Directory sync
Connect your identity provider
Inrick speaks SCIM 2.0, so Okta, Entra or anything else that speaks it can create accounts, change what people may do and switch them off when they leave. Nobody files a ticket to join, and nobody is forgotten on their last day.
- Base URL
https://app.inrick.com/api/scim/v2- Token
- Your provider authenticates with a bearer token. Make one in Settings, Security.
Setting it up
Okta
- 1In Okta, open your Inrick app and go to Provisioning, then Configure API Integration.
- 2Tick Enable API integration, paste the base URL above, and paste your token as the API token.
- 3Test the connection, then save. Okta will read the workspace and show the people already in it.
- 4Under To App, enable Create Users, Update User Attributes and Deactivate Users.
- 5Assign the people and groups who should have Inrick. They appear in your members list within a minute or two.
- 6To let a group decide what people may do, push the group, then open Settings, Security in Inrick and choose what it grants.
Microsoft Entra ID
- 1In Entra, open Enterprise applications, your Inrick app, then Provisioning.
- 2Set Provisioning Mode to Automatic.
- 3Paste the base URL above as the Tenant URL, and your token as the Secret Token.
- 4Test Connection, then Save.
- 5Under Mappings, keep the default user attribute mappings. Inrick reads userName, emails, name and active.
- 6Set Provisioning Status to On, and assign the users and groups who should have Inrick.
What is supported
Saying a feature works when it does not is worse than saying no: your provider will use it, and the sync will fail somewhere you cannot see. So this list is honest, and /ServiceProviderConfig says the same thing to your provider.
- Users: create, read, update, replace and deactivate
- Groups: create, read, rename, membership and delete
- Filtering on userName and displayName
- Pagination with startIndex and count
- PATCH in the forms Okta and Entra actually send
- Bearer token authentication, revocable at any time
- Bulk operations: send one request per change
- Sorting: results come back oldest first
- ETags: there is no conditional request support
- Password sync: Inrick never holds your passwords
What happens, and when
Somebody is assigned
They are added to the workspace with the role you asked for, and take a seat. Their account itself is made the first time they sign in, by whichever method your workspace allows, so Inrick never holds a credential your provider issued.
Somebody leaves
Setting active to false, or sending a delete, switches them off rather than removing them. They cannot sign in and their seat is freed at once, and their tables, their runs and the record of what they spent stay attributed to them. A directory sync should not be able to rewrite a year of history.
Somebody rejoins
Assigning them again switches them back on, with everything they had. You do not need to delete anything first, and a provider that re-sends a person it deactivated is handled as a rejoining rather than as an error.
A group decides a role
Push the group, then say in Inrick what it grants. Until you do, being in it changes nothing. Your directory says who is in a group; what that group may do is set here, so nobody can grant themselves admin by creating a group.
The owner is untouchable
The workspace owner is never deactivated, removed or re-roled by a sync, whatever the directory sends. They are who pays, and a workspace whose owner cannot sign in has nobody left who can fix it.
The plan runs out of seats
Inrick answers with a message naming how many seats the plan includes, which your provider shows in its own error log. Nobody is quietly dropped, and the next sync adds them once there is room.
Questions
- Do I need single sign-on as well?
- No. They are separate and either works without the other. Most companies run both: single sign-on decides how somebody proves who they are, and directory sync decides who exists at all.
- What happens to somebody's work when they leave?
- It stays. Their tables, their runs and the ledger rows saying what they spent keep pointing at them, and an admin can still see what they did. Only their access ends.
- Can the directory make somebody an owner?
- No. The highest role a sync can grant is admin. Owner is who pays for the workspace, and it changes by a person deciding to, not by a group membership.
- Does a deactivated person still cost a seat?
- No. Their seat is freed as soon as they are switched off, so a plan with ten seats fits ten people who can actually sign in.
- Can I revoke a token?
- Yes, in Settings, Security, and it stops working at once. Nobody is removed from the workspace when you do: the sync simply stops until you make a new one.
- What if my provider is not Okta or Entra?
- Anything that speaks SCIM 2.0 with a bearer token will work. Point it at the base URL above and read /ServiceProviderConfig, which tells it exactly what is supported.