Provisioning
Creating user accounts and entitlements in target systems. Modern provisioning is automated via SCIM or vendor APIs, triggered by HR system events. Manual provisioning is the leading cause of orphaned accounts.
Automated provisioning is worth building for correctness more than for speed: a manual process creates accounts inconsistently, misses systems, and leaves no record of why an entitlement exists. SCIM covers the applications that support it well, and the residual work is always the ones that do not, which is where scripts and orphaned accounts accumulate.
See also: what is SCIM, SCIM 2.0, deprovisioning, set up SCIM provisioning recipe
Related on Start with Identity
- GlossaryOrphaned Account
An active account with no valid owner, typically left behind after someone leaves or changes roles. A common audit finding and a soft target for attackers. Orph
- GlossaryJoiner-Mover-Leaver (JML)
The three lifecycle events that drive identity changes: new hires (joiner), internal transfers (mover), and departures (leaver). JML automation is a core IGA ca
- CVESailPoint ISC connector path traversal
Identity Security Cloud connector configuration allowed path traversal. The 2025-2026 research notes that SCIM itself was quiet; provisioning risk sat in IdP an
- GlossaryABAC
Attribute-Based Access Control. Access decisions are made by evaluating attributes of the subject, resource, action, and environment against policy. Flexible bu
- GuideSCIM Provisioning Implementation Guide
A practical guide to implementing SCIM-based automated user provisioning and deprovisioning, covering the SCIM protocol, lifecycle management, vendor integratio
- ArticleTop 7 SCIM Provisioning Tools
The best SCIM provisioning tools in 2026, from Okta and Microsoft Entra to WorkOS, SSOJet, Frontegg, Auth0, and Keycloak, compared on directory sync depth, depr