Getting started with SSO and SCIM

ENT_Tag-Small.png 

Available only on Enterprise plans.

Setting up SSO

Single Sign-On (SSO) allows your team to securely access Scribe with just one set of login credentials, streamlining the login process and enhancing security.

Before you can set up SSO, you'll need to add any email domains that users will be logging in with under the General tab in the Domains section. This tells Scribe which email addresses are associated with your organization.

Follow the steps below to configure SSO:

Once you begin the setup process, it's best to complete it in one go, as the link will expire after 5 minutes if not used. If the link expires, simply click "Start Setup" again to generate a new one.

At the conclusion of set up, you'll be prompted with an opportunity to test SSO to confirm it's working as expected. Organization admins can always go back and edit/remove the current SSO setup.

Best Practices for SSO Configuration

  • Named IdP vs. generic SAML/OIDC: We support integrations with most of the major IdPs. We recommend selecting the named IdP if it's listed instead of the generic SAML option. Different IdPs have slight configuration differences, and using the preconfigured option ensures these are handled appropriately.
  • Who to authorize in your IdP: Once SSO is enabled for your Scribe instance, any new users invited to Scribe will also need to be authorized within your IdP to log into Scribe. Most IdPs let you configure security groups (e.g. "All Employees," "Sales," "IT"). We recommend authorizing the broadest group of users (e.g. "All Employees"). This ensures new Scribe users won't get an access error from your SSO provider when logging in for the first time, and IT won't have to grant permission to each new Scribe user individually.
  • Multiple email domains: If your organization uses multiple email domains, make sure the User Principal Name (UPN) matches the user's email address when configuring SSO mapping. 

    See a guide here on adjusting this in Microsoft Entra:

 

Configuring SCIM

SCIM is available on select Enterprise plans. Existing customers should reach out to success@scribehow.com to discuss available options.

SCIM (System for Cross-domain Identity Management) lets you automatically provision and deprovision Scribe users from your Identity Provider (IdP). Once enabled, all user management moves out of the Scribe interface, and instead syncs with your organization's directory.

Before you begin: Map all existing Scribe users to their current teams in your IdP before enabling SCIM. When you enable SCIM, existing team memberships are overwritten by your directory groups. Any user not in a mapped group will lose access.

Prerequisites

  • To set up SCIM, you'll need System Admin access in Scribe, and admin access to your IdP. We recommend that someone from your IT team is granted System Admin access to complete this process directly as a best practice.
  • SCIM can only work if SSO has already been set up, and if SSO Only is selected under Settings > General > Login method.
  • Finalize your team structure in Scribe. SCIM provisioning is built on your existing teams.

Step 1: Create directory groups in your identity provider

Each group maps to one team and role in Scribe, with a separate directory group for each combination. A group can be mapped to multiple teams if needed.

System Admins must be included in a dedicated team and mapped to at least one team to maintain access. SCIM enablement will be blocked if this group is not yet mapped.

For this guide, we'll use this example of a company with two System Admins managing a Scribe organization with the following teams:

  • Accounting Team: 10 Creators, 10 Viewers, 2 Team Admins
  • Customer Support Team: 5 Creators, 5 Viewers, 1 Team Admin
  • General Team: All 33 users as Viewers

Scribe Capture

Capture users can belong to multiple groups. Existing directory groups can be reused, although we recommend caution to avoid confusion.

Example Directory Group Scribe Team Scribe User Role
ScribeCapture_SystemAdmin General Creator or Team Admin (since System Admin is appointed, can be any Standard role)
ScribeCapture_AccountingAdmin Accounting Team Admin
ScribeCapture_AccountingCreator Accounting Creator
ScribeCapture_AccountingViewer Accounting Viewer
ScribeCapture_SupportAdmin Customer Support Team Admin
ScribeCapture_SupportCreator Customer Support Creator
ScribeCapture_SupportViewer Customer Support Viewer
ScribeCapture_General General Viewer

Scribe Optimize

With Scribe Optimize, a user can only be a Participant in one team. If a user belongs to two Participant groups in your IdP, Optimize will not function correctly for them. Verify there's no overlap before enabling. The Org Optimizer role is the exception, and can span all teams.

Example Directory Group Scribe Team Scribe User Role
ScribeOptimize_SystemAdmin General Org or Team Optimizer (since System Admin is appointed, can be any role except Participant)
ScribeOptimize_OrgOptimizer General Org Optimizer
ScribeOptimize_AccountingTeamOptimizer Accounting Team Optimizer
ScribeOptimize_AccountingParticipant Accounting Participant
ScribeOptimize_SupportTeamOptimizer Customer Support Team Optimizer
ScribeOptimize_SupportParticipant Customer Support Participant

Deploying with Capture & Optimize

Users can belong to Capture and Optimize groups simultaneously. For example, your 15 Accounting Capture users can also all be in ScribeOptimize_AccountingParticipant, or your Optimize Participants can be an entirely different set of people. The mutual exclusivity rule applies only within Optimize Participant groups.

Step 2: Connect to Scribe, map, and enable

Follow the guide below to initiate the connection, map all groups, configure email notifications, and enable provisioning.

Note that once the connection is initiated, any groups included in your SCIM connection will populate. If you don't see all of your expected groups yet, allow up to an hour for them to sync from your IdP. Larger organizations may take longer.

After enabling SCIM

All user management moves to your IdP after enabling SCIM.

  • When a user is deactivated or deleted in your IdP, their Scribe account is deactivated and their license is released.
  • Content created by deactivated users is preserved and can be reassigned by a System Admin under Settings > Users with the three-dot menu.
  • Users removed from a team may show as "deactivated" from that team in CSV exports.
  • If your organization has Domain Control enabled, note that SCIM supersedes it, and once active any user not mapped to a SCIM group will see a message to contact their IdP admin.

You have the option to Pause provisioning at any time. While paused, your identity provider will stop syncing with Scribe. Existing members keep access, but future changes must be made manually until you turn provisioning back on.

If at any point you need to remove your SCIM connection altogether and start over, you can use the three-dot menu in the top right corner to Reset Connection.

Need help?

For assistance, reach out to your dedicated Customer Success Manager, or to success@scribehow.com.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Compare Scribe Plans
Find the right plan for you and your team.