# SCIM & JIT

> Business+: SSO + JIT (allow-listed email domains) creates membership on first login. Enterprise: SCIM 2.0 Users at /api/scim/v2 with Bearer token (create, list, soft-disable). Nested SCIM Groups are not supported yet.

- HTML: https://www.simpleworkload.com/en/scim-provisioning-it
- Markdown: https://www.simpleworkload.com/en/scim-provisioning-it.md

## SCIM provisioning for IT

## SCIM provisioning for IT — SSO JIT & SCIM Users Enterprise | Workload

IT provisioning: SSO JIT by domain and SCIM 2.0 Users (create/patch active). IdP runbook for Azure AD / Okta. Enterprise plan. No nested SCIM Groups yet.

Workload SCIM provisioning

User provisioning via SSO JIT and SCIM 2.0 Users for Enterprise organizations.

How do you provision Workload users from an IdP?

Business+: SSO + JIT (allow-listed email domains) creates membership on first login. Enterprise: SCIM 2.0 Users at /api/scim/v2 with Bearer token (create, list, soft-disable). Nested SCIM Groups are not supported yet.

- SSO Azure AD / Google / Okta
- JIT membership (allow-listed domains)
- SCIM 2.0 Users + soft-disable
- IdP runbook in Settings
- Diligence pack / RSSI evidence (no secrets)

## SCIM & JIT

for Enterprise IT

Provision from your IdP without manual invites — honest scope for security reviews.

Request an Enterprise IAM demo

### Nested AD SCIM Groups?

Not in v1. Only SCIM Users (create/list/patch active) ship today. Nested Groups = P3 backlog.

### Does soft-disable remove access?

Yes. Patch active=false sets disabledAt on the membership; the user can no longer access the org.

### Where is the runbook?

Settings → SCIM card (base URL /api/scim/v2, Bearer, supported ops) plus training/docs links.

## Sitemap

- [Markdown sitemap](https://www.simpleworkload.com/sitemap.md)
- [XML sitemap](https://www.simpleworkload.com/sitemap.xml)
- [llms.txt](https://www.simpleworkload.com/llms.txt)
- [llms-full.txt](https://www.simpleworkload.com/llms-full.txt)
