Configuring SCIM Provisioning and Identity Role Mapping

Open Settings > Authentication. This area requires Full Access and Manage Settings.

SCIM connects an identity provider's user-provisioning workflow to CaseWyze. It is separate from SSO sign-in.

SCIM configuration

  1. Open the SCIM section and review whether provisioning is enabled.
  2. Use the displayed SCIM Endpoint URL in your identity provider.
  3. Generate a token through the provided control and store it securely when displayed.
  4. Configure the provider with that token, then test provisioning with a controlled user.
  5. Check the provisioning status, user counts, and activity logs.

Replacing or revoking a token can stop the provider's connection until its configuration is updated. Do not put the token in an article, email, or screenshot.

Role Mapping

Select Add Role Mapping. Enter the IdP Group Name, choose the Application Role, and set the Priority used to resolve mappings. Verify the resulting role for a test user, especially when the person belongs to multiple groups.

Activity Logs

SCIM Activity Logs records provisioning activity and failures. Review these when a user is not created, updated, or deprovisioned as expected. The status cards distinguish users provisioned from users deprovisioned.

Identity-provider membership and CaseWyze record scope must both be appropriate. Provisioning an account does not automatically assign it to every case.