# Provision users and teams with SCIM

URL: https://attio.com/help/reference/workspace-settings-billing/security/provision-users-and-teams-with-scim
Breadcrumbs: [Help](https://attio.com/help) > [Reference](https://attio.com/help/reference) > [Workspace settings & billing](https://attio.com/help/reference/workspace-settings-billing) > [Security](https://attio.com/help/reference/workspace-settings-billing/security)

Automate member provisioning from your identity provider.

> Available on enterprise plans.
>
> Only **admins** can configure SCIM.

SCIM (System for Cross-domain Identity Management) lets you manage Attio workspace membership directly from your identity provider (IDP). When SCIM is configured, your identity provider can be used to manage workspace membership in Attio. Adding someone in your IDP provisions them in Attio, and removing them suspends their access.

SCIM works independently of [Single sign-on (SSO)](https://attio.com/help/reference/workspace-settings-billing/security/single-sign-on). You can use either feature without the other, though many organizations use both together.

## SCIM and domain verification

First, make sure you have at least one [verified domain](https://attio.com/help/reference/workspace-settings-billing/security/verify-a-domain) on your workspace. This is the best way to use SCIM, and allows you to add users directly to your workspace. Without a verified domain, you will only be able to send workspace invites to those users.

## Linking an Attio workspace with an identity provider

For step-by-step instructions on configuring your identity provider, see:

- [Set up SCIM with Okta](https://attio.com/help/reference/workspace-settings-billing/security/set-up-scim-with-okta)
- [Set up SCIM with Microsoft Entra](https://attio.com/help/reference/workspace-settings-billing/security/set-up-scim-with-microsoft-entra)

### Automatic seat assignment

When a new user is provisioned via SCIM, Attio uses an available seat on your subscription first. If no seats are available, the provisioning request fails.

To change this behavior, enable **Automatic seat assignment** in Attio:

- Click your workspace name and select **Workspace settings**.
- Click **Security** in the sidebar.
- Under **User provisioning (SCIM)**, toggle on **Automatic seat assignment**.

When enabled, Attio will use an available seat if one exists, or automatically add a new paid seat to your subscription if not.

## How SCIM works

Once SCIM is configured, your IDP controls how members are provisioned and managed in Attio.

### Provisioning users

Assigning a user to the Attio SCIM integration in your IDP adds them to your workspace. If a user with that email already exists in Attio, they are linked to the workspace rather than provisioned as a new user.

Users are provisioned as non-admin members by default. To provision someone as an admin, set their role to **admin** in your IDP before assigning them.

How a user is added depends on their email domain:

- **Verified domain:** The user is added to the workspace directly and receives an email notifying them they've been added. New Attio users also receive a welcome email.
- **Non-verified domain:** The user receives a workspace invite and is added once they accept it.

### Deprovisioning users

Removing or deactivating a user in your IDP suspends their Attio workspace membership immediately and revokes their session.

It’s not possible to delete or downgrade the last remaining admin in a workspace. First, give another member admin access.

### Manage admin and member roles

Set and update roles using the **roles** attribute in your IDP. Attio supports two roles: **member** and **admin**. An unrecognized role value defaults to member. If both roles are assigned to the same user, admin takes precedence.

### Manage teams

SCIM groups map to Attio teams. Pushing a group from your IDP to Attio creates a new team, or you can link an IDP group to an existing team.

### How Attio and your IDP work together

Your IDP is the source of truth for any members and teams provisioned through it. If a change is made directly in Attio, such as updating a role or team membership, your IDP will reconcile it back to its own state on the next sync.

Any members or teams not currently managed by your IDP can still be managed freely from within Attio and won't be affected by syncs.

## Disconnect SCIM

To stop syncing, remove your credentials from your identity provider. If you connected using a developer token, you can also delete it from **Workspace settings > Developers**. Once the token is removed, your IDP can no longer provision or suspend members in Attio.

All changes made via SCIM remain in place and are not reverted.

## FAQ

### What happens to a member's data when they are suspended via SCIM?

Suspending a member via SCIM has the same effect as manually suspending them in Attio. See [how suspending a member impacts data](https://attio.com/help/reference/workspace-settings-billing/manage-members-and-admins#how-does-suspending-a-member-impact-data).

### Can I use SCIM across multiple verified domains?

Yes. SCIM applies to all [verified domains](https://attio.com/help/reference/workspace-settings-billing/security/verify-a-domain) on your workspace. When a user is provisioned, Attio checks all verified domains to determine whether to add them directly to the workspace or send them an invite.

### Can I use SCIM without a verified domain?

Yes. If your workspace doesn't have a verified domain, or if a user's email doesn't match one, they will receive a workspace invite rather than being added directly. They become active workspace members once they accept the invite.
