Skip to main content
SCIM Provisioning can push the identity provider’s groups into StackOne as synced groups. The identity provider (IdP) owns each synced group’s name and members, and you grant access with it in StackOne like any other group. Add someone to the group in the IdP and they gain the projects the group is assigned to. Remove them and that access goes with them.

How synced groups work

When the IdP pushes a group, StackOne creates a group of the same name on the Groups tab of Organization > Manage Team, marked with a Synced tag. From then on:
  • The IdP manages the name and the members. Rename the group there and it is renamed here. Add or remove members there and the membership follows. In StackOne the group is marked Managed by the identity provider, and renaming it, deleting it, and editing its members are disabled.
  • You manage its access. Assign the group to projects and accounts and choose a role, the same way as for any other group. See Assign Group Access.
  • Its members are people the directory has provisioned. A synced group can only contain members that SCIM Provisioning created or linked through the same connection. Someone who is in the directory group but not assigned to the StackOne application isn’t a StackOne member, so they don’t appear in the group until they are.
Synced groups never change anyone’s organization role. See Organization Roles.

Prerequisites

  • SCIM Provisioning linked on the SSO connection, with users provisioning. See Enable SCIM Provisioning.
  • Groups available in the organization.
  • Organization Admin, or Admin on the project, to assign a group to a project.

Prepare the access before you push

A pushed group takes over an existing StackOne group of the same name when that group has no members. Names match ignoring case and surrounding spaces. This lets you set up the access before anyone arrives:
1

Create the group in StackOne

  1. On the Groups tab, click Create group.
  2. Give it the exact name of the directory group, for example Finance.
  3. Leave it empty.
2

Assign its access

  1. Open the group’s Projects tab.
  2. Add the projects it should grant, each with a role.
See Manage Groups.
3

Push the group from the IdP

When the IdP pushes Finance, StackOne turns the empty group into the synced one and keeps its assignments. Its members gain that access as they are pushed.
A StackOne group that already has members is never taken over. If the IdP pushes a group with the same name, StackOne creates a second group, tagged Synced, and leaves yours untouched. To end up with one Finance group, remove the members from yours before the push, or push the directory group under a different name.

Push groups from the identity provider

Okta

Push groups from the app’s Push Groups tab.

Microsoft Entra

Provision the groups assigned to the application.

What changes when

If you stop pushing a group but keep it in StackOne, it stays a synced group and can’t be edited until you unlink SCIM Provisioning. Delete it from the IdP’s push instead, or unlink SCIM Provisioning to get every synced group back.

When SCIM Provisioning is unlinked or replaced

Unlinking SCIM Provisioning, or deleting the SSO connection it’s on, hands every synced group back to you. Each becomes a normal group that keeps its members and its project and account assignments, and you can edit it again. Nobody loses access. If you link SCIM Provisioning again, on the same connection or a new one, a pushed group with the same name takes that group back as a synced group, members and assignments intact, rather than creating a second copy.

Limits

  • A group push can contain at most 1,000 direct members. StackOne rejects larger pushes, and the IdP reports the error.
  • Synced group names must be unique within the SCIM Provisioning connection. A push that reuses the name of another synced group is rejected. A group you created by hand can share the name, which is how the takeover above works.
  • Members must already be provisioned. A push that lists someone SCIM Provisioning doesn’t know is rejected until that person is assigned to the StackOne application and provisioned.

Next steps

Groups

Assign synced groups to projects and accounts, and manage groups created by hand.

SCIM Provisioning

How provisioning works and how it attaches to the SSO connection.