Overview
System for Cross-domain Identity Management (SCIM) automates dashboard user provisioning and de-provisioning between your Identity Provider (IdP) and Whatfix. It automatically creates, updates, and removes user accounts, thereby improving security, saving account manager’s time, and reducing manual efforts. SCIM helps in maintaining the Whatfix Dashboard in sync with your organization’s identity management system.
Why Use SCIM?
Organizations that manage user access through a centralized Identity Provider often enable SCIM to keep Whatfix aligned with organizational policies. It reduces manual user management, ensures consistent access control across applications, supports auditability and governance, and automatically reflects access changes across integrated platforms.
How SCIM Helps Manage Users?
SCIM simplifies user management by automating user lifecycle operations between the IdP and Whatfix. With SCIM provisioning:
Users are automatically added to Whatfix when assigned access in the IdP along with the Translator role set as default, which can later be changed by the Account Manager.
Updates made to user details in the IdP are synchronized with Whatfix.
Users marked inactive in the IdP are deprovisioned from Whatfix.
Administrative teams manage users from a single centralized system instead of multiple platforms.
This approach reduces manual intervention while maintaining accurate and up-to-date user access.
Info:
Follow these pre requisites before setting up SCIM on the Whatfix dashboard:
SSO must be enabled on your account before you proceed with SCIM. If it isn’t enabled, the SCIM page shows a Needs SSO message. For more information, see Whatfix Single Sign-On.
You need Account Manager access to both the Whatfix Dashboard and your Identity Provider (for example, Okta).
Configure SCIM
Expand the following accordion for more details:
Steps to enable SCIM on the Whatfix Dashboard
Step 1: Open SCIM Configuration
On the Whatfix Guidance Dashboard, click Settings.

Click SCIM.

Info:
You can also access SCIM configuration from SSO and Authentication. For more information, see Single Sign On.
Under Set up your SCIM, click Get started.

Step 2: Add Whatfix Information
Copy and add the following SCIM credentials of Whatfix to your identity provider site such as Okta and Azure.
Note:
Follow the articles below to set up a SCIM application on your IdP:
Okta: Add SCIM provisioning on Okta
Copy the SCIM Base URL.

Click Generate token to create and copy the Bearer token.

Note:
When you click Regenerate token, click Confirm to regenerate the token. Regenerating the token breaks your existing SCIM connection. You must update your IdP with the new token to resume provisioning.

Info:
SCIM Base URL: The endpoint URL provided by Whatfix where your Identity Provider (IdP) sends SCIM provisioning requests.
Bearer token: A secret, unique security token used by your IdP to authenticate and authorize all SCIM requests with Whatfix.
Under Mark these as done once you have configured them in your identity provider, select the given options in your IdP.

Info:
The application uses a Bearer Token to securely authenticate API requests.
Select the provisioning actions that your application supports such as creating users, updating user profiles and syncing groups.
Click Continue.

Step 3: Add Identity Provider information
Choose one of the methods how users should be provisioned in Whatfix. Only dashboard users matching these criteria will be created or updated.
Add User attributes
Provision users based on a user attribute such as role or department.
Enter User attribute name (for example, department).
Enter User attribute value (for example, training).

Add Group name
Provision users from a specific group. Enter the Group name exactly as it appears on your identity provider site.

Add Group attribute
Provision users belonging to groups with specific attributes. Enter the Group attribute name and Group attribute value (for example, role = dashboard user).

Note:
Use only one identification method at a time.
Enable the SCIM toggle.

Click Continue.

Step 4: Role Provisioning (Optional)
Configure role mappings to automatically assign desired Whatfix roles to users during SCIM provisioning.
Info:
If you skip this step, all provisioned users receive the Translator role by default. You can configure or update role mappings at any time.
Use the following steps to configure role provisioning:
Click Attribute name.

Click Create new attribute.

Enter the attribute name and click Create.

Enter the corresponding Attribute value.

Select the Whatfix role from the dropdown.

Click Add Rule to configure additional role mapping as required.

Click Save.

Click Enable SCIM.

The role mappings are saved.
After you save the configuration, Whatfix then waits 72 hours for provisioning call from your Identity Provider to activate SCIM. The status changes to Awaiting provisioning call and SCIM activates automatically once the call is received.

Info:
After successful provisioning:
An Enable or Disable toggle appears, enabling Account Managers to control SCIM provisioning status.
What to expect after SCIM is enabled?
Once SCIM provisioning is enabled:
Users can be added or managed directly from the Identity Provider (IdP).
User accounts are automatically provisioned in Whatfix based on IdP configuration.
Users marked inactive in the IdP, can no longer access the Whatfix dashboard.
Newly provisioned users are assigned the Translator role by default.
Manual invitations from Whatfix are no longer possible, as IdP is the only source of truth.

