# SCIM user provisioning

> Set up SCIM 2.0 to create, update and remove workspace members automatically from your identity provider, with the base URL, token and supported endpoints.

SCIM 2.0 keeps workspace members in sync with your directory (Business
plan, with [SSO](/docs/teams/sso) set up).

## Connect

1. **Workspace settings → SSO → SCIM token → Generate.** The
   token (`scim_…`) is shown once. Generating a new one replaces the old.
2. In your IdP's provisioning settings:

   | Setting | Value |
   |---|---|
   | SCIM base URL | `https://privatusanalytics.com/scim/v2` |
   | Authentication | HTTP header, Bearer token: the `scim_…` token |
   | Unique identifier | `userName` = email address |

3. Enable **create**, **update** and **deactivate** users, and assign the
   people or groups to provision.

## What's supported

| Operation | Endpoint | Effect |
|---|---|---|
| List / filter users | `GET /scim/v2/Users` | Users provisioned into this workspace (`filter=userName eq "…"` supported) |
| Get a user | `GET /scim/v2/Users/{id}` | |
| Create | `POST /scim/v2/Users` | Creates the user if needed and adds them as a member with the SSO default role |
| Update | `PUT` or `PATCH /scim/v2/Users/{id}` | Display name and `active`. `active: false` removes the membership |
| Delete | `DELETE /scim/v2/Users/{id}` | Removes the member from the workspace |

Groups aren't provisioned: set roles and site access in Privatus Analytics. Removing
a member revokes their API tokens for this workspace. The person's account itself is kept (they may belong to
other workspaces).

Every SCIM change is recorded in the [audit log](/docs/teams/audit-log).
