Setup guide

Set up automatic provisioning (SCIM)

Last updated: September 29, 2026

Back

For company admins. With SCIM, your identity provider adds people to your Loomrail company, keeps their names up to date, and turns off their access when they leave — they're signed out at once. Set up single sign-on first; SCIM works alongside it.

1. Before you start

  • Verify your email domain in Loomrail (Settings → Company → Sign-in). People can be added only with an email on one of your verified domains.
  • Assign users, not groups: Loomrail doesn't sync groups, and roles (member / admin) are set in Loomrail.

2. Make a token in Loomrail

Settings → Company → Sign-in → Automatic provisioning (SCIM) → Make token. Copy the SCIM base URL and the token — the token is shown only once. Making a new token stops the old one; Turn off stops provisioning (existing members stay).

3. Okta

  1. In your Loomrail SAML app (or a new app), turn on SCIM provisioning in the app's General settings.
  2. Provisioning tab → Integration: SCIM connector base URL = Loomrail's SCIM base URL; Unique identifier field for users = userName; supported actions: Push New Users and Push Profile Updates; Authentication Mode: HTTP Header, with the Loomrail token as the Bearer token. Test the connector and save.
  3. Provisioning → To App: turn on Create Users, Update User Attributes and Deactivate Users.
  4. Assign people to the app — they appear in Loomrail. Unassigning or deactivating someone turns off their Loomrail access.

4. Microsoft Entra ID

  1. Enterprise applications → your Loomrail app (or a new non-gallery app) → Provisioning → set Provisioning Mode to Automatic.
  2. Tenant URL = Loomrail's SCIM base URL; Secret Token = the Loomrail token. Test Connection, then save.
  3. Mappings: turn off provisioning of groups; for users, map userName to the attribute that holds the person's work email (often userPrincipalName or mail).
  4. Assign users to the app, then turn provisioning on. Entra syncs on its own schedule (typically every 40 minutes); use Provision on demand to test one person straight away.

Automatic provisioning may need a paid Microsoft Entra ID plan on your side.

5. What each change does in Loomrail

In your directoryIn Loomrail
Assign a personA Loomrail account is created (or their existing one on your domain is used) and they join your company
Change their name or emailUpdated in Loomrail; an email change signs them out once
Deactivate or unassignAccess turned off: signed out everywhere and can't sign in any way until reactivated
ReactivateAccess back, with their data as it was
DeleteRemoved from your company and signed out; deleting the account itself is a separate admin action

Your company owner can't be turned off or removed by the directory. Every change is recorded in your company's audit log (filter: Directory sync). Google Workspace can't send SCIM to custom apps — with Google, use Add people automatically on your verified domain instead.

Questions: support@loomrail.com. See also Security.