Directory provisioning (SCIM)
Automatically create, update, and deprovision users and groups from your directory.
How it works
With SCIM 2.0 connected, your IdP pushes user and group changes to Veridenti in real time. New hires get access automatically; departures are deprovisioned instantly with forward secrecy (their access is cut and keys rotate). Group membership can drive role mapping.
Setup
- Turn on SCIM in SSO & Directory; copy the SCIM base URL and bearer token into your IdP's provisioning config.
- Assign the users/groups you want provisioned.
- Map directory groups → roles so access follows your org structure.
Manual groups (no directory required)
Not running a directory? You can still organize people. Under Members → Groups, create a manual group, then click Manage members to add or remove people in a searchable drawer. Manual groups behave like directory groups everywhere else — you can map them to a role and set a default data-residency region for the whole group — and they are never touched by SCIM, so they coexist safely with directory sync. This is the recommended path for SMBs and for grouping people who aren't in your IdP.
What if…
- A deprovisioned user still appears — SCIM is eventually consistent; a sync runs shortly. You can also revoke immediately from Members.
- Group mapping isn't applying — confirm the group is assigned to the app in your IdP and mapped under Roles & Policies.
- You need a group but have no directory — create a manual group under Members → Groups.