Set up SCIM user provisioning in Wispr Flow

Last updated: September 10, 2026

Available on: Web admin console for setup; sign-in verification on Mac, Windows, and iOS. iOS shows enterprise plan status but has no admin UI. Android shows the plan label only.

Connect your identity provider to Wispr Flow so users are created, updated, and removed automatically. Setup takes about 10 minutes and applies to your whole organization.


Before you start

Confirm you have:

  • Org admin access in Wispr Flow, or the IT Admin role assigned by an org admin. IT Admin grants team, billing, and SSO management without a paid dictation seat; IT Admins cannot dictate and can only sign out or open the admin console from the app. A role upgrade takes effect when the app refreshes.

  • An Enterprise plan. SCIM directory sync and SSO enforcement are available to enterprise admins and IT Admins.

  • Admin access to your identity provider (Okta, Azure AD, OneLogin, or similar).

  • An email address on your admin profile in Flow.

Note: Admins creating a team can enable "Auto-add all future @<domain> users", which emails and adds future signups on that domain at next login and adds a seat automatically. Domains requiring sales-assisted onboarding cannot self-serve create a team — Flow shows "Your domain requires sales-assisted onboarding. Please reach out to sales."

Warning: Enabling SCIM blocks the Add new user button in Settings → Team, replaces the per-row Add buttons on the Other Domain Users tab with a note that domain users are SCIM-managed, and makes Approve and Deny on pending join requests non-actionable.


How to set up SCIM provisioning

  1. Open the Wispr Flow admin console and go to SSO settings.

  2. Launch the admin portal from the SSO settings page.

  3. Navigate from SSO configuration to Directory Sync.

  4. Select your identity provider and enable Directory Sync.

  5. Map the attributes as directed by the admin portal:

    1. Primary email (required)

    2. First name

    3. Last name

  6. Wait for directory sync to activate; Flow then processes provisioning events.

  7. Assign a pilot group to the Wispr Flow application in your identity provider. Confirm they appear in Flow's admin console before assigning everyone else.

Note: On activation, Flow imports domains from your identity provider organization into the enterprise's allowed domain list. Existing IdP users are not backfilled — they are provisioned only as your IdP sends individual creation events, usually when you assign users to the application.

Warning: Manual user management stays blocked until you delete the directory sync connection in the admin portal. Deleting the connection preserves existing memberships — no users are removed.

What the team console shows

The team console is at Settings → Team, with up to three tabs: Team Members; Other Domain Users (non-public domains only); and Requests, which appears only when requests are pending.

Each member row shows Name, Status (Active / In trial (ends <date>) / Pending), and Role (Admin, Member, Super Admin, IT Admin).

The seat total = active (billable, non-trialing) + trialing (individual trial end date in the future) + IT Admin (non-billable) + invited (pending invitations). Invitations can be Pending, Accepted, Rejected, or Expired. Admins can generate a shareable team invite link, revoke invitations, and bulk-accept join requests.


How to verify your provisioned account

Mac and Windows

  1. Open the Wispr Flow app and start sign-in.

  2. Choose your SSO sign-in method in the browser and enter your work email when prompted.

  3. Complete the SSO flow and return to Flow.

  4. Open Settings → Account and compare the values against your identity provider. If they do not match, ask your admin to adjust IdP mappings.

Email comes from your IdP and is read-only in Flow.

iOS

  1. Open the Wispr Flow app and tap More options to reveal Continue with Microsoft, Continue with SSO, and Continue with Email.

  2. Select Continue with SSO, enter your work email, tap Continue, and complete the SSO flow.

  3. Tap your profile in the account section and compare the values against your identity provider. If they do not match, ask your admin to adjust IdP mappings.

On iOS, first and last name are stored as one combined name, and email is read-only.


Troubleshooting

Directory sync is not activating

Verify that:

  • Directory sync is enabled and active in the admin portal.

  • Your identity provider is correctly connected to the admin portal.

  • Your identity provider can reach Flow, with no network or firewall blocks.

Users are not being created in Flow

Check that:

  • Automatic provisioning is enabled in the identity provider.

  • The app is assigned to the user or their group.

  • The email or username field is mapped correctly.

  • The user's email domain exactly matches a registered domain. A user at mail.example.com is not provisioned if only example.com is registered — add the subdomain to your enterprise domains.

  • Your enterprise has not reached its seat cap. At the cap, provisioning is blocked and no email invitation is sent; increase your seat count or remove users, then reassign the user in your identity provider.

  • The user does not already belong to another Wispr Flow enterprise. A user can belong to only one at a time and must be removed from the current one first; no email invitation is sent. Contact support if this is unexpected.

User updates are not appearing in Flow

Check that:

  • Update provisioning is enabled in your identity provider, not just create and delete.

  • Attribute mappings include the fields you expect to update, such as first name and last name.

  • The user is still assigned to the app in your identity provider.

Deactivated users can still sign in

SCIM removal removes enterprise membership but does not delete the Flow account. If a removed user still accesses enterprise resources, check that:

  • The deprovisioning event was sent by the identity provider and reached Flow.

