SCIM automates the user lifecycle from your IdP: joiners get provisioned with the right role and team, movers get updated, leavers get deprovisioned same-day. Available on Enterprise; pairs with SSO.
What SCIM automates
Create (new hire in IdP group → turgo user with mapped role/team), update (group change → role/scope change), deactivate (offboarded in IdP → deprovisioned in turgo, conversations reassigned per your rules).
Setup
Settings → Security → SCIM → generate the SCIM token and base URL; paste into your IdP's provisioning config (Okta/Entra guides inline). Map IdP groups to turgo roles and teams in the mapping table.
Deprovisioning rules
Define what happens to a departing user's assets: conversations → pool or named successor, sequences and workflows → team ownership, API keys → auto-revoked. Configure once; offboarding becomes a non-event.
Audit
Every SCIM operation logs with the IdP as the actor. The provisioning log is the answer to "why did this account appear/disappear" — check it before assuming a mystery.