Who can use this feature?
- Organization administrators
- Customers with SSO
When users are added to the platform via system for cross-domain identity management (SCIM), an organization administrator must assign them to appropriate user group(s) so they can access the platform.
On this page:
- Automatically assign users to groups and roles
- Set up security group mappings
- Basic concepts of SCIM auto-provisioning
Automatically assign users to groups and roles
As an Organization Administrator, you can automate SCIM-driven user provisioning and role management. Connect your Identity Provider (such as Okta or Microsoft Entra ID) to the platform via SCIM 2.0, and then map IdP groups directly to platform roles and security groups. When group memberships are pushed from the IdP, the platform automatically reconciles user access, thus eliminating manual, per-user permission management.
Note: You can automatically assign users to platform roles, workspaces, and digital assets, based on their Identity Provider (IdP) groups using SCIM 2.0. Once configured, any user assigned to an IdP group automatically receives the corresponding access levels across your organization’s workspaces and digital assets.
Recompute access
The platform can re-evaluate data previously pushed from your IdP. It does not fetch new data. To obtain fresh updates, initiate a sync directly from your IdP.
To recompute access:
- Navigate to the organizational level.
- Under Manage, select Organization settings → Users → Group Mappings.
- Select Recompute access.
Set up security group mappings
Step 1: Set up and provision users via SCIM
Set up your platform organizational hierarchy (add workspaces and digital assets).
Create and configure your user groups within your Identity Provider.
Configure your IdP to push users and groups to the platform's SCIM 2.0 endpoint.
We provide full SCIM v2 Groups API support (GET, POST, PUT, PATCH, DELETE).
The following endpoints are available:
GET /Groups: — List groupsPOST /Groups— Create a groupGET /Groups/{id}— Retrieve a groupPUT /Groups/{id}— Replace a groupPATCH /Groups/{id}— Update a groupDELETE /Groups/{id}— Delete a group
For details, contact your IT administrator.
Step 2: Create or remove group mappings
You can create or remove a group mapping manually.
Note: You can map only those groups that are already synced from your IdP. If a group is missing, check your SCIM provisioning settings. A group is mapped to a role within a specific scope. The same scope cannot appear twice in a single mapping.
To create a group mapping:
- Navigate to the organizational level.
- Under Manage, select Organization settings → Users → Group mappings.
Select +Create Mapping. The dropdown list contains only the groups that are already synced from your IdP. If a group is missing, check your SCIM provisioning settings.
Choose the IdP Group you wish to map.
-
Under Target Access Mapping, select workspaces and digital assets and assign them to groups:
Under Browse and select targets, search for and select workspaces and digital assets.
Under Selected targets, search for and select a workspace or digital asset you want to map. For each of them, select the permission from the Group dropdown.
Under Custom group, select a ready-to-use group with predefined access to specific workspaces and digital assets.
Select Save changes.
To remove a group mapping:
- Under Manage, select Organization settings → Users → Group Mappings.
Select +Create Mapping.
Under Target and Access Mapping → Selected targets, select the X button for each workspace or digital asset mapping you want to remove from the group.
Step 3: Manage Unassigned users
A user might be provisioned via SCIM, but not belong to any mapped IdP group. Such users are listed on the Unassigned users tab and can be assigned manually.
Note: If you’re assigning multiple users at once, they must belong to the same user group. You can’t assign multiple users to different user groups at the same time. SCIM auto-assignment operates alongside manual assignments. Manually granted permissions remain untouched during automated reconciliations.
To manage unassigned users manually:
- Under Manage, select Organization settings, and then Users.
- Select Unassigned users.
Note: The tab is available only if the SCIM is enabled.
- Choose the user(s) you want to assign.
- Select Assign users.
- Choose the group(s) you want to add the users to.
- Review the users and make changes if needed.
- Select Assign users. The user(s) will receive a welcome email from Level Access.
Basic concepts of SCIM auto-provisioning
The following table describes how the platform hierarchy and access roles interact. Learn these key concepts, to set up your mappings effectively.
Concept |
Description |
|---|---|
Platform hierarchy |
Platform consists of three levels of structure:
Archived workspaces or assets are treated as follows:
|
Out-of-the-box security groups |
Predefined roles that govern user permissions: • Org Admin (Organization-wide) • Workspace Admin (Scoped to a specific Workspace) • Workspace User (Scoped to a specific Workspace) • Digital Asset User (Scoped to a specific Digital Asset)
|
| Deprovisioning | When a user is removed from an IdP group, the associated SCIM-managed access is automatically revoked during the next sync. |
Mapping |
A configuration rule that links a specific IdP group to one or more platform security group instances (role + target node).
|
| Union of permissions | If a user belongs to multiple mapped IdP groups, they receive the combined access of all mapped instances. If there is a role conflict on the same asset (e.g., Workspace Admin and Workspace User), the highest privilege level applies. |
Unassigned bucket |
A holding area for provisioned SCIM users who do not match any active mapping rules, which allows administrators to assign access manually. |
Reconciliation |
The automatic background process that evaluates user group memberships and applies the appropriate platform permissions. These reconciliation triggers and synchronization events automatically recompute platform access:
|
Comments
0 comments
Article is closed for comments.