> ## Documentation Index
> Fetch the complete documentation index at: https://f4c7a9e2d8b1-docs.tenzo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# SCIM Directory Sync

> Configure SCIM so your identity provider can add and deactivate Tenzo users

## SCIM Directory Sync

Organization admins can configure SCIM from the **Admin** section of the Tenzo app.

* Navigate to **Admin > Organization & Users > SCIM Settings**.

SCIM keeps the people in Tenzo in sync with your identity provider. It does not sign people in.

SCIM Settings has two tabs:

* **Setup** — create a SCIM connection, copy the **base URL** and **token** your identity provider needs, and rotate the token when your security policy requires it.
* **Role mappings** — map identity-provider roles to Tenzo roles. This tab appears after the organization has a SCIM connection.

### Before You Start

People added by SCIM do not receive an invite email. They sign in the same way as other users in the organization: with [SSO](/user-management/sso) if it is turned on, or with email and password if it is not. An admin can also allow email and password for a specific person on [Manage Users](/user-management/users#password-exceptions).

They do not start with a password. If they need one, they can set it with **Forgot password** on the login page.

### Creating a New SCIM Connection

To add a new SCIM connection in Tenzo:

1. Go to **Admin > Organization & Users > SCIM Settings** and open the **Setup** tab.
2. Click **New connection**.
3. Enter a **Display Name** that will help admins recognize the connection (for example, “Okta - Production”).
4. Choose **Okta** or **Microsoft Entra**, then save. Tenzo shows a **base URL** and **token**. Keep this page open.

Then finish the matching steps in your identity provider.

### Okta

You can add SCIM to the same Okta app you use for [SSO](/user-management/sso), or create a standalone SCIM app.

#### Add SCIM to your SSO app

1. In Okta, open the SAML application you use for Tenzo.
2. On the **General** tab, under **App Settings**, check **Enable SCIM Provisioning**. Save.
3. Create the SCIM connection in Tenzo as described above, and choose **Okta**.
4. In Okta, open the **Provisioning** tab and:
   1. Set **Authentication mode** to **HTTP Header**.
   2. Paste the Tenzo **base URL** into **SCIM connector base URL**.
   3. Set **Unique identifier** to `userName`.
   4. Under **Supported provisioning actions**, select all of the **Push** options.
   5. Paste the Tenzo **token** into **HTTP Header → Authorization**.
5. Save.
6. Assign people to the application (and remove them) to create and deactivate Tenzo users. To set Tenzo roles, map each identity-provider role on the **Role mappings** tab (for example, Manager → Admin).

A longer walkthrough with screenshots is in [SCIM with Okta](https://stytch.com/docs/multi-tenant-auth/enterprise-ready/scim/okta).

#### Standalone SCIM app

If you do not already have a SAML application for Tenzo:

1. In Okta, go to **Applications → Browse App Catalog**.
2. Search for **SCIM 2.0 Header Auth** and select **SCIM 2.0 Test App (Header Auth)**.
3. Name the application and save it.
4. On **Sign-on Options**, under **Credential Details**, set **Application username format** to **Email**. Save.
5. Open the **Provisioning** tab and click **Configure API Integration**.
6. Create the SCIM connection in Tenzo as described above, and choose **Okta**.
7. Back in Okta, paste the Tenzo **base URL**. For the API token, enter `Bearer ` followed by the Tenzo **token**.
8. Choose which SCIM actions to send, then save.
9. Assign people to the application (and remove them) to create and deactivate Tenzo users. To set Tenzo roles, map each identity-provider role on the **Role mappings** tab.

### Microsoft Entra

1. If you do not already have an application in Entra, go to **Applications → Enterprise Applications** and select **Create your own application**. Name it and choose **Integrate any other application you didn't find in the gallery**.
2. Open **Provisioning** (or **Provision User Accounts** under Getting Started).
3. Click **Get started**, then set provisioning mode from **Manual** to **Automatic**. You should see **Admin Credentials**. Leave this tab open.
4. Create the SCIM connection in Tenzo as described above, and choose **Microsoft Entra**.
5. In Entra, under **Admin Credentials**:
   1. Paste the Tenzo **base URL** into **Tenant URL**.
   2. Paste the Tenzo **token** into **Secret Token**.
6. Click **Test Connection**, then save.
7. Back on **Provisioning**:
   1. Under **Mappings**, map `objectId` to `externalId` (`objectId` is the source, `externalId` is the target).
   2. Set **Provisioning Status** to **On**.
8. Assign people to the application (and remove them) to create and deactivate Tenzo users. Entra syncs on a schedule (about every 40 minutes). You can provision on demand to test sooner.
9. To set Tenzo roles from Entra, assign groups or app roles to the same application, include group provisioning in the mapping, then map those role names to Tenzo roles on the **Role mappings** tab.

A longer walkthrough with screenshots is in [SCIM with Microsoft Entra](https://stytch.com/docs/multi-tenant-auth/enterprise-ready/scim/microsoft-entra).

### Supported Operations

SCIM syncs people and the Tenzo role that matches the identity-provider roles you mapped on **SCIM Settings**.

| In your identity provider | In Tenzo |
| - | - |
| Assign someone to the Tenzo app | They appear on [Manage Users](/user-management/users) as **Active**. New people start as **Limited Access User** unless one of their identity-provider roles is mapped. Someone who already has a Tenzo role keeps it until a mapped role is assigned |
| Give them a mapped role (for example, Manager → Admin) | Their Tenzo role becomes the mapped role. If they have more than one mapped role, they get the highest access: Admin, then Editor, then Viewer, then Recruiter, then Hiring Manager |
| Remove a mapped role | Their Tenzo role is recalculated from the mapped roles they still have. If none remain, they become **Limited Access User**. They stay **Active** |
| Change a mapping on the **Role mappings** tab | Everyone with that identity-provider role is updated to the new Tenzo role |
| Rename an identity-provider role so it no longer matches a mapping | Same as removing that mapped role. Add a new mapping for the new name |
| Update name or email | Name and email are updated on Manage Users |
| Unassign, disable, or delete the person | Status becomes **Deactivated**. They cannot sign in. They stay on Manage Users |
| Assign them again | Status becomes **Active** again, and their role follows their current mapped roles |

People added by SCIM do not get an invite email. They sign in the same way as other users in the organization.

A role you set on [Manage Users](/user-management/users) for a directory-managed user is overwritten on the next sync if they have a mapped identity-provider role. Change the mapping or their role in the identity provider instead.

### Role mappings

On the **Role mappings** tab, map each identity-provider role name to a Tenzo role: Admin, Editor, Viewer, Recruiter, or Hiring Manager. The tab is available after you create a SCIM connection on **Setup**.

If the organization has no mappings, SCIM still creates and deactivates people. New people start as **Limited Access User**. Existing Tenzo roles are left unchanged until you add a mapping that matches one of their identity-provider roles.

Do not delete a directory-managed user from Tenzo if they still have the app assigned in your identity provider. The next sync will create them again. Remove them in the identity provider instead. You can delete them from Manage Users after they are Deactivated, or after you disable SCIM.

### Managing Existing Connections

From **Setup** you can:

* View the associated **IdP** and **status**.
* Rotate the token when your security policy requires it.
* Disable the connection when needed.

From **Role mappings** you can map identity-provider roles to Tenzo roles.

Disabling the connection stops the identity provider from creating or deactivating users. Existing Tenzo users are unchanged.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.