Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

All integrations
S2
PLATFORM·Beta

SCIM 2.0

Standards-based offboarding ingest. When your HRIS or IDP fires a SCIM termination event, ScopeMantle cascades a revoke across every connected source for that user.

WHAT IT DOES

What ScopeMantle can do with SCIM 2.0.

  • Receive standards-compliant SCIM 2.0 termination events from any HRIS or IDP that speaks SCIM
  • On a SCIM `DELETE /Users/{id}` event, automatically revoke every OAuth grant that user holds across every connected source
  • Compile a confirmation report listing every grant revoked, the source it was revoked on, and the time-to-revoke for each
  • Emit a single audit log entry per cascade with the upstream SCIM event correlation ID
  • Run dry-run mode for the first 30 days of any new HRIS connection so you can verify before enabling cascade

LEAST PRIVILEGE

What we read, and what we don't.

We read
  • scim:Users (write)Receive lifecycle operations from your HRIS/IDP. ScopeMantle does not push directory data back upstream.
We never
  • Read mailbox, calendar, or document content on the user being deprovisioned, only the user identifier and lifecycle state are consumed
  • Take cascade actions in any source the tenant has not explicitly connected
  • Cross tenant boundaries, every SCIM endpoint is scoped to a single tenant and bearer-token authenticated
  • Modify your HRIS, communication is one-way HRIS → ScopeMantle on this surface

SETUP

Connect in a few steps.

  1. 01

    Generate the SCIM endpoint URL and bearer token

    In tenant settings, open Settings → Integrations → SCIM → Generate endpoint. ScopeMantle returns a unique HTTPS URL and a rotating bearer token specific to this tenant.

  2. 02

    Wire the endpoint into your HRIS or IDP

    Paste the URL and bearer token into your HRIS provisioning settings (BambooHR, Rippling, Workday, HiBob), or your IDP's SCIM provisioning panel (Okta, Microsoft Entra). Map your `externalId` to the corresponding ScopeMantle user.

  3. 03

    Run dry-run for the first 30 days

    By default new SCIM connections run in dry-run mode. ScopeMantle records every cascade that would have fired without taking action. Review the dry-run report and enable enforcement when comfortable.

  4. 04

    Enable enforcement and monitor

    Switch the connection to enforcing. Each cascade produces a confirmation report email to the tenant's compliance contact and an immutable audit row. The cascade itself completes within 60 seconds for most users.

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.