Skip to main content

How to set up SCIM integration in Sally AI

SCIM (System for Cross-domain Identity Management) lets you automatically connect Sally with your Identity Provider (IdP). This way, users and groups are always kept in sync without manual updates.

Quick navigation

  1. What is SCIM and why use it with Sally AI?
  2. How do I set up SCIM in Sally AI?
  3. Where do I enter SCIM credentials in my IdP?
  4. What is the final configuration step in Sally?
  5. FAQ: SCIM in Sally

1. What is SCIM and why use it with Sally AI?

SCIM is an open standard for user and group provisioning. It allows you to automatically transfer account information from your Identity Provider to Sally.

Instead of manually creating, updating, or removing users, SCIM ensures that:

  • New employees get access to Sally immediately.
  • Existing user details stay up to date.
  • Users who leave your company lose access automatically.

By connecting once through SCIM, your IdP becomes the single source of truth. Groups and licenses can still be managed centrally in your IdP, while Sally always reflects the latest state. That means less admin work, fewer mistakes and consistent access for your team.


2. How do I set up SCIM in Sally AI?

  1. Open Settings at the bottom of the left sidebar.
Sally calendar view with the Settings entry highlighted at the bottom left of the sidebar
Figure 1: Open Settings
  1. Under Administration, open User Administration.
  2. Click SCIM integration above the member list on the right.
User Administration with the SCIM integration button in the top right highlighted
Figure 2: Open the SCIM setup
  1. The Connect SCIM integration panel opens on the right. Pick your system under Identity provider and click Set up SCIM, or Cancel to stop.
Connect SCIM integration panel with the identity provider selection and the Set up SCIM button
Figure 3: Choose the identity provider and start the setup
Available integrations
  • Microsoft Entra (Azure AD)
  • Google Workspace
  • Okta
  • OneLogin
  • PingOne
  1. Sally creates the credentials and opens SCIM management: Identity provider. Under Credentials you get the SCIM tenant URL and the Bearer token, each with an icon to copy it. Copy both, you need them in your identity provider in the next step.
SCIM management panel with the SCIM tenant URL and Bearer token credentials highlighted
Figure 4: Copy the SCIM tenant URL and the Bearer token
Continue in your IdP

Now it's time to enter these credentials in your Identity Provider.
Jump directly to the instructions for your tool:


3. Where do I enter SCIM credentials in my IdP?

Until this step is done, groups won't appear in Sally, since the IdP hasn't started syncing yet.

3.1 Microsoft Entra (Azure AD)

Follow these steps to connect Sally via SCIM in Microsoft Entra:

  1. In the Azure portal, go to "Enterprise Applications" and click on "+ New application".
Create new application
Figure 5: Create a new Enterprise Application
  1. Select "Create your own application".
Create your own application
Figure 6: Start creating your own application
  1. Give the app a name (e.g., Sally AI SCIM Integration) and choose "Integrate any other application you don't find in the gallery (Non-gallery)". Then click Create.
Name the application
Figure 7: Name the application and select non-gallery integration
  1. Once the application is created, open it and go to Provisioning.
Microsoft Entra enterprise application with the Provisioning menu opened
Figure 8: Navigate to the Provisioning menu
  1. Click on "+ New configuration".
Add new configuration
Figure 9: Start a new provisioning configuration
  1. In the new configuration screen, enter the Tenant URL and Secret Token you copied from Sally. Click "Test connection" and then Create.
Enter Tenant URL and Token
Figure 10: Add credentials from Sally and test the connection
  1. After the configuration is created, you can now assign groups to this profile.
Note

Only groups are supported for provisioning to Sally, not single users.

  1. Finally, start the provisioning by clicking on "Start provisioning".
Microsoft Entra provisioning page with the 'Start provisioning' button highlighted
Figure 11: Enable provisioning to start syncing groups to Sally
  1. After provisioning has started, return to Sally and complete the setup by assigning the correct groups and licenses. You can find the detailed instructions in Final step in Sally.

3.2 Google Workspace

  1. Open Admin Console → Apps → Web and mobile apps.
  2. Add a new custom SCIM app.
  3. Enter Tenant URL and Token.
  4. Assign groups for provisioning.
  5. After provisioning has started, return to Sally and complete the setup by assigning the correct groups and licenses. You can find the detailed instructions in Final step in Sally.

3.3 Okta

  1. Go to Applications → select your Sally app.
  2. Open Provisioning tab.
  3. Enter Tenant URL and Token.
  4. Enable provisioning features (create, update, deactivate users).
  5. After provisioning has started, return to Sally and complete the setup by assigning the correct groups and licenses. You can find the detailed instructions in Final step in Sally.

3.4 OneLogin

  1. Navigate to Apps → SCIM Provisioning.
  2. Paste Sally's Tenant URL and Token.
  3. Map groups and save.
  4. After provisioning has started, return to Sally and complete the setup by assigning the correct groups and licenses. You can find the detailed instructions in Final step in Sally.

