Stitchflow
Atlan logo

Atlan SCIM guide

Native SCIM

How to automate Atlan user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Atlan supports native SCIM 2.0 provisioning with full user and group management capabilities. However, SCIM is only available on Enterprise tier, which requires custom pricing negotiations. Additionally, SSO must be enabled before SCIM can be configured, and Atlan's pricing tiers (Starter, Premier, Enterprise) are not publicly disclosed, making cost planning difficult for IT teams.

This creates a significant barrier for organizations wanting automated provisioning without committing to enterprise-level contracts. For data teams evaluating Atlan, the lack of transparent pricing means you can't budget for provisioning capabilities upfront. The SSO prerequisite also forces organizations into a specific implementation sequence that may not align with their rollout timeline.

The strategic alternative

Atlan gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Atlan accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Atlan pricing problem

Atlan gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
StarterCustom pricing
PremierCustom pricing
EnterpriseCustom pricing

Note: Atlan requires SSO to be enabled before SCIM can be configured. Both features are bundled exclusively in the Enterprise tier.

What this means in practice

Without public pricing, organizations face several procurement challenges:

Forced sales conversations
No self-service pricing means mandatory sales cycles for basic provisioning capabilities
Tier jumping
Teams using Starter or Premier must upgrade to Enterprise solely for user provisioning
Bundle bloat
SCIM comes packaged with enterprise governance features that smaller teams may not need
Negotiation complexity
Custom pricing makes budget planning and vendor comparison difficult

The lack of pricing transparency means IT teams can't quickly assess whether Atlan's SCIM costs justify the investment versus alternative provisioning approaches.

Additional constraints

SSO prerequisite
SCIM cannot be configured without first enabling SSO, creating an additional dependency chain.
Limited sync scope
Username and email are only synchronized during initial user provisioning, not on subsequent updates.
Token security
SCIM tokens are displayed only once after generation, creating potential recovery issues if not properly stored.
Tier gate everything
Both SSO and SCIM are locked to Enterprise, preventing gradual feature adoption.

Summary of challenges

  • Atlan supports SCIM but only at Enterprise tier (Custom (Enterprise tier))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Atlan doesn't sell SCIM à la carte. It's bundled with Enterprise tier features at undisclosed custom pricing:

SCIM 2.0 automated provisioning
SAML single sign-on (SSO) - required before SCIM setup
Advanced workspace governance
Enhanced data lineage and cataloging
Enterprise security controls
Dedicated customer success
Priority technical support

The challenge: Atlan keeps all pricing tiers (Starter, Premier, Enterprise) behind custom quotes, making it impossible to evaluate costs upfront. You'll need to go through their sales process just to understand what you'll pay for Enterprise features you may not need.

Stitchflow Insight

If you need comprehensive data governance anyway, the Enterprise upgrade may make sense. If you just want automated user provisioning, you're locked into an expensive bundle with features most IT teams won't use. We estimate ~60% of Enterprise features are irrelevant for teams that only need SCIM provisioning.

What IT admins are saying

Community sentiment on Atlan's SCIM implementation reveals frustration with the gatekeeping approach. Common complaints:

  • Requiring Enterprise tier for basic SCIM provisioning
  • Hidden pricing that forces sales conversations for basic features
  • SSO prerequisite adding another layer of complexity
  • Username/email sync limitations that break on user updates

Having to enable SSO first before SCIM just adds unnecessary friction to the setup process. Why can't these be independent?

Reddit r/sysadmin

Another vendor hiding their pricing behind 'contact sales' - just tell us what Enterprise costs so we can budget properly.

Spiceworks Community

The recurring theme

Atlan treats SCIM as an enterprise-only luxury rather than a standard identity management requirement, forcing teams into opaque pricing conversations for basic provisioning capabilities.

The decision

Your SituationRecommendation
On Starter or Premier, need SCIMUse Stitchflow: avoid the Enterprise tier upgrade
Already on Enterprise tierUse native SCIM: you're paying for it
Need Enterprise features beyond SCIMEvaluate Enterprise: SCIM comes bundled
Can't enable SSO due to organizational constraintsUse Stitchflow: bypasses the SSO prerequisite
Small data team, minimal user changesManual may work: but watch for data access sprawl

The bottom line

Atlan's SCIM requires both Enterprise tier pricing and SSO enablement—two significant barriers for teams that simply want automated user provisioning. For organizations on lower tiers or those with SSO constraints, Stitchflow delivers the same provisioning outcomes without the tier jump or prerequisites.

Make Atlan workflows AI-native

Atlan gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SSO must be enabled before configuring SCIM
  • Pricing tiers (Starter, Premier, Enterprise) not publicly disclosed
  • Username and email only synced on initial provisioning
  • SCIM token displayed only once after generation

Documentation not available.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Atlan → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Full SCIM provisioning support with Azure AD. Azure AD SSO must be enabled first. Supports user creation, updates, and group sync.

Atlan gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Atlan

Atlan gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Atlan logo
Atlan
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Alteryx logo

Alteryx

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Alteryx supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (7+ users minimum). The feature requires SSO (SAML or OIDC) to be configured first and completely overrides manual user management. For teams on Professional ($5,000/user/year) or Business ($10,000-$20,000/user/year) plans, accessing SCIM means upgrading to Enterprise - often a significant cost increase for functionality that should be table stakes. This creates a provisioning gap for most Alteryx deployments. Without automated user lifecycle management, IT teams face manual onboarding/offboarding workflows, delayed access provisioning, and compliance risks around orphaned accounts. The high per-user costs make Alteryx particularly expensive to scale, and forcing an Enterprise upgrade just for basic provisioning automation compounds that challenge.

View full guide
Benchling logo

Benchling

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Benchling supports SCIM provisioning, but only on Enterprise plans with custom pricing that typically starts at $1M+ annually. This creates a massive barrier: organizations on Professional plans ($20,000+/year) face a 50x+ price increase to unlock automated user provisioning. Even mid-sized life sciences teams end up paying enterprise-level licensing just to automate basic user lifecycle management. The pricing gap is so extreme that most organizations either stick with manual provisioning or delay Benchling adoption entirely. This creates a significant operational burden for IT teams managing researchers across multiple lab environments. Manual user provisioning in a platform that handles sensitive R&D data introduces compliance risks and delays researcher onboarding. When a scientist joins or leaves, IT must manually coordinate access across Benchling's complex permission structure for notebooks, entities, and workflows. For organizations with frequent collaborator access or seasonal research teams, this becomes unmanageable.

View full guide
Bitrise logo

Bitrise

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Bitrise supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing and a minimum 10-seat commitment. For teams on Starter or Pro plans, there's no path to automated user provisioning—you're limited to manual account management even with SSO configured. This creates a significant operational burden for IT teams managing developer access to CI/CD pipelines. The pricing gap is particularly problematic for smaller development teams. Moving from Pro (build-based pricing) to Enterprise just for SCIM means paying for enterprise features like advanced security controls and priority support that many teams don't need. Without automated provisioning, IT admins must manually onboard developers, manage workspace memberships through groups, and handle offboarding—creating security risks when former employees retain access to build systems and deployment pipelines.

View full guide