Manage Guru users and Groups with automatic provisioning (SCIM)
Guru supports automatic user and group provisioning with the SCIM (System for Cross-domain Identity Management) standard. To setup automatic provisioning, your team will need to first have Single Sign On (SSO) set up and configured for your team.
What does automatic provisioning do? Why is it useful?
With automatic provisioning enabled, Guru Admins can no longer manually invite users or maintain user groups inside of Guru. All user maintenance, including adding, removing, and assigning users to groups will occur inside the identity provider, not in Guru. This process allows larger teams to manage their users and groups in one place.
When can I set up automatic provisioning?
Before you set up automatic provisioning, please confirm the following:
Your team must have Single Sign-On enabled.
You must be an Admin.
The Guru team must manually enable automatic provisioning for your team before you will see the below options. Please contact your team's Account Manager or firstname.lastname@example.org if you do not see the ability to toggle SCIM on.
How do I set up automatic provisioning?
After our team has enabled automatic provisioning for you, follow the below steps:
Navigate to the SSO/SCIM page in Team Settings
Toggle the button next to Authorize SCIM Provisioning to ON.
Select if you will allow Guru to sync users only or users and groups:
Should I select "Users Only" or "Users and Groups"?
When "Users Only" is selected, Guru Admins will NOT be able to invite users from within Guru. Admins can still create Groups and add users to Groups from within Guru.
When Users and Groups is selected, Guru Admins will NOT be able to
Create users or groups from within Guru
Add users to synced groups from within Guru
NOTE: Members added through automatic provisioning are billable as soon as they sign in for the first time. The cost of new member accounts will be prorated for the remainder of your current billing period.
Instructions specific for your IDP
The provisioning setup varies depending on the identity provider (IDP) your team uses. For detailed instructions on how to setup automatic provisioning for your specific IDP, please reach out to Guru at email@example.com. Guru is featured as a member of the Okta network, but this functionality works for any IDP that supports the SCIM 2.0 standard. Here is a list of IDPs we've worked with in the past (however we are not limited to this list):
NOTE: Guru currently does not support automatic provisioning through Office 365. We only support SSO through Google and standard SAML using a third party identity provider.
What should I expect after Automatic Provisioning is enabled?
Automatic provisioning allows Admins to manage Guru team members more efficiently. Upon enabling auto provisioning:
Any users or groups that pre-existed in Guru that DO NOT match users or groups in your IDP will remain in Guru and are editable/removable
Users, groups, and group assignments from your IDP will come in to Guru immediately
Any users, groups, and group assignments with pre-existing exact matches in Guru will be merged, and once merged these become uneditable in Guru
Admins will be able to distinguish users/groups from your identity provider from Guru users/groups via this syncing symbol
Any Cards that are unassigned due to removal of a user or group can be re-assigned in the Card Manager
When users are removed from SSO they will be immediately deleted in Guru
Reassign user responsibilities such as Card verification BEFORE removing them from SSO
If you have any questions about Guru, please contact Guru Support by clicking "Chat with Us!" under 'Team Settings' in Guru or by sending an email to firstname.lastname@example.org 🧠