Synchronize workspace users, groups, roles, and offboarding.
Users and Groups support create, read, replace, patch, delete, and membership updates. Use userName (normally work email) for user identity and displayName for groups.
Map each User's roles attribute to admin, security_admin, billing_admin, editor, or viewer. Unsupported or unmapped values become viewer. Groups synchronize as governance principals; workspace roles belong to User resources. SCIM cannot grant or deactivate the owner role.
Setting active to false removes non-owner membership and revokes active agent sessions, personal API tokens, and per-user connector credentials. Deletion cuts off the same access and retains a disabled directory record for audit continuity.
Keep one provisioning token per provider connection. Rotation in Workspace settings replaces and immediately revokes the previous token.
scimType for invalid filters, paths, or values.