SCIM User Provisioning | Fountain Help Center

SCIM User Provisioning

Automate user provisioning, access permissions, and account lifecycles in Fountain by integrating SCIM with your Identity Provider.

Updated this week

What SCIM Manages in Fountain

When SCIM is enabled, your Identity Provider becomes the system of record for users and user access in Fountain. User management is performed in your Identity Provider rather than in Fountain's Team settings.

User Attributes Managed via SCIM:

Important Behavior:

Once SCIM management is enabled for specific attributes (roles, locations, etc.), those attributes become read-only in Fountain and can only be updated through your Identity Provider.

Set Up SCIM in Fountain (steps)

Step 1: Enable SCIM in Fountain

  1. Navigate to Settings > Security > SCIM Provisioning
  2. Toggle Enabled to turn on SCIM provisioning
  3. Copy the SCIM Base URL and Authentication Token - you'll need these to configure your Identity Provider

Step 2: Choose What SCIM Manages

In the SCIM Provisioning settings, select which attributes your Identity Provider should control:

These settings define the boundary between IdP-managed and Fountain-managed data. Attributes you don't sync remain manually manageable in Fountain.

Step 3: Configure Your Identity Provider

The specific steps vary by Identity Provider, but the general process is:

  1. Create a SCIM application in your Identity Provider
  2. Enter connection details:
    • Paste your Fountain SCIM Base URL
    • Paste your Fountain Authentication Token (as Bearer token or OAuth)
  3. Enable provisioning actions:
    • Create users
    • Update user attributes
    • Deactivate users
  4. Map attributes from your IdP to Fountain (see Attribute Mapping section below)
  5. Assign users to the SCIM application

Fountain does not support SCIM Groups - only user provisioning is supported.

Attribute Mapping

SCIM allows you to map attributes from your Identity Provider to Fountain user attributes. This determines how user information and access permissions flow from your IdP to Fountain.

Required Attributes

At minimum, your Identity Provider must provide:

These are standard SCIM attributes and are automatically recognized by most Identity Providers.

Optional Attributes (Fountain Extension)

Fountain provides a custom SCIM extension to manage roles and access restrictions:

Extension Schema: urn:ietf:params:scim:schemas:extension:fountain:2.0:User

Attribute Type Purpose Notes
role String User role assignment Must match exact role name in Fountain
externalLocationIds Array of strings Location access Accepts Fountain Location IDs or exact location names
externalJobIds Array of strings Job/position access Accepts Fountain Job IDs or exact job names
externalLocationGroupIds Array of strings Location group access Accepts Fountain Location Group IDs or exact names
externalOpeningIds Array of strings Opening-level access Accepts Fountain Opening IDs

Attribute Behavior:

Example: For a location named "Atlanta" with UUID 3372067a-c2d5-4524-9525-1bcaf01fe586, either value is valid:

Attribute mapping is fully customizable based on your organization's needs and IdP capabilities. Any IdP attribute (standard or custom) can be mapped to Fountain attributes as long as data types match.

User Lifecycle Management

Creating Users

When a user is assigned to your SCIM application in your Identity Provider:

If a user already exists in Fountain before being assigned to the SCIM app, they will be upgraded to a SCIM-managed user. Their existing access may be overwritten based on your SCIM configuration.

Updating Users

When user attributes are updated in your Identity Provider:

Deactivating Users

When a user is unassigned from the SCIM application in your Identity Provider:

SCIM deactivates users but does not permanently delete them. User data is retained in Fountain for historical and compliance purposes.

Managing SCIM-Managed Users in Fountain

In Settings > Users, SCIM-managed users are identified with visual indicators:

Mixed User Management: You can have both SCIM-managed and manually-managed users in the same Fountain account:

Testing and Validation

Fountain recommends the following approach for initial SCIM setup:

Testing Environment

Invitation emails are automatically sent to users when they are provisioned via SCIM. During testing, consider using dummy/test email addresses to prevent unexpected notifications to real users.

Validation Steps

  1. Assign a test user in your Identity Provider
  2. Verify the user appears in Fountain with correct attributes
  3. Update the user's attributes in your IdP
  4. Confirm changes sync to Fountain
  5. Unassign the user and verify they are deactivated in Fountain
  6. Check SCIM logs in your Identity Provider for any errors

Troubleshooting

If SCIM provisioning doesn't behave as expected:

Check SCIM logs in your Identity Provider

Validate attribute mappings

Confirm SCIM scope selections in Fountain

Common Issues:

Identity Provider-Specific Guidance

The following sections provide specific configuration guidance for popular Identity Providers. While SCIM setup follows the same general principles across all providers, each has unique interface elements and configuration steps.

Okta Setup

Fountain's SCIM implementation works seamlessly with Okta. Here are the key configuration points to ensure successful setup:

Critical Configuration Details:

  1. App Selection: Use the SCIM 2.0 Test App (OAuth Bearer Token) from Okta's app catalog - this version matches Fountain's authentication method.
  2. Username Format: Set Application username format to "Okta username" - this determines how Okta identifies users when provisioning.
  3. Disable Groups: Uncheck Import Groups during integration setup - Fountain currently supports user provisioning only, not group provisioning.
  4. Provisioning Features: Enable these three actions in Provisioning > To App:
    • Create Users ✓
    • Update User Attributes ✓
    • Deactivate Users ✓
    • Sync Password ✗ (Leave disabled - passwords aren't needed for Fountain)

Custom Attribute Configuration:

To map Fountain roles and locations, you'll need to create custom attributes in Okta's Profile Editor:

For Role Mapping:

For Location Mapping:

The External name and External namespace values must match exactly. The Display name and Variable name can be customized to your organization's preferences.

What Happens After Configuration:

Once users are assigned to the SCIM app in Okta:

Microsoft Entra (formerly Azure AD) Setup

Fountain's SCIM implementation is fully compatible with Microsoft Entra ID provisioning.

In Microsoft Entra Admin Center:

  1. Create a Non-gallery Enterprise Application
  2. Enable Provisioning
  3. Select SCIM as the provisioning method
  4. Paste Fountain's Base URL and Authentication Token
  5. Entra will automatically discover all required SCIM metadata
  6. Configure attribute mappings in the Entra UI
  7. Assign users or groups to the application

Entra automatically handles:

Helpful Reference: Microsoft provides a SCIM setup video for DocuSign that follows the same process Fountain uses: https://youtu.be/6m9NY8pnjfs?t=99 (SCIM configuration occurs at 1:39-2:10)