SCIM Directory Sync
Organization admins can configure SCIM from the Admin section of the Tenzo app.- Navigate to Admin > Organization & Users > SCIM Settings.
- Setup — create a SCIM connection, copy the base URL and token your identity provider needs, and rotate the token when your security policy requires it.
- Role mappings — map identity-provider roles to Tenzo roles. This tab appears after the organization has a SCIM connection.
Before You Start
People added by SCIM do not receive an invite email. They sign in the same way as other users in the organization: with SSO if it is turned on, or with email and password if it is not. An admin can also allow email and password for a specific person on Manage Users. They do not start with a password. If they need one, they can set it with Forgot password on the login page.Creating a New SCIM Connection
To add a new SCIM connection in Tenzo:- Go to Admin > Organization & Users > SCIM Settings and open the Setup tab.
- Click New connection.
- Enter a Display Name that will help admins recognize the connection (for example, “Okta - Production”).
- Choose Okta or Microsoft Entra, then save. Tenzo shows a base URL and token. Keep this page open.
Okta
You can add SCIM to the same Okta app you use for SSO, or create a standalone SCIM app.Add SCIM to your SSO app
- In Okta, open the SAML application you use for Tenzo.
- On the General tab, under App Settings, check Enable SCIM Provisioning. Save.
- Create the SCIM connection in Tenzo as described above, and choose Okta.
- In Okta, open the Provisioning tab and:
- Set Authentication mode to HTTP Header.
- Paste the Tenzo base URL into SCIM connector base URL.
- Set Unique identifier to
userName. - Under Supported provisioning actions, select all of the Push options.
- Paste the Tenzo token into HTTP Header → Authorization.
- Save.
- Assign people to the application (and remove them) to create and deactivate Tenzo users. To set Tenzo roles, map each identity-provider role on the Role mappings tab (for example, Manager → Admin).
Standalone SCIM app
If you do not already have a SAML application for Tenzo:- In Okta, go to Applications → Browse App Catalog.
- Search for SCIM 2.0 Header Auth and select SCIM 2.0 Test App (Header Auth).
- Name the application and save it.
- On Sign-on Options, under Credential Details, set Application username format to Email. Save.
- Open the Provisioning tab and click Configure API Integration.
- Create the SCIM connection in Tenzo as described above, and choose Okta.
- Back in Okta, paste the Tenzo base URL. For the API token, enter
Bearerfollowed by the Tenzo token. - Choose which SCIM actions to send, then save.
- Assign people to the application (and remove them) to create and deactivate Tenzo users. To set Tenzo roles, map each identity-provider role on the Role mappings tab.
Microsoft Entra
- If you do not already have an application in Entra, go to Applications → Enterprise Applications and select Create your own application. Name it and choose Integrate any other application you didn’t find in the gallery.
- Open Provisioning (or Provision User Accounts under Getting Started).
- Click Get started, then set provisioning mode from Manual to Automatic. You should see Admin Credentials. Leave this tab open.
- Create the SCIM connection in Tenzo as described above, and choose Microsoft Entra.
- In Entra, under Admin Credentials:
- Paste the Tenzo base URL into Tenant URL.
- Paste the Tenzo token into Secret Token.
- Click Test Connection, then save.
- Back on Provisioning:
- Under Mappings, map
objectIdtoexternalId(objectIdis the source,externalIdis the target). - Set Provisioning Status to On.
- Under Mappings, map
- Assign people to the application (and remove them) to create and deactivate Tenzo users. Entra syncs on a schedule (about every 40 minutes). You can provision on demand to test sooner.
- To set Tenzo roles from Entra, assign groups or app roles to the same application, include group provisioning in the mapping, then map those role names to Tenzo roles on the Role mappings tab.
Supported Operations
SCIM syncs people and the Tenzo role that matches the identity-provider roles you mapped on SCIM Settings.
People added by SCIM do not get an invite email. They sign in the same way as other users in the organization.
A role you set on Manage Users for a directory-managed user is overwritten on the next sync if they have a mapped identity-provider role. Change the mapping or their role in the identity provider instead.
Role mappings
On the Role mappings tab, map each identity-provider role name to a Tenzo role: Admin, Editor, Viewer, Recruiter, or Hiring Manager. The tab is available after you create a SCIM connection on Setup. If the organization has no mappings, SCIM still creates and deactivates people. New people start as Limited Access User. Existing Tenzo roles are left unchanged until you add a mapping that matches one of their identity-provider roles. Do not delete a directory-managed user from Tenzo if they still have the app assigned in your identity provider. The next sync will create them again. Remove them in the identity provider instead. You can delete them from Manage Users after they are Deactivated, or after you disable SCIM.Managing Existing Connections
From Setup you can:- View the associated IdP and status.
- Rotate the token when your security policy requires it.
- Disable the connection when needed.