Does iDBQuery support SCIM user provisioning and deprovisioning?

Yes. iDBQuery supports SCIM-based user provisioning with identity providers such as Okta and Microsoft Entra, so accounts are created, updated, and deactivated automatically from your directory. When someone joins, moves teams, or leaves, iDBQuery reflects the change without an admin editing users by hand.

SCIM keeps your iDBQuery user list in sync with your identity provider so joiner-mover-leaver events happen automatically.

  • Auto-provisioning - a new hire in Okta or Entra gets an iDBQuery account created for them, no manual invite needed.
  • Attribute and group sync - department, title, or group changes flow through, so role-based access stays aligned with your directory.
  • Automatic deprovisioning - when HR offboards someone in your IdP, SCIM deactivates their iDBQuery account, which is critical for clean access reviews and audits.
  • Pairs with SSO - SCIM handles the lifecycle while SSO handles authentication, giving you one source of truth for identity.

As an example, moving an employee from 'Sales' to 'Finance' in your directory can automatically switch their iDBQuery role and the projects they can query, without a support ticket. This matters because access governance is only as good as its weakest manual step - forgotten accounts are a common audit finding. iDBQuery's broader posture reinforces this: data is queried in place, every answer is cited to its source, and access is bounded by RBAC and encryption. SCIM simply ensures the right people, and only the right people, have accounts. Ask us which SCIM attributes and IdPs we support for your rollout.

Updated 2026-06-22