Provisioning
Directory sync (SCIM) lets your identity provider create and remove organization members automatically. When someone is disabled in your directory, Reflex ends their organization membership and active sessions as part of deprovisioning.
Use SCIM when your organization manages workforce access centrally and needs account changes in Reflex to follow the same lifecycle.
Configure directory sync
Open Provisioning in the organization sidebar. The page provides:
- A SCIM base URL to copy into your identity provider.
- A Tokens section for credentials used by the directory connection.
To create a token:
- Enter a name that identifies the connection, such as
Okta production. - Select Create token.
- Copy the token immediately. Reflex will not show it again.
- Add the displayed SCIM base URL and token to your identity provider.
- Test with a small, approved group before rolling it out to the organization.
The token list shows each token's name, prefix, creation date, and last-used information so admins can identify active connections.
Revoke a token
Revoke a provisioning token when you rotate credentials, replace a connection, or suspect exposure. The identity provider immediately stops being able to provision or deprovision members with that token. Existing members keep their access.
Groups and project access
Directory groups synced through SCIM appear as teams in Reflex. Group membership controls who belongs to the team, while project access remains under your control in Reflex.
Open a project's Members page and assign a role to the synced team. Current and future group members inherit that role.
Teams created manually in Reflex are not managed by the identity provider. If the identity provider deletes a synced group, Reflex removes its team and project-role assignments.
A synced team's project role can also be granted through the API, so that onboarding somebody is nothing more than a directory add. See Automated provisioning for that flow end to end, including the credential a provisioning system should run as.
Related
- Automated provisioning — wire directory sync, permissions, and placement together.
- Members & seats — understand membership and seats.
- Teams — grant project access to groups.
- Single sign-on (SSO) — authenticate through your identity provider.
- Audit logs — review administrative activity.