IT Glossary
SCIM automates user provisioning and deprovisioning across apps. Learn how SCIM works, how it differs from SAML, and how Corma extends it to every app.
June 8, 2026
SCIM (System for Cross-domain Identity Management) is an open standard that automates the exchange of user identity information between an identity provider and applications. Using a JSON-based REST API, SCIM creates, updates, deactivates, and deletes user accounts automatically, which keeps access in sync across a SaaS stack throughout the employee lifecycle.
When a new hire joins, SCIM auto-creates accounts in Google Workspace, Slack, and Jira based on their role. On their last day, SCIM deactivates all of them in one motion, which prevents orphaned accounts that fail audits.
The limit: SCIM only works for apps that expose a SCIM endpoint. Many smaller or legacy SaaS tools do not. Covering those long-tail apps is exactly where a SaaS Management plus IAM layer earns its keep.
System for Cross-domain Identity Management. It standardizes how user accounts are provisioned across applications.
Usually yes. SCIM manages the account lifecycle, and SAML or OIDC handles login. Together they cover provisioning and authentication.
They need an alternative method to stay in sync. Corma handles these long-tail and non-SCIM apps so deprovisioning is not left manual.
Corma automates provisioning for SCIM apps and extends coverage to the apps SCIM cannot reach. Explore user provisioning or request a demo.