Control objective
The System for Cross-domain Identity Management (SCIM) standard defines HTTP-based schemas and operations for managing users and groups across systems. Provisioning creates and updates local account state. Deprovisioning disables or removes it. These are lifecycle operations, not authentication ceremonies.
Provisioning flow
An identity source or lifecycle system calls the service provider's SCIM endpoint with authorized requests. The provider maps stable identifiers, validates schemas, applies create, replace, patch, delete, and group membership operations, and returns protocol results. The system must handle retries and out-of-order change safely.
Federation is separate
OpenID Connect or SAML can authenticate a user without creating every application record. SCIM can create an account without authenticating its user. Keep account status, federation subject mapping, group state, application permission, and session state connected but distinct.
Failure and residual risk
Duplicate identifiers can create or link the wrong account. Partial updates can leave stale groups. A disabled SCIM record might not terminate active sessions. Delete and recreate operations can change identifiers. Broad SCIM credentials can modify many accounts.
Pomerium boundary
Pomerium uses federated authentication and route policy. It does not replace application provisioning. If route policy depends on directory groups, operators must understand how those groups are sourced, refreshed, and revoked. Applications can still need SCIM or another lifecycle process for local accounts.
Evaluation checklist
- Which stable identifier joins the source and service-provider account?
- Are create, update, disable, delete, retry, and out-of-order cases tested?
- Does deprovisioning terminate or invalidate relevant sessions and permissions?
- Are SCIM credentials narrowly scoped, rotated, and audited?
- Is provisioning kept separate from authentication and authorization decisions?
