Automating user provisioning with SCIM

System for Cross-domain Identity Management (SCIM) v2 is a standard protocol for automating user provisioning. Roam supports SCIM 2.0 to allow enterprise identity providers (IdPs) like Okta to seamlessly create, update, deactivate, and synchronize user accounts in Roam.

Learn about Roam’s support for SCIM in the Roam Developer Documentation.

Automatic Office Assignment for New Members

Members provisioned using SCIM will be assigned an office using automatic seat assignment. If you’d prefer to seat someone elsewhere after this automatic assignment, you can manually unassign their seat and assign a different office.

Managing SCIM-Provisioned Members

Members your identity provider manages show “SCIM” in the “Managed By” column in Settings > Roam Administration > Members, and you cannot delete them directly in Roam. To remove one, deprovision or remove the user in your identity provider. This change will then sync to Roam, and the member will be removed automatically.

A member becomes SCIM-managed both when your identity provider creates them in Roam and when it updates an existing Roam member — including someone an admin added by hand — with that member’s external ID. If you roll out SCIM after already using Roam, expect existing members to start showing as SCIM-managed as your identity provider matches them.

A member already managed by another HR system, such as Rippling, will not be taken over by SCIM. Disconnect that integration first, then have your identity provider sync.

If you stop using SCIM, members provisioned through it stay marked as SCIM-managed. Contact Roam support to release them so you can manage them yourself.

Email Address Changes

When your identity provider updates a member’s email address, Roam applies the change and emails the member at their previous address (copying the new one) with the subject “Roam Account - Email Address Update - Action Required”. The member will need to sign out of Roam on all their devices, including web browsers, and sign back in with their new email address. Their chat history and Roamaniac status carry over.

If the member tries to sign in with their old address, Roam tells them their email was changed by an administrator and points them at that message. This notice appears for two weeks after the change, so make sure the member switches to their new address within that window. If single sign-on is enabled for that domain, signing in with the old address continues through your identity provider as usual and this notice does not appear.