SCIM

Let your identity provider add and remove your Burrow's members, and decide their roles from its groups.

Updated Sep 28, 2026

The SCIM section under Burrow Settings connects your identity provider's directory to your Burrow. Your identity provider tells the Burrow who should have access, and with group roles, which role each person holds. Only the Burrow's owner can open it. SCIM is included on eligible plans. On other plans the section shows what it adds.

People your identity provider provisions get into the Burrow by signing in through it, so set up single sign-on on the SSO page as well.

Connect your identity provider#

Your identity provider needs two things for provisioning: the Base URL shown under Provisioning, and a token. Enter a name for the token, such as the name of your identity provider, and create it. The token is shown once. Copy it into your identity provider's provisioning settings, where it is usually called the API token or secret token, together with the base URL.

Each token is listed with when it was last used, and Revoke stops it working at once. A Burrow holds up to five live tokens, so you can create a new one and move your identity provider over before revoking the old one.

Provisioned shows how many people your identity provider has pushed, and how many of them have signed in.

What your identity provider decides#

  • Someone it provisioned becomes a member the first time they sign in through it, even when Let it add new members is off on the SSO page. Joining takes a seat on your plan.

  • Deactivating or deleting someone in your identity provider cuts their access and ends their sessions straight away. Reactivating them restores it, when a seat is free.

  • Access your identity provider cut can only be given back by your identity provider, so the Members page can't restore it. A member you disabled yourself stays disabled whatever your identity provider says.

  • The owner is never affected, whatever your identity provider sends.

  • Members your identity provider doesn't know about are left as they are, and you manage them on the Members page.

Group roles#

Your identity provider's groups appear under Group Roles once it pushes them. Pick a group to map it, then choose the role its members get. Put the mappings in order with the arrows, and remove one with its cross. When a member is in several mapped groups, the first one in the list decides their role. Save your changes, and every provisioned member's role follows at once.

While any mapping exists, a provisioned member in none of the mapped groups has no access until they are added to one. Their role is set by your identity provider, so it can't be changed on the Members page. A role used by a mapping can't be deleted until the mapping is removed.

With no mappings, your identity provider decides who gets in but not their role. A new member gets the role for new members set on the SSO page, and an existing member keeps the role they have.

If your plan stops including SCIM, your identity provider's changes are no longer applied, and your setup stays visible, read-only, until the plan includes it again.