Stitchflow
Domino Data Lab logo

Domino Data Lab SCIM guide

Native SCIM

How to automate Domino Data Lab user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Domino Data Lab supports SCIM provisioning, but only on Enterprise plans with custom pricing that includes per-user licensing plus consumption-based cloud units. This creates a significant barrier for data science teams that need automated user management but don't require enterprise-grade features like advanced governance controls or multi-cloud deployment options. The custom pricing model makes it difficult to predict costs, especially with variable consumption charges.

For teams on Pro or Business plans, the leap to Enterprise represents a substantial investment increase that often includes features unnecessary for core data science workflows. This forces organizations to choose between manual user management (creating security gaps and administrative overhead) or paying for enterprise capabilities they don't need. SSO alone doesn't solve the provisioning problem - IT teams still face manual account creation, role assignment, and deactivation processes.

The strategic alternative

Domino Data Lab gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Domino Data Lab accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Domino Data Lab pricing problem

Domino Data Lab gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
ProCustom (Data Analyst License)
BusinessCustom (Data Science Professional License)
EnterpriseCustom + Domino Cloud Consumption Units

Plan Structure

PlanPriceSCIM
ProCustom (Data Analyst License)
BusinessCustom (Data Science Professional License)
EnterpriseCustom + Domino Cloud Consumption Units

What this means in practice

Domino's pricing opacity creates significant budget uncertainty. The Enterprise tier includes:

Custom per-user licensing
No published rates for data science professional seats
Consumption units
Additional charges based on compute resource usage (CPU, GPU, memory)
Deployment premium
Choice between managed SaaS or self-managed VPC deployment

Without transparent pricing, organizations cannot predict total cost of ownership. Mid-market teams often find the Enterprise tier financially prohibitive, especially when factoring in both seat licenses and compute consumption charges.

Additional constraints

Dual pricing model
Per-user seats plus consumption units create unpredictable monthly costs.
Role mapping complexity
Requires exact group name matches between IdP and Domino for proper role assignment.
Deployment dependency
SCIM configuration varies between Domino Cloud (SaaS) and self-managed VPC options.
Enterprise sales cycle
Custom pricing requires lengthy procurement discussions, delaying implementation.

Summary of challenges

  • Domino Data Lab supports SCIM but only at Enterprise tier (Custom + Domino Cloud Consumption Units)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Domino Data Lab doesn't sell SCIM à la carte. It's bundled with Enterprise features:

SCIM automated provisioning (Create/Update/Deactivate)
SAML 2.0 and OIDC single sign-on (SSO)
Advanced security controls and audit logging
Role-based access controls with group mapping
Dedicated VPC deployment options
Enterprise-grade compute resource management
Premium support and professional services
Advanced collaboration and governance features

Stitchflow