  • The user was unassigned from the app, not just deactivated in a way that does not trigger a SCIM delete event.

  • SSO enforcement is enabled. Without it, users can still sign in via other methods after SCIM removal.

  • Your Enterprise subscription is active — contact support if enforcement appears to have lapsed.

Duplicate user accounts

Duplicates usually mean one of the following:

  • The user was created manually in Flow before SCIM was turned on.

  • The identity provider sends a different email or username than the one already used in Flow.

  • The user signed up directly with a personal variant of their email before being provisioned.

Users receive email invitations instead of automatic provisioning

On a transient provisioning error, Flow falls back to an email invitation and the user can still join via the link. No invitation is sent at the enterprise seat cap or when the user belongs to another enterprise. Contact support if invite fallbacks or rejections repeat.

Member count in Flow doesn't match your directory

Refresh team data from Settings → Team. If the refresh fails, Flow keeps the last-known-good team and enterprise data rather than clearing it, so counts may be stale until a refresh succeeds. Enterprise data is cleared only when the server confirms the account has no enterprise.

If you recently rotated or re-connected your identity provider, re-verify membership and re-assign users.

If the count still does not match, contact support to push a sync. Include your identity provider, your enterprise domain, the count in your directory versus the count in Flow, and roughly when you last provisioned users.

A provisioned user still can't sign in (network restrictions)

Enterprise admins can restrict sign-in to an IP allowlist. On desktop, a user signing in from a non-allowlisted network is signed out and blocked, with the message "Your admin at <org> only allows Wispr on approved networks. Switch networks or contact your admin." Retry restarts sign-in and re-blocks if the network is still disallowed. IP-allowlist enforcement is not available on Android.

iOS enterprise policy not loading

On iOS, if the app cannot reach enterprise policy for a user known to belong to an enterprise, it fails closed: Privacy Mode is forced on, Cloud Sync forced off, and Auto-delete transcripts forced on, all locked until the policy fetch succeeds. The app retries automatically and shows no error message.


FAQs

What happens when a user is removed from the identity provider?

Their enterprise membership is removed; the Flow account is not deleted. If re-provisioned later, the existing account is re-associated with the enterprise. They can also rejoin, auto-join, or accept invite links normally.

Can users sign up for Flow directly when SCIM is enabled?

No. Users on SCIM-managed domains cannot self-register; direct sign-up attempts are blocked and they must be provisioned by the identity provider.

How do SCIM-provisioned users sign in?

With whatever authentication methods your enterprise allows; SCIM alone does not enforce a sign-in method. If your enterprise enforces SSO (a separate setting), users must sign in via SSO. If your enterprise restricts domain access, a signing-in user who is not a member of the enterprise is blocked.

Does SCIM affect billing?

Yes. Your seat count increases automatically as users are provisioned, which may increase your bill. Contact support to reduce or adjust seats manually. IT Admin members do not count toward paid seats.

What is the difference between a user removed by an admin and one removed via SCIM?

Users removed manually by an admin cannot re-add themselves with a Rejoin button or an invite link and must be explicitly re-invited. Users removed through SCIM deprovisioning face no such block.


Limitations and notes

  • SCIM provisioning is available on the Enterprise plan only.

  • Role mapping from the identity provider is not supported: all SCIM-provisioned users are created as Member, SCIM never changes an existing member's role, and it never assigns IT Admin. Assign IT Admin through the standard team invitation flow or by promoting an existing member.

  • The invite dialog offers only Member and Admin, and only when billing info is set up, so Super Admin cannot be assigned from the invite flow.

  • A user can belong to only one Wispr Flow enterprise at a time.

What admins can enforce org-wide

Enterprise admins can set org-level policies that apply to all provisioned members:

  • Local Data Policy floor — Store Normally / Delete After 24h / Never Store. The stricter of the org floor and the user's own preference wins; "Never Store" locks the choice for all members.

  • Privacy Mode and Cloud Sync — Admins can force-disable usage-data sharing (Privacy Mode) and Cloud Sync, overriding member toggles. On iOS this also covers Auto-delete transcripts.

  • Context awareness — Admins can disable context awareness org-wide, force-disabling the member's context setting.

  • Note sharing audience — A four-tier setting in Settings → Organization controls who members may share meeting notes with. Non-admins see the dropdown as read-only, and the desktop app hides or disables sharing options the active tier disallows. From most to least restrictive:

    • Disabled — Sharing is off entirely. No notes are deleted; existing shared links are preserved and restored automatically if the setting is widened later.

    • Internal only — Members can share notes within the organization. Public links are off.

    • Internal and external — Members can also share with specific named people outside the organization; public links remain off.

    • Public links — All sharing options, including "Anyone with link". Default for organizations with no setting configured.


Still need help?

Contact Wispr Flow support if:

  • You cannot find SCIM settings but believe your plan should include them.

  • Users are created or removed in Flow without a matching change in your identity provider.

  • Users repeatedly receive email invitations instead of being provisioned automatically.

Include your platform, identity provider, the affected user's email, and what you've already tried. To open a ticket, click Help in the Flow desktop sidebar and select Talk to support. On iOS, go to Menu → Talk to Support.