3.5 PingOne

  1. Go to Connections → Provisioning.
  2. Add a new SCIM connection.
  3. Provide Tenant URL and Token.
  4. Test and activate.
  5. After provisioning has started, return to Sally and complete the setup by assigning the correct groups and licenses. You can find the detailed instructions in Final step in Sally.

4. What is the final configuration step in Sally?

After you have added the Tenant URL and Token to your Identity Provider and started the provisioning, the connection between your IdP and Sally is live.

What is left is to finish the setup in Sally and say which groups and licenses count. Users coming from your IdP then get the right role and license on their own.

Sally lets you assign multiple IdP groups per role and per license tier. You don't have to merge everything into one big umbrella group: you can map several groups from your IdP to the same category and even combine categories (for example, the same group can activate users as standard users and grant them a Pro license).

Follow these steps:

  1. Open User Administration and click Manage SCIM in the top right corner. That is what the button is called once SCIM is set up.
  2. Under Active users + admin role, map your IdP groups to Sally roles:
Info
  • Active Sally user group → Select one or more groups whose members should get access as standard users.
  • Admin group → Select one or more groups whose members should have administrator rights in Sally.
  1. Under License assignment, link IdP groups to the Starter license, the Pro license, or the Enterprise license. You can pick multiple groups per license tier, so membership in any of them controls which license users receive in Sally.
SCIM management panel with the sections for active users plus admin role and license assignment
Figure 12: Map groups to roles and licenses
Important

If the selected groups combined contain more users than the number of available licenses, Sally will automatically purchase additional licenses.
These licenses are billed immediately, so make sure your group sizes align with your subscription plan.

  1. Scroll further down the panel to the Behavior section. Send welcome email on creation decides whether Sally sends newly provisioned users a welcome email.
  2. SCIM sync active lets you pause the connection to your identity provider without resetting the token.
  3. Click Save to apply the configuration. As the note at the top of the panel says, saving also applies the changes to existing memberships.
Lower part of the panel with the Behavior section, the welcome email and SCIM sync switches, and the Save button
Figure 13: The Behavior section and the Save button
No groups showing yet?

As long as no groups have arrived from your identity provider, every field reads: "No teams in this organization. Create a team first or wait for the next SCIM group sync from your IdP."

  1. After saving, all members provisioned via SCIM will appear in your user list in Sally.
User Administration with three new members in the Invited status and without a license
Figure 14: New members in the list, still without a name and a license

The new people show up without a name at first, with Invited in the Status column and None under License. Name and license fill in once someone accepts the invitation.

Recommendation: How to structure your groups

Because Sally supports multiple groups per category, you don't need one oversized group for the whole company. A few patterns that work well in practice:

  • Group by department or team: Keep separate IdP groups for Sales, Marketing, Support, etc. Assign all of them as Active Sally user group and, if they all use the same license, also as the matching license group. Adding a new team later is just a new group, not a new configuration.
  • Use a dedicated admin group: Keep Sally admins in a small, focused group (e.g. Sally Admins or IT Leads). Members of that group get admin rights on top of their regular user role.
  • Model license tiers as explicit groups: Create IdP groups like Sally Starter, Sally Pro, Sally Enterprise. Upgrading a user is then a single membership change in your IdP, with no changes needed in Sally.
  • Combine both approaches: Use departmental groups to control who gets access, and a smaller tier group (e.g. Sally Pro) on top to upgrade selected power users to a higher license.

The more granular your groups, the easier it is to change access or licenses later, entirely from within your IdP.

5. FAQ: SCIM in Sally

5.1 What happens if there are more users in a group than available licenses?

If the groups assigned to a license tier contain, in total, more users than you currently have licenses for, Sally will automatically purchase additional licenses.
These licenses are billed immediately to ensure all users get access.


5.2 How does license priority work if a user is in multiple groups?

When a user belongs to multiple SCIM license groups, Sally will always assign the lowest license tier. For example: if a user is in both the Starter group and the Pro group, the user will only receive a Starter license.


5.3 Can I assign single users instead of groups?

No. SCIM provisioning in Sally works exclusively with groups from your Identity Provider.
This ensures consistency and avoids manual exceptions.


5.4 Do I need to reconfigure SCIM if new groups are added in my IdP?

No. As long as SCIM is active, any new groups created in your Identity Provider can be added directly in Sally under Active users + admin role or License assignment without restarting the setup. You can map as many groups as you need per category, so new teams or license tiers only require picking them in the multi-select.


5.5 How often does the sync run?

Provisioning runs automatically in cycles (based on your IdP's schedule). In Microsoft Entra, for example, provisioning typically runs every 40 minutes.
Changes in your IdP (like adding or removing users) will appear in Sally after the next sync.


5.6 Can I disable SCIM once it's active?

Yes, and there are two ways to do it, both in the SCIM management panel:

  • Switch off SCIM sync active in the Behavior section. That pauses the connection while the token stays in place.
  • Use Disconnect at the bottom of the panel. That deletes the provider, the token, and all group mappings.

Already provisioned users remain in Sally in both cases until you remove them manually. After disconnecting, your identity provider no longer controls status changes in Sally.