Directory Sync (SCIM)
Directory Sync lets you automatically provision and deprovision OneCal team members from your identity provider. When someone joins your company, they are added to your OneCal team automatically. When they leave, their access is removed automatically.
Directory Sync requires SSO to be set up for your organization first.
Enable Directory Sync
Directory Sync is enabled on request. Reach out to us at contact@onecal.io, and our team will guide you through connecting your identity provider.
Once your workspace has SSO enabled, a Directory Sync button also appears on the Team page next to the invite form.
How provisioning works
When a user is created or activated in your directory:
- They are added to your OneCal team as a Member, and a seat is added to your subscription.
- They receive an email letting them know your organization added them to your workspace, and that they can sign in with your organization's SSO. No invite acceptance is needed.
- If they already had a personal OneCal account, it is merged into your team.
When a user is deactivated or deleted in your directory:
- They are removed from your team, and their seat is released.
- Their OneCal account is deleted.
Good To Know
The workspace Owner is never removed by Directory Sync, even if their directory account is deactivated. Group memberships in your directory are not mapped to OneCal roles, only user creation, updates and deletion are processed.
Audit trail
Every member added or removed by Directory Sync is recorded in your Audit Logs, with "System" shown as the actor, so you can always review what your directory changed.