Skip to content
English
  • There are no suggestions because the search field is empty.

How do I set up automatic user provisioning (SCIM)?

SCIM lets your IT team manage Welbi access for your employees automatically from your own identity provider, instead of inviting and updating users one at a time. When someone joins, changes roles, or leaves, that change flows into Welbi for you, so employees are already set up correctly before they ever sign in.

This was designed for larger organizations with many employees and a central IT team who want one place to manage access and less manual account upkeep in Welbi.

SCIM and SSO work together

SCIM and Single Sign-On (SSO) solve two different halves of the same problem, and they are strongest when used together:

  • SSO gets your employees in. It confirms who an employee is and lets them sign in with your company login.
  • SCIM gets them ready. It creates the employee's Welbi account, gives them the right community access, assigns the correct Welbi role (such as Welbi Admin or Team Member - Enhanced), and updates or removes access when things change.

A simple way to think about it: SSO answers "is this really you?", and SCIM answers "what should already be set up for you in Welbi?"

What SCIM manages for you

Once connected, SCIM can:

  • create Welbi accounts for your employees,
  • set which communities each employee can access,
  • assign the correct Welbi role, and
  • update or remove access automatically when an employee's role changes or they leave.

Before you set up: Business Units

Community access is determined by matching your identity provider's groups to your communities in Welbi, using a label called a Business Unit. A Business Unit is simply how a given community is named in your organization's structure.

For SCIM to send each employee to the right communities, every community must have the correct Business Unit name set in Welbi before setup begins. Your Welbi Customer Success representative will help you confirm these before you start.

How setup works

  1. Let your Welbi Customer Success representative know you would like to move to SCIM.
  2. Welbi provides you with a secure SCIM token and a setup guide for your IT team.
  3. Your IT team uses the token and guide to connect your identity provider to Welbi and to map your groups to the right roles and communities.
  4. Welbi helps you confirm your Business Unit details so access lands in the right place.

The setup guide is written for a non-technical IT administrator and is designed to be completed in about two hours. Your Customer Success representative can walk through it with you if you would like.

What your employees experience

Employees do not need to do anything differently. They sign in through SSO as usual, and their Welbi access is already in place and up to date, based on the information your IT team manages. When your IT team makes a change, it takes effect in Welbi after the next scheduled sync (roughly every 40 minutes).

A few common questions

  • Is SCIM the same as SSO? No. SSO lets employees sign in; SCIM sets them up correctly in Welbi. They work best together.
  • Who handles the setup? Your IT team, using the token and guide Welbi provides. Welbi helps with the Business Unit details and is available if you have questions.
  • Do changes happen instantly? No. Welbi receives updates on a schedule, about every 40 minutes.