---
title: "Understand the System for Cross-domain Identity Management"
slug: "system-for-cross-domain-identity-management"
updated: 2026-07-31T11:23:28Z
published: 2026-07-31T11:23:28Z
canonical: "support.whatfix.com/system-for-cross-domain-identity-management"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.whatfix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Understand the System for Cross-domain Identity Management

### Overview

System for Cross-domain Identity Management (SCIM) automates dashboard user provisioning and de-provisioning between your Identity Provider (IdP) and Whatfix. It automatically creates, updates, and removes user accounts, thereby improving security, saving account manager’s time, and reducing manual efforts. SCIM helps in maintaining the Whatfix Dashboard in sync with your organization’s identity management system.

#### Why Use SCIM?

Organizations that manage user access through a centralized Identity Provider often enable SCIM to keep Whatfix aligned with organizational policies. It reduces manual user management, ensures consistent access control across applications, supports auditability and governance, and automatically reflects access changes across integrated platforms.

#### How SCIM Helps Manage Users?

SCIM simplifies user management by automating user lifecycle operations between the IdP and Whatfix. With SCIM provisioning:

- Users are automatically added to Whatfix when assigned access in the IdP along with the Translator role set as default, which can later be changed by the Account Manager.
- Updates made to user details in the IdP are synchronized with Whatfix.
- Users marked inactive in the IdP are deprovisioned from Whatfix.
- Administrative teams manage users from a single centralized system instead of multiple platforms.

This approach reduces manual intervention while maintaining accurate and up-to-date user access.

> [!NOTE]
> Info:
> 
> Follow these pre requisites before setting up SCIM on the Whatfix dashboard:
> 
> - SSO must be enabled on your account before you proceed with SCIM. If it isn’t enabled, the SCIM page shows a **Needs SSO** message. For more information, see [Whatfix Single Sign-On](/studio/docs/whatfix-single-sign-on). ![Needs_SSO.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Needs_SSO.png)
> - You need Account Manager access to both the Whatfix Dashboard and your Identity Provider (for example, Okta).

---

#### Configure SCIM

Expand the following accordion for more details:

****Steps to enable SCIM on the Whatfix Dashboard****

**Step 1: Open SCIM Configuration**

1. On the [Whatfix Guidance Dashboard](/studio/docs/overview-of-the-whatfix-dashboard), click **Settings**.

![Click Settings on dashboard](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/settings_ia.png)
2. Click **SCIM**.

![Click SCIM on dashboard](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Dashboard_click_SCIM.png)

> [!NOTE]
> Info:
> 
> You can also access SCIM configuration from SSO and Authentication. For more information, see [Single Sign On](/studio/docs/whatfix-single-sign-on).
3. Under **Set up your SCIM**, click **Get started**.

![Click Get started to start the process of SCIM on dashboard](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Dashboard_SCIM_getstarted.png)

---

**Step 2: Add Whatfix Information**

Copy and add the following SCIM credentials of Whatfix to your identity provider site such as Okta and Azure.

> [!NOTE]
> Note:
> 
> Follow the articles below to set up a SCIM application on your IdP: **Okta**: [Add SCIM provisioning on Okta](https://help.okta.com/en-us/content/topics/apps/apps_app_integration_wizard_scim.htm)
> 
> **Azure**: [Add SCIM provisioning on Azure](https://learn.microsoft.com/en-us/azure/databricks/admin/users-groups/scim/aad)

1. Copy the **SCIM Base URL**. ![Base_url_SCIM.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Base_url_SCIM.png)
2. Click **Generate token** to create and copy the **Bearer token**.

![SCIM_generate_token.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SCIM_generate_token.png)

> [!WARNING]
> Note:
> 
> When you click **Regenerate token**, click **Confirm** to regenerate the token. Regenerating the token breaks your existing SCIM connection. You must update your IdP with the new token to resume provisioning. ![Regenerate_token_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Regenerate_token_scim.png)

> [!NOTE]
> Info:
> 
> - **SCIM Base URL**: The endpoint URL provided by Whatfix where your Identity Provider (IdP) sends SCIM provisioning requests.
> - **Bearer token**: A secret, unique security token used by your IdP to authenticate and authorize all SCIM requests with Whatfix.

