaround. That’s useful context—thank you. Was the problem mainly that you had to do that? Or that it wasn’t obvious that you needed to?

    We’re wondering if the issue is tied to how we evaluate login policies. If group membership is only checked at login, changes in your identity provider wouldn’t be picked up mid-session. That might be expected technically—but definitely surprising in practice.

    We’d love to understand more about what “working access control” looks like for you in those moments. For example:

    • How urgent was the update?

    • What did you expect to happen?

    • What would have made you feel confident the system was in sync?

    And for others watching: if SCIM is something you’ve looked into, is it mostly about automated provisioning? Or about revoking access quickly and reliably?

    We’re open to SCIM support, but want to make sure we’re solving the right problem—not just matching a standard. Appreciate all context you can share.