SCIM: Automating Identity Lifecycle Across Systems

How the System for Cross-domain Identity Management standard synchronises users, groups, and entitlements between cloud apps and identity providers.

8 min read

What Is SCIM?

SCIM (System for Cross-domain Identity Management) is an open standard (RFC 7642 – 7643 – 7644) that defines a REST API schema for automating the exchange of identity data between domains. Think of it as a universal adapter for user provisioning.

Before SCIM, every SaaS app had its own proprietary API for creating, updating, and deleting users. Identity providers (Azure AD / Okta) had to write custom connectors for each one — a maintenance nightmare. SCIM standardises this: one API contract that any SCIM-compliant app can speak. Credenti sits alongside other services as a SCIM receiver, ingesting identity data pushed by the IdP.

graph TD
    IdP["<b>Identity Provider</b><br/>Azure AD / Okta"] -->|SCIM| Slack["<b>Slack</b><br/>messaging"]
    IdP -->|SCIM| Credenti["<b>Credenti</b><br/>SCIM receiver"]
    IdP -->|SCIM| GitHub["<b>GitHub</b><br/>dev tools"]

    style IdP fill:#e8f0fe,stroke:#0071e3,color:#1d1d1f
    style Slack fill:#f5f5f7,stroke:#d2d2d7,color:#1d1d1f
    style Credenti fill:#e8f0fe,stroke:#0071e3,color:#1d1d1f
    style GitHub fill:#f5f5f7,stroke:#d2d2d7,color:#1d1d1f

The Provisioning Problem

When a new hire joins, they need accounts in: HRIS, email, Slack, GitHub, Jira, VPN, and dozens of other tools. When they leave, every account must be deactivated — ideally within minutes.

Doing this manually is slow, error-prone, and a security risk. Orphan accounts (active accounts for former employees) are one of the most common attack vectors in enterprise breaches. SCIM automates the entire lifecycle.

SCIM in the Identity Stack

SCIM fills a specific gap. Understanding where it fits helps clarify why it exists:

LayerProtocolWhat It Does
AuthenticationOIDC / SAML”Who is this user?” — verifies identity at login
AuthorisationOAuth 2.0”What can this app do?” — grants API permissions
ProvisioningSCIM”Does this user have an account?” — creates/deactivates accounts
DirectoryLDAP”Where is this user in the org chart?” — looks up attributes

OIDC lets Alice log into Slack. SCIM ensures Alice has a Slack account to log into — and deactivates it when she leaves.

The JML Lifecycle

SCIM maps directly to the three phases of identity management:

graph LR
    J["<b>JOINER</b><br/>POST /Users {active:true}"] -->|account created| M["<b>MOVER</b><br/>PATCH /Users {dept: &quot;Eng&quot;}"]
    M -->|roles updated| L["<b>LEAVER</b><br/>PATCH /Users {active:false}"]

    style J fill:#e8f0fe,stroke:#0071e3,color:#1d1d1f
    style M fill:#f5f5f7,stroke:#86868b,color:#1d1d1f
    style L fill:#f5f5f7,stroke:#d2d2d7,color:#1d1d1f

How It Works: A Complete Flow

Here’s what happens when a new engineer joins Credenti:

Step 1: HR system creates user

The HRIS (Workday, BambooHR) adds Alice with department=Engineering. This triggers a webhook to the IdP.

Step 2: IdP pushes to SCIM endpoints

The IdP makes a POST /Users request to every SCIM-connected app:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
  "userName": "alice@credenti.com",
  "name": { "givenName": "Alice", "familyName": "Jones" },
  "emails": [{ "value": "alice@credenti.com", "type": "work", "primary": true }],
  "active": true,
  "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User": {
    "department": "Engineering",
    "employeeNumber": "12345"
  }
}

Step 3: Each app provisions

Slack creates an account, adds Alice to #engineering and #general. GitHub adds her to the engineering team with read access. Zoom creates a licensed account.

Step 4: Lifecycle event

When Alice moves to Product, the IdP sends PATCH /Users/{id} with { "department": "Product" }. Group memberships update automatically. When Alice leaves, PATCH /Users/{id} { "active": false } deactivates every account.

SCIM API Sequence

The SCIM API calls over the wire:

sequenceDiagram
    participant IdP as Identity Provider
    participant App as SCIM Service<br/>(Credenti)

    Note over IdP,App: JOINER
    IdP->>App: POST /Users
    Note right of App: active: true<br/>department: "Eng"
    App-->>IdP: 201 Created

    Note over IdP,App: MOVER
    IdP->>App: PATCH /Users/{id}
    Note right of App: department: "Product"
    App-->>IdP: 200 OK

    Note over IdP,App: LEAVER
    IdP->>App: PATCH /Users/{id}
    Note right of App: active: false
    App-->>IdP: 200 OK

Core Operations

OperationHTTP MethodEndpointLifecycle Event
List usersGET/UsersIdP sync (discovery)
Create userPOST/UsersJoiner
Get userGET/Users/{id}Lookup
Update userPUT/Users/{id}Mover (full replace)
Patch userPATCH/Users/{id}Mover (partial update)
Delete userDELETE/Users/{id}Leaver (hard delete)
DeactivatePATCH/Users/{id}Leaver (soft delete via active:false)

SCIM also supports groups via /Groups and bulk operations via /Bulk for large-scale syncs.

Why SCIM Matters for Security

  • Instant deprovisioning — When a user is deactivated in the IdP, SCIM propagates deactivation to every connected app within seconds to minutes. No orphan accounts.
  • Least privilege at scale — Entitlements (group memberships, roles) are managed centrally. A role change in the IdP automatically updates access across all apps.
  • Audit trail — Every create, update, and delete is logged on both sides.
  • JML automation — Joiners, movers, and leavers are handled without IT tickets.

Real-World Adoption

Major identity providers support SCIM out of the box:

Thousands of SaaS apps expose SCIM endpoints — from Salesforce and ServiceNow to Zoom and Slack. Most enterprise apps in the major cloud marketplaces now require SCIM support.

SCIM 2.0 vs. Custom Integrations

AspectSCIM 2.0Custom API Integration
StandardisationRFC 7642 – 7643 – 7644Proprietary per vendor
Time to integrateDays (known contract)Weeks to months
MaintenanceMinimal (stable spec)Ongoing (API changes)
ToolingBuilt into every major IdPCustom code required
Attribute mappingStandard schemaAd-hoc per integration

SCIM is the plumbing that keeps identity consistent across hundreds of SaaS apps. Without it, deprovisioning is manual, slow, and leaky. With it, identity lifecycle management becomes automated, auditable, and secure. In a zero-trust world, knowing exactly who has access to what — and revoking it instantly — is non-negotiable. SCIM makes that possible.