> [!WARNING]
> Note:
> 
> **Workspace distribution** enables you to share the bearer token with the other workspaces that use the same SSO configuration. Sharing the token does not enable SCIM, each account must complete its own SCIM setup.
> 
> > [!TIP]
> > If all your workspaces use the same SSO configuration and a single SAML application, use Workspace distribution to share the bearer token across all the Whatfix dashboards.
> 
> - Click **Push Token** to share the bearer token with the other Workspaces that use the same SSO configuration. ![Push_token.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Push_token.png)
> 
> Here is a GIF illustration.
> 
> ![Push_token.gif](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Push_token.gif)
> - If you did not push the bearer token to a workspace that uses the same SSO configuration, click **Fetch from existing** on the required Whatfix dashboard to retrieve the bearer token shared with the other workspaces that use the same SSO configuration.
> 
> ![Fetch_from_existing.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Fetch_from_existing.png)
> 
> Here is a GIF illustration.
> 
> ![Fetch_token.gif](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Fetch_token.gif)
> - Ensure you have the permissions of an Account Manager to add workspaces that use the same SSO configuration. For more information, see [Whatfix User roles](/studio/docs/whatfix-user-roles) and [Use Custom roles on Whatfix dashboard](/studio/docs/use-custom-roles). ![add_workspaces.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/add_workspaces.png)
3. Under **Mark these as done once you have configured them in your identity provider**, select the given options in your IdP.

![scim_select_checkbox.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/scim_select_checkbox.png)

> [!NOTE]
> Info:
> 
> - The application uses a Bearer Token to securely authenticate API requests.
> - Select the provisioning actions that your application supports such as creating users, updating user profiles and syncing groups.
4. Click **Continue**.

![Scim_click_continue.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Scim_click_continue.png)

---

**Step 3: Add Identity Provider information**

Choose one of the methods how users should be provisioned in Whatfix. Only dashboard users matching these criteria will be created or updated.

1. Add **User attributes**

Provision users based on a user attribute such as role or department.

- Enter **User attribute name** (for example, department).
- Enter **User attribute value** (for example, training).

![User_attributes_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/User_attributes_scim.png)

1. Add **Group name**

Provision users from a specific group. Enter the **Group name** exactly as it appears on your identity provider site.

![Group_name_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Group_name_scim.png)

1. Add **Group attribute**

Provision users belonging to groups with specific attributes. Enter the **Group attribute name** and **Group attribute value** (for example, role = dashboard user). ![group_attribute_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/group_attribute_scim.png)

> [!WARNING]
> Note:
> 
> Use only one identification method at a time.

1. Enable the SCIM toggle. ![Enable_scim_toggle.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Enable_scim_toggle.png)
2. Click **Continue**. ![Scim_click_continue.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Scim_click_continue.png)

---

**Step 4: Role Provisioning (Optional)**

Configure role mappings to automatically assign desired Whatfix roles to users during SCIM provisioning.

> [!NOTE]
> Info:
> 
> If you skip this step, all provisioned users receive the Translator role by default. You can configure or update role mappings at any time.

Use the following steps to configure role provisioning:

1. Click **Attribute name**.

![Attribute_name_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Attribute_name_scim.png)
2. Click **Create new attribute**. ![create_new_attribute.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/create_new_attribute.png)
3. Enter the attribute name and click **Create**. ![Click_create_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Click_create_scim.png)
4. Enter the corresponding **Attribute value**. ![Enter_attribute_value.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Enter_attribute_value.png)
5. Select the **Whatfix role** from the dropdown. ![Select_role_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Select_role_scim.png)
6. Click **Add Rule** to configure additional role mapping as required. ![Add_rule.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Add_rule.png)
7. Click **Save**. ![Click_save_scim.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Click_save_scim.png)
8. Click **Enable** **SCIM**. ![SCIM_activation.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SCIM_activation.png)

The role mappings are saved.

After you save the configuration, Whatfix then waits 72 hours for provisioning call from your Identity Provider to activate SCIM. The status changes to **Awaiting provisioning call** and SCIM activates automatically once the call is received.

![Awaiting provision call message for SCIM](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/Dashboard_SCIM_awaitingprovisioncall.png)

> [!NOTE]
> Info:
> 
> After successful provisioning:
> 
> An **Enable** or **Disable** **toggle** appears, enabling Account Managers to control SCIM provisioning status.
> 
> ![SCIM_ENABLED.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SCIM_ENABLED.png)

#### **What to expect after SCIM is enabled?**

Once SCIM provisioning is enabled:

- Users can be **added or managed directly from the Identity Provider (****IdP****)**.
- User accounts are automatically provisioned in Whatfix based on IdP configuration.
- Users marked inactive in the IdP, can no longer access the Whatfix dashboard.
- Newly provisioned users are assigned the **Translator** role by default.
- Manual invitations from Whatfix are no longer possible, as IdP is the only source of truth.

An Identity Provider (IdP) is an authority system that holds and verifies the user authentication information. Whatfix interacts with your IdP and trusts the information provided by the IdP to gain access to the application. Whatfix supports the following identity providers: Okta, Azure Active Directory, or any identity provider compliant with SAML 2.0 that works with Whatfix SSO.

The Whatfix Dashboard is where you can perform the following actions:

- Access all content that has been created by users in your organization.
- Access and manage content widgets like Self Help, Pop-ups, Smart tips, Beacons, and Task List
- Manage users
- Manage tags
- Access Analytics
- Manage translations
- Manage Tip or Flow configurations
