Skip to main content

User Provisioning with SCIM

How SCIM handles adding, updating, and removing Camphouse users automatically when your organization manages staff through an identity provider like Okta or Azure AD.

Written by Micaela Rosling Caesar

What is SCIM?

Many organizations manage their staff centrally in a tool like Okta or Azure AD. SCIM is the industry standard that lets that system talk directly to Camphouse, so when someone joins, leaves, or changes role in your company's IT system, their Camphouse account updates automatically, without an admin having to log in and repeat the change by hand.

Behind the scenes, SCIM doesn't follow its own separate set of rules. It uses the same process a Camphouse admin would trigger manually, it just proves that the request is coming from a trusted company system rather than a person logged into the app.

⚠️ Camphouse doesn't keep a record of whether an account was created manually or through SCIM. It's only used in the moment to process the request, not stored for later reference.


Setting up SCIM

To connect SCIM to your identity provider, reach out to your Customer Success Manager.


What SCIM sets automatically, and what still needs a manual step

Most user settings in Camphouse can be managed automatically. SCIM itself, however, only covers part of that. Here's what happens on its own, and what an admin still needs to set up by hand afterwards.

Organization access: Which organization or subsidiary a user belongs to is fully handled by SCIM. When your IT system adds, removes, or moves someone, their Camphouse access changes automatically.

Role (Administrator, Editor, Contributor, Viewer): SCIM does not set a user's role. Every account created or updated through SCIM automatically gets the most limited role, Viewer. An admin needs to go in and change it manually if the person needs more access.

Teams: SCIM has no concept of teams, so team membership always has to be set manually in Camphouse, no matter how the account was created.

Restricted fields: Not something SCIM touches. An admin needs to set this up manually for the person or their team.

Protected tags: Also not set by SCIM. Any protected tag access someone needs has to be granted manually.


What this means for a new employee added through your IT system

When someone is added in your company's IT system, they'll automatically get a Camphouse account in the right organization. From there, an admin still needs to:

  • Promote them to the right role (Editor, Contributor, or Admin) if Viewer isn't enough.

  • Add them to the right team(s).

  • Grant any protected tag access they need.

💡 Read User roles in Camphouse to learn what each role can do, and Managing Team Permissions for how to set up teams, restricted fields, and protected tags.

Did this answer your question?