Set up SCIM user provisioning in Wispr Flow
Last updated: July 24, 2026
Available on: Web admin console for setup. Sign-in verification on Mac, Windows, and iOS.
Connect your identity provider to Wispr Flow so users are created, updated, and removed automatically — no manual provisioning. Setup takes about 10 minutes and applies to your whole organization.
Before you start
Confirm you have:
Org admin access in Wispr Flow, or the IT Admin role assigned by an org admin.
An Enterprise plan. SCIM directory sync and SSO enforcement are available to enterprise admins and IT Admins.
Admin access to your identity provider (Okta, Azure AD, OneLogin, or similar).
An email address on your admin profile in Flow.
Note: The IT Admin role grants access to team, billing, and SSO management without using a paid dictation seat. IT Admin users cannot dictate, use the notetaker, or access other dictation features — they will see a blocking modal inside the app offering only Sign out or Go to Admin Portal. The modal shows your enterprise name (when available) along with instructions to change your seat type in the Admin Portal, which opens to admin.wisprflow.ai in an external browser. If an IT Admin's role is later upgraded, the blocked modal dismisses automatically when the app refreshes.
Warning: Enabling SCIM disables manual user invites and removals in Flow. Invite, bulk invite, remove member, and revoke invitation actions are all blocked. Users see the message: "User management is controlled by your identity provider via SCIM. Please add or remove users through your identity provider." Join-request Approve and Deny buttons are also hidden from the Team page while SCIM is enabled — pending join requests still display but cannot be actioned in the desktop app.
How to set up SCIM provisioning
Open the Wispr Flow admin console and go to SSO settings.
Launch the admin portal from the SSO settings page.
Navigate to the Directory Sync section in the admin portal.
Select your identity provider and enable Directory Sync.
Map the following attributes as directed by the admin portal:
Primary email (required)
First name
Last name
Group or team assignments (optional)
Wait for directory sync to activate. Once active, Flow is ready to process provisioning events.
Assign a small pilot group of test users to the Wispr Flow application in your identity provider. They should appear in Flow's admin console within a few minutes. Confirm they are listed before assigning the rest of your users.
Note: The admin portal always opens on the SSO configuration section first, so you will need to navigate to Directory Sync manually. When directory sync activates, Flow imports any domains from your identity provider organization into the enterprise's allowed domain list. Existing users in your IdP are not backfilled — they are only provisioned as your IdP sends individual creation events, which usually happens when you assign users to the application.
Warning: Manual user management remains blocked until the directory sync connection is deleted in the admin portal. Existing memberships are preserved when the connection is deleted — no users are removed.
How to verify your provisioned account
Once your IT admin has set up SCIM, confirm your account synced correctly. Steps differ by platform.
Mac and Windows
Open the Wispr Flow app.
Click Sign in via browser. This is the only sign-in button in the desktop app — it opens authentication in your web browser, where you choose your sign-in method.
Choose your SSO sign-in method in the web browser and enter your work email when prompted.
Complete the SSO flow and return to the Flow app.
Open Settings → Account. Your first and last name are editable input fields with a Save button; your email is read-only. Compare the displayed values against your identity provider manually — there is no automated IdP-match indicator. If they do not match, ask your admin to adjust IdP mappings.
iOS
Open the Wispr Flow app.
Tap More options. Three additional sign-in methods appear (Continue with Microsoft, Continue with SSO, and Continue with Email). Select Continue with SSO, enter your work email, then tap Continue.
Complete the SSO flow.
Open your account or profile section. The profile is editable — tapping opens a dialog for first and last name, with email shown read-only. Compare the displayed values against your identity provider manually. If they do not match, ask your admin to adjust IdP mappings.
Troubleshooting
Directory sync is not activating
If your identity provider is configured but users are not being provisioned, verify that:
Directory sync is enabled and active in the admin portal.
Your identity provider is correctly connected to the admin portal.
Your identity provider can reach Flow (no network or firewall blocks).
Member count in Flow doesn't match your directory
If the number of users in your identity provider's directory doesn't line up with the number of members shown in your Wispr Flow account, contact support right away. We can push a sync from our end to reconcile the connection and make sure every provisioned user is correctly reflected in Flow.
When you reach out, include your identity provider, your enterprise domain, the count you see in your directory versus the count you see in Flow, and roughly when you last provisioned users. That helps us reconcile the two sides quickly.
Users are not being created in Flow
Check that:
Automatic provisioning is enabled in the identity provider.
The app is assigned to the user or their group.
The email or username field is mapped correctly.
The user's email domain exactly matches a registered domain. A user at mail.example.com will not be provisioned if only example.com is registered — add the specific subdomain to your enterprise domains.
Your enterprise has not reached its seat cap. When the cap is reached, provisioning is blocked and no email invitation is sent. Increase your seat count or remove existing users, then reassign the user in your identity provider.
The user does not already belong to a different Wispr Flow enterprise. A user can only belong to one enterprise at a time and must be removed from their current one first. If this is the cause, no email invitation is sent — contact support if it is unexpected.
User updates are not appearing in Flow
Check that:
Update provisioning is enabled in your identity provider (not just create and delete).
Attribute mappings include the fields you expect to update, such as first name and last name.
The user is still assigned to the app in your identity provider.
Deactivated users can still sign in
When users are removed via SCIM, their enterprise membership is removed but their Flow account is not deleted. If a removed user can still access enterprise resources, check that:
The deprovisioning event was sent by the identity provider.
