Skip to content

SCIM Offboarding

SCIM Offboarding connects your company directory to Shiplight Cloud so that a directory user deletion or deactivation can automatically remove the matching employee's organization access.

Enterprise SSO can admit employees when they first sign in. SCIM handles offboarding: adding or enabling a directory user does not create or restore a Shiplight membership.

Before you start

  • SCIM is not enabled automatically with an Enterprise plan. Contact your Shiplight administrator to enable it for your organization, even if SSO is already enabled. Your organization owner can then connect the directory below.
  • An active organization owner must configure the directory connection.
  • Your identity administrator needs permission to configure directory provisioning for the company application.
  • Directory user emails must match the corresponding Shiplight account emails.

Shiplight uses WorkOS or Scalekit for directory setup. The Provider shown in Settings is configured by Shiplight and is shared with your organization's SSO connection. Follow the directory instructions in the portal opened from Shiplight; the portal appearance and fields depend on the provider. See WorkOS and Scalekit for how these services relate to your company IdP.

Connect your directory

  1. Switch to the intended organization and open Settings → Organization.
  2. In SCIM Offboarding, select Set up directory.
  3. Follow the portal instructions for your company directory. Your identity administrator configures the connection using the endpoint and credentials provided there.
  4. Return to Shiplight and check the directory connection. When available, select Refresh status to retrieve its current state. Confirm Ready for directory removals and an Active directory connection.

Use Manage directory provider for later configuration changes. If the setup link expires, open a new one from Settings. Keep setup links and directory credentials private.

Before rolling out, test with an ordinary member account: confirm it has access, deactivate or unassign it in the IdP so that the directory sends a removal event, then check that it appears as inactive in Shiplight Members and can no longer access the organization.

What changes when someone leaves

Directory changes can take time to appear in Shiplight. Check the Members page to confirm that the employee is inactive. An owner can also remove the member manually.

Directory event or actionShiplight behavior
A user is deleted or marked inactive, including an unassignment that produces a removal notificationThe matching active member is made inactive in that organization. A matching pending invitation is also canceled.
A user is created, enabled, or updated while activeNo account, membership, role, or access is created or restored.
A removal matches an organization ownerThe owner membership is preserved. Owners require manual offboarding.
No member or pending invitation matches the emailNo membership is changed.
The directory is deleted or disconnectedExisting members remain. Restore the directory connection to resume automated offboarding.

Matching and access scope

Removal uses the connected organization and the user's email. Matching ignores email case and leading or trailing spaces, but does not resolve aliases or previous email addresses. Keep the directory email aligned with the member's Shiplight account email.

A matching ordinary member can be removed regardless of whether they joined through SSO or an invitation. Removal revokes organization and workspace access governed by that membership, including authorization through their personal API tokens. It preserves the global Shiplight account, login methods, historical records, and memberships in other organizations. Organization-owned resources remain with the organization.

Owners should also remove the departing employee's application access in the company IdP. Handle owner access changes explicitly in Shiplight, and retain an active owner who can manage the organization.

Restore access

Re-enabling someone in the directory does not restore their Shiplight membership, and a new SSO sign-in cannot override a removal.

  1. Restore the employee's intended application access in the company IdP.
  2. As a Shiplight owner, open Settings → Members.
  3. Find the person under Inactive, select Reactivate, and confirm.

Reactivation is subject to the organization's member limit. Owners can manually remove or reactivate ordinary members whether or not SCIM is connected. A subsequent directory removal notification can remove a reactivated membership again.

Reactivation preserves the previous role. See Restoring access for member management instructions.

Current scope

SCIM Offboarding supports directory-driven access removal. It does not provision accounts or memberships, synchronize profile information, map directory groups to roles, or assign workspace seats. Shiplight does not run a full-directory reconciliation or infer removals from users missing from a directory snapshot.

The Members page shows Shiplight memberships and invitations. Directory users appear as members only after they have joined Shiplight through a supported admission flow, such as SSO.

Troubleshooting

What you seeWhat to check
No SCIM Offboarding sectionContact your Shiplight administrator to enable SCIM. An Enterprise plan or an existing SSO connection does not automatically enable it. Once enabled, an organization owner can configure it.
Connection needs attentionOpen Manage directory provider, resolve the directory configuration, then select Refresh status.
Previous directory is no longer connectedUse Set up directory to establish a directory connection again. Existing members are not automatically removed.
An employee remains active after removal in the IdPCheck that a removal notification was sent, that directory and Shiplight emails match, and that the person is a member rather than an owner. Allow time for processing; contact support if the removal remains unapplied. An owner can manually remove the member when access needs to be revoked.
A re-enabled employee cannot access ShiplightComplete the owner reactivation steps above. Directory activation alone does not restore membership.

Released under the MIT License.