Custom SCIM integration development
Appfront builds SCIM integrations: the open standard that allows identity platforms to automatically create, update and delete users and groups in other applications. For organisations, this means new employees get access automatically, and leavers lose it on time. For software vendors, it means your application communicates with each customer's identity platform in the same way. We build the SCIM side of your application, or the integration with an application that cannot yet support it.
What is a SCIM integration?
SCIM, System for Cross-domain Identity Management, is an open standard for automatically managing users and groups across systems. An identity platform, such as an employer's, uses SCIM to tell an application who needs an account, which details have changed, which groups someone belongs to, and who should be deactivated. Many identity platforms and business applications support SCIM.
An application without SCIM is maintained by hand: an administrator creates accounts and forgets to remove them when someone leaves. For a software vendor, this means every business customer asks how users can be managed automatically, and every answer is custom work. Larger customers often make it a procurement requirement.
We build custom solutions because applications differ: how users, roles and permissions are structured, which identity platforms your customers or your organisation use, and how groups must be mapped to permissions. The standard is fixed; we make sure your application works with it and is tested against the platforms that matter.
Automatic on and off
Users created, updated and deactivated from the identity platform, without an administrator.
Groups become permissions
Groups from the identity platform translated into roles and permissions in your application.
One standard for everyone
A single SCIM interface that every customer with a supported platform can connect to.
How we build your SCIM integration
We start with your application: how users and permissions are structured, which platforms need to connect, and how things work today. Often users are currently invited by email or created by a customer administrator. That route remains available for customers without SCIM, so the integration does not exclude anyone.
Your user model, roles, permissions and the identity platforms that matter.
Users and groups according to the standard, with security and mapping to permissions.
Testing with the identity platforms your customers or organisation use.
Documentation for customers, a log for every action, and maintenance during updates.
What a SCIM integration actually does
The components below come up in almost every SCIM integration. Which ones you need depends on your application.
Users
Creating, updating, deactivating and deleting.
Groups
Groups and memberships from the identity platform.
Permissions
Groups mapped to roles and permissions.
Security
Access to the interface using tokens per customer.
Testing
Tested with the common identity platforms.
Audit log
What was done for each action, and by which platform.
Who we build SCIM integrations for
The integration is intended for those who want to manage users automatically.
Software suppliers
Business customers who ask for SCIM. A single interface is the core.
Organisations with their own apps
Your own applications alongside packaged software. Automatic deactivation on departure matters most.
IT departments
Applications without SCIM. An integration in between is what is needed.
Platforms with many customers
Many environments per customer. Separation per customer is the core.
Technology and integrations
This page is about SCIM integrations. For a Tools4ever identity platform, see our page on a HelloID integration; for Microsoft, our page on an Azure AD integration; and for custom identity and access management, our page on an IAM system. You can read about our approach at software laten maken.
Why choose Appfront for your SCIM integration?
An account that outlives an employee's departure is a risk, and a customer who walks away because of it is lost revenue. That's what we build around: users switched on and off automatically, permissions derived from groups, and one standard for everyone.
No manual work
Administrators no longer have to maintain accounts by hand.
Secure on departure
Anyone who leaves loses access immediately.
Procurement requirement met
Customers who ask for SCIM can connect.
Security and privacy in a SCIM integration
The SCIM interface controls who has access to your application. It is secured with tokens per customer or environment, grants access only to user management, and every action is logged.
The integration runs in your application's environment, with encrypted connections and storage, and daily backups.
Frequently asked questions about an SCIM integration
Questions software vendors and IT departments ask before getting started.
System for Cross-domain Identity Management is an open standard for automatically managing users and groups across systems. Through SCIM, an identity platform tells you who should get an account, what has changed, and who should be deactivated.
Because they don't want to manage users by hand in every application, and because an account that outlives an employee's departure is a risk. For many larger customers, it is a procurement requirement.
For each customer or environment, you define which group from the identity platform gets which role in your application. If someone's group changes, their permissions change with it. A customer can manage that mapping themselves in your application's settings, so your own support team isn't needed.
Those that support SCIM. Since they don't all implement the standard in exactly the same way, we test with the platforms that matter to your customers or organisation.
The identity platform sends a deactivation, and the user loses access immediately. Whether the account is then deleted or retained is something you define, for example because that user's data is still needed. Every creation, change and deactivation is logged, so that during an audit a client can see who had access and when.
Yes, with an integration that speaks SCIM on one side and the application's interface on the other. This way, an application without SCIM can also be managed automatically.
Software vendors with business customers who need automated user management, and organisations with in-house applications that need to connect to their identity platform.
Users who switch on and off automatically?
Tell us how users and permissions are structured in your application and which identity platforms need to connect. We'll show you what the integration will look like.