Skip to content
Docs
foxborne.comRequest a pilot

SCIM provisioning

Keep Foxborne's member list in step with your identity provider. With SCIM on, adding someone to a Foxborne group adds them here, and removing them upstream removes them within five minutes.

How-toMarkdown
On this page9

Offboarding should happen once, in the directory your organization already trusts. With SCIM on, Foxborne follows your identity provider: removing someone there removes them here within five minutes. Five groups in the identity provider line up with Foxborne's five roles.

Before you start#

  • You need the Admin role. Only admins hold Manage hosting, keys and access.
  • Single sign-on is set up with your identity provider.
  • You can create groups in your identity provider and change who belongs to them.

Read the Provisioning panel#

Go to Access and open the Sign-in tab. The Provisioning panel carries the chip SCIM on and two rows.

RowWhat it shows
Last syncWhen Foxborne last synchronized with your identity provider, as a relative time
Groupsfoxborne-admins, foxborne-investigators, foxborne-reviewers, foxborne-viewers and foxborne-auditors

The panel has nothing to edit. Group membership lives in your identity provider, and Foxborne follows it.

Groups and roles#

The five group names match the five roles one to one.

Group in your identity providerRole in Foxborne
foxborne-adminsAdmin
foxborne-investigatorsInvestigator
foxborne-reviewersReviewer
foxborne-viewersViewer
foxborne-auditorsAuditor

Roles and permissions lists what each role may do.

Provision people#

  1. Create the five groups

    In your identity provider, create the five groups. Use the names exactly as the Provisioning panel lists them.

  2. Add people to their group

    Add each person to the group for the role they need. With SCIM on, this does the same job as Invite in the console. The Invite someone dialog says so: With SCIM on, adding them to a Foxborne group in the identity provider also works.

    Assign the same groups to the Foxborne SAML application, so their members can sign in.

  3. Check the sync

    On Access, Sign-in, Last sync shows when Foxborne last synchronized. The audit log records each sync as Synced users on SCIM, by System, with a detail such as 9 users, 5 groups, no changes.

  4. Check the members

    Open the Members tab. Each person appears with the role their group matches and Single sign-on under Sign-in. The note under the table reads Removing someone in the identity provider removes them here within five minutes.

Remove someone#

Remove the person in your identity provider. Foxborne removes them within five minutes, with no second list to clean up.

Their audit entries stay. The audit log is append-only and never deleted, so every action they took remains attributed to them.

For an immediate cut-off, also use Remove access on Members: They lose access at once. See Remove access.

SCIM and the console#

The same three tasks can start in either place.

TaskIn your identity providerIn the console
Add someoneAdd them to a Foxborne groupInvite
Change a roleMove them to the matching groupChange role, which takes effect on their next request
Remove someoneRemove them, and Foxborne follows within five minutesRemove access, which cuts access at once

With SCIM on, keep the identity provider as the record: a change made only in the console leaves the two lists apart.

Check the result#

  • Last sync shows a recent time.
  • The audit log has a recent Synced users entry. Type SCIM in Filter by person, action or object to find it.
  • The Members table matches the membership of the five groups.

Troubleshoot#

A new person is missing from Members. Check that they belong to one of the five groups, spelled exactly as the panel shows it. Then check Last sync and the latest Synced users entry, or invite them from the console with Invite.

Someone removed upstream is still listed after five minutes. Look for a recent Synced users entry in the audit log. Use Remove access to stop their access at once while you find out why.

A person holds the wrong role. Compare the Role column on Members with the Foxborne group that holds them in your identity provider. The group names match the roles.

Next#