The user was unassigned from the app (not just deactivated in a way that does not trigger a SCIM delete event).
Your identity provider reached Flow successfully.
SSO enforcement is enabled. Without it, users may still sign in via other methods after SCIM removal.
Your Enterprise subscription is active. SSO enforcement lapses if your subscription is canceled or expired. Past-due subscriptions are still considered live and continue to enforce SSO.
Duplicate user accounts
Duplicates usually mean one of the following:
The user was created manually in Flow before SCIM was turned on.
The identity provider is sending a different email or username than the one already used in Flow.
The user signed up directly with a personal variant of their email before being provisioned.
Users receive email invitations instead of automatic provisioning
If SCIM provisioning hits a transient error, Flow falls back to sending an email invitation. The user can still join by clicking the link. This fallback does not apply when the enterprise seat cap is reached — in that case, no invitation is sent. If this happens repeatedly, contact support.
A user on iOS sees "Sign-in not allowed" and is signed out
This screen appears when a user tries to sign in from a network your organization's IP allowlist does not permit. Flow automatically signs the user out and displays the "Sign-in not allowed" screen with guidance about approved networks. (On Mac and Windows, the equivalent screen is titled "Your network isn't allowed.")
The user has two options on that screen:
Retry: Connect to an approved network (such as your corporate VPN or office Wi-Fi), then tap Retry. This clears the block state and returns the user to the sign-in screen, where they sign in again. If their IP still violates the allowlist, the block re-triggers.
Sign Out: Dismiss the blocked screen without signing in.
If users on approved networks are still seeing this screen, verify that their device's current IP address falls within your organization's configured allowlist ranges. IP allowlist enforcement applies on Mac, Windows, and iOS.
FAQs
What happens when a user is removed from the identity provider?
Their enterprise membership is removed and their directory sync link is cleared. Their Flow account is not deleted. If they are later re-provisioned, the existing account is re-associated with the enterprise.
Can users sign up for Flow directly when SCIM is enabled?
No. Users on SCIM-managed domains cannot self-register — they must be provisioned by the identity provider. Direct sign-up attempts are blocked.
How do SCIM-provisioned users sign in?
They sign in using whatever authentication methods your enterprise allows. If your enterprise also enforces SSO (a separate setting), users must sign in via SSO. SCIM provisioning alone does not enforce a specific sign-in method. Note that if your enterprise restricts domain access, a signing-in user who is not a member of the enterprise will be blocked as well.
What role are SCIM-provisioned users assigned?
All SCIM-provisioned users are assigned the Member role — SCIM never assigns or modifies the IT Admin role. Role mapping from the identity provider is not currently supported. The IT Admin role can be assigned through the standard team invitation flow or by promoting an existing member from your admin surface.
Why does the welcome notification say "Your teammate" instead of a name?
"Your teammate" appears in the secondary billing notification when no inviter name is available. SCIM-provisioned users see this because the SCIM flow does not pass an inviter name. The primary welcome notification is unaffected.
What happens if a directory group is deleted in the identity provider?
All users in that group are removed from Flow, and any pending invitations for those users are revoked.
Does SCIM affect billing?
Yes. Your seat count increases automatically as users are provisioned, which may increase your bill. Seat counts are not reduced immediately when users are removed — reductions happen during billing reconciliation cycles. Contact support to adjust seats manually if needed. IT Admin role members do not count toward paid seats.
Does the IP allowlist apply to iOS users?
Yes. iOS enforces the same IP allowlist restrictions as Mac and Windows. If a user signs in from a network not on your organization's approved list, they are signed out automatically and shown a "Sign-in not allowed" screen (titled "Your network isn't allowed" on Mac and Windows) until they connect from an approved network.
Limitations and notes
SCIM provisioning is available on the Enterprise plan only.
Role mapping from the identity provider is not supported — all provisioned users start as Member.
SuperAdmin is a database-only role and cannot be assigned via any UI or invite.
A user can only belong to one Wispr Flow enterprise at a time.
Existing users in your IdP are not backfilled — users are provisioned only when your IdP sends individual creation events.
Seat counts increase automatically when users are provisioned. Reductions happen during billing reconciliation cycles, not immediately on removal.
Admins cannot demote themselves to Member — another admin must make that change.
While SCIM is enabled, manual invites and member removals are blocked in Flow, and join-request Approve/Deny buttons are hidden from the Team page. Those actions must go through your identity provider.
IP allowlists accept a maximum of 64 CIDR entries; wildcard ranges (0.0.0.0/0, ::/0) are rejected.
IP allowlist enforcement applies on Mac, Windows, and iOS. Users who sign in from a network not on the allowlist are signed out automatically and must connect from an approved network.
Still need help?
Contact Wispr Flow support if:
You cannot find SCIM settings but believe your plan should include them.
The member count in Flow doesn't match your identity provider's directory — we can push a sync from our end to reconcile the connection.
Users are created or removed in Flow without a matching change in your identity provider.
Users repeatedly receive email invitations instead of being provisioned automatically.
You've worked through the Troubleshooting section and the issue persists.
When you reach out, include your platform, identity provider, the affected user's email, and what you've already tried. To open a ticket, click Help in the Flow desktop sidebar and select Talk to support. On iOS, go to Menu → Talk to Support. On Android, open the navigation drawer and tap Report an issue.