Skip to Content
Support StaffSSO and SCIM

SSO and SCIM Playbook

Use this playbook when enterprise customers report SSO login failures, SCIM user mismatch, missing members, duplicate users, or token rotation issues.

SSO checks

Confirm tenant ID, identity provider status, SAML metadata, callback URL, entity ID, signing certificate status, domain policy, and the user email involved. Ask for the identity provider error text when available.

SCIM checks

Confirm SCIM token status, last provisioning event, user external ID, email normalization, active state, role mapping, and whether the identity provider sent create, update, deactivate, or group events.

Token lifecycle

SCIM token creation and revocation are high-risk actions. They require step-up authentication, audit logging, and approval when policy requires it. Never reveal token values after creation.

Customer reply shape

Ask for the identity provider, affected user email, approximate time, and error text. Explain what configuration area is being checked without exposing token values, internal logs, or private metadata.

Escalation triggers

Escalate repeated provisioning failure, owner lockout caused by identity policy, suspected unauthorized identity provider changes, or any request to bypass SSO controls.