Introduction
SCIM directory sync lets you manage your Gamma workspace membership directly from your identity provider, like Okta or Microsoft Entra ID. Once connected, adding someone to Gamma in your directory creates their account automatically, and removing them disables their account and frees their seat, with no manual cleanup in Gamma.
🔷 Note: SCIM is available on Gamma's Enterprise plan and requires single sign-on (SSO) to be active first. You'll need workspace admin access in Gamma, plus admin access to your identity provider.
How SCIM compares to just-in-time provisioning
Gamma supports two ways to provision users through SSO.
Just-in-time (JIT) provisioning. A user's Gamma account is created automatically the first time they sign in with SSO. This works out of the box with no setup beyond SSO. Until people log in, the workspace may look empty, and that's expected.
SCIM provisioning. Gamma syncs user accounts directly from your identity provider's directory. Accounts are created without requiring a first login, and removing someone from your directory deprovisions them in Gamma automatically.
Most teams start with JIT and add SCIM when they want offboarding handled from the directory.
Setting up SCIM
Before you begin
SCIM has two prerequisites.
SSO must be active for your workspace. Directory sync builds on your SSO connection, so the option to set it up only appears once SSO setup is complete.
Add everyone who needs Gamma access to your directory group first. Once SCIM is on, your directory is the only way into the workspace for people on your verified domains. Anyone not in the directory won't be able to join, even by signing in with SSO.
Step 1: Make sure SSO is active
SCIM can only be configured after SSO setup is complete. If your workspace doesn't have SSO yet, start there.
Step 2: Open directory sync settings
From your workspace, go to Workspace Settings > Security & authentication. Once SSO is active, you'll see a Directory sync section with a SCIM row.
Click Configure to open a secure setup portal in a new tab.
Step 3: Connect your identity provider's directory
The setup portal walks you through connecting your directory, with instructions tailored to your provider.
Once connected, Gamma runs an initial sync against your directory. Existing workspace members are matched by email, so their accounts are linked, not duplicated, and nothing about their content changes.
When the sync is complete, the Security & authentication page shows directory sync as Activated, along with the activation date. From that point on, workspace membership is managed from your identity provider.
How membership works once SCIM is active
Adding people
Assign someone to Gamma in your identity provider and their Gamma account is created automatically. They don't receive an invitation email from Gamma. They simply sign in with SSO and their account and workspace membership are already waiting.
If someone already had a Gamma account with a matching email, it's linked to your workspace the same way, also without an email.
New members join as Members. An existing admin can promote them to Admin from workspace settings.
SCIM syncs each user's email, first name, and last name. Profile updates in your directory sync to Gamma automatically.
🔷 Note: While SCIM is active, invites sent from Gamma's Members page to emails on your SSO-managed domain are skipped, and no invite email is sent. Add those people through your directory instead. Invites to emails outside your managed domain, like external guests, still work normally.
Removing people
Remove or unassign someone in your identity provider and their Gamma account is disabled, they're removed from the workspace, any active sessions are ended, and their seat is freed immediately. No follow-up steps are needed in Gamma.
If you re-assign them later, their account and content are restored the next time they sign in.
Everything they created in the company workspace stays there with its permissions intact. To transfer a departing employee's content to another account, contact our support team.
💎 Pro Tip: Keep at least two admins in your workspace. The sole admin (or billing admin) can't be deprovisioned via SCIM, which protects you from locking yourself out but can block offboarding if there's only one admin.
Seats
Users added through your directory are provisioned even if you're over your purchased seat count, and your subscription doesn't adjust automatically.
Size your seat count before assigning your group in the identity provider, and use Members > Manage seats to keep members and purchased seats aligned.
FAQs & Common Issues
I invited someone from the Members page and they never got the email.
If their email is on your SSO-managed domain, the invite is skipped while SCIM is active.
Add them to Gamma in your identity provider's directory instead.
Someone on my team sees an error saying our organization uses directory sync.
They haven't been added to Gamma in your identity provider yet.
Ask your IT admin to assign them to Gamma in the directory, then have them sign in again.
Do provisioned users get a welcome or invitation email?
No. Gamma creates the account silently in the background.
If any notification goes out, it comes from your identity provider, not from Gamma.
Can we control workspace membership with identity provider groups, or map groups to roles?
Not yet. Group sync is on our roadmap.
Everyone provisioned through SSO or SCIM joins as a Member, and Admin must be granted manually inside Gamma.
We removed someone in our identity provider but didn't set up SCIM. Are they out?
Without SCIM, removing someone from your IdP blocks new sign-ins, but an existing session lasts until it expires, and their seat isn't freed automatically.
Remove them from Workspace Settings > Members to free the seat. This is exactly the manual step SCIM eliminates.
Can we turn SCIM off later?
Reach out to our support team and we'll help you disable or reconfigure directory sync.
