Set up SCIM user provisioning in Wispr Flow
Last updated: September 19, 2026
Connect your identity provider to Wispr Flow to create, update, and remove organization members automatically. Configure SCIM in the web admin console.
Before you start
You need an Enterprise plan, an Admin or IT Admin role in Flow, an email address on your Flow admin profile, and administrator access to your identity provider, such as Okta, Azure AD, or OneLogin.
SCIM manages membership. Enabling it disables manual additions, removals, and join-request approvals and denials in Flow. Users on SCIM-managed domains cannot sign up directly; provision them through your identity provider.
Set up directory sync
Open SSO settings in Flow’s admin console, then launch the admin portal from that page.
Go to Directory Sync, select your identity provider, and enable directory sync.
Follow the portal’s attribute-mapping instructions. Map primary email (required), first name, and last name.
Wait for directory sync to activate.
Assign a pilot group to the Wispr Flow application in your identity provider. Confirm those users appear in Flow before assigning everyone else.
Activation imports your identity provider organization’s domains into Flow’s allowed domain list. It does not backfill existing users: provisioning happens when the provider sends individual creation events, usually when users are assigned to the application.
Verify the setup
Confirm the assigned user appears in Flow’s admin console.
Have them sign in using an authentication method your organization permits. SCIM alone does not enforce SSO; see Configure SSO for that separate setting.
Compare their name and email with the identity provider in Settings → Account on Mac or Windows, or the account profile on iOS. Email is read-only; iOS combines first and last name. Correct mismatches in your provider’s attribute mappings.
Manage provisioned members
Roles: SCIM creates users as Member and does not change existing roles or support role mapping. An admin can change an existing member’s role in Flow.
Billing: Provisioning increases your seat count and may increase your bill. IT Admins do not consume paid seats. Contact support for seat reductions or adjustments; see Manage users and billing.
Removal: SCIM removes organization membership and revokes pending invitations while retaining the Flow account. Re-provisioning reconnects that account. Unlike manual admin removal, SCIM removal does not block rejoining or accepting invitations; other organization access policies still apply.
Disconnecting SCIM: Delete the directory sync connection in the admin portal to restore manual membership management. Existing memberships are preserved.
Troubleshooting
Directory sync does not activate
Check that directory sync is enabled, your identity provider is connected correctly, and network or firewall rules allow it to reach Flow.
Users are not created
Enable automatic provisioning, assign the user or group to the app, and check email or username mapping.
Register the exact email domain. For example,
mail.example.comrequires its own entry when onlyexample.comis registered.Check your seat cap. Increase it or remove users, then reassign the affected user in your provider.
Check for membership in another Flow enterprise. A user can belong to only one; remove the existing membership first.
Seat-cap and other-enterprise rejections do not send fallback invitations. Contact support for unexpected rejections.
Profile updates or account matching are wrong
Enable update provisioning as well as creation and deletion, confirm the user remains assigned, and check name and email mappings. For duplicates, check for an existing manually created account, a personal-email signup, or a different email or username sent by your provider.
A deactivated user still has access
Confirm the user was unassigned and a SCIM delete event reached Flow; deactivation alone may not send one. If sign-in violates your organization’s policy, check SSO enforcement and your active Enterprise subscription.
Removal is blocked if it would leave no admin or no member in a billable role. Assign a replacement admin or retain another billable member before retrying.
Users receive invitations instead of automatic provisioning
A temporary provisioning error can trigger an email invitation, which the user can accept. Contact support if this keeps happening; seat-cap and other-enterprise errors follow the rules above.
Member counts do not match
Refresh Settings → Team; a failed refresh can leave stale counts visible. After reconnecting or rotating your provider, re-verify memberships and reassign users. If counts still differ, contact support to request a sync.
A provisioned user cannot sign in
Check the permitted sign-in method and organization membership. Enforced SSO requires SSO login; domain restrictions can block nonmembers. For network lockouts, follow the approved-network troubleshooting steps.
Organization privacy settings apply separately; see privacy and retention policies.
Get help
Contact support for missing SCIM controls, unexpected membership changes, or persistent failures. Include your provider, enterprise domain, affected user’s email, platform, and steps tried. For count mismatches, include both counts and the last provisioning time. On desktop, choose Help → Talk to support; on iOS, choose Menu → Talk to Support.