How does SCIM provisioning work?
SCIM keeps membership in sync with your identity provider when enabled for your plan.
Updated 2026-08-13
SCIM can keep FabricLoop membership in sync with your identity provider on Enterprise. There is no SCIM page in Settings — provisioning is enabled with support, not self-serve.
Set up provisioning
- Confirm the workspace is on Enterprise, or talk to us about upgrading.
- Finish SSO / SAML so people sign in through your IdP.
- Contact us and ask to enable SCIM. Include your workspace name and identity provider (for example Okta, Entra, or Google Workspace).
- We'll walk your IT team through the remaining IdP-side steps. Don't look for a SCIM token or endpoint in FabricLoop Settings — it isn't there.
Until SCIM is live, keep using email invites and join requests. Owners still change FabricLoop roles in Team Permissions unless we map those from the IdP as part of setup.
Tips
- If email domain join is on at the same time as SSO, people can skip your IdP. Turn domain join off if SSO (and SCIM) should be the only path in.
- Keep a break-glass owner procedure with your IT team in case the IdP app is misconfigured.
Related
Still stuck?
Contact us or browse all help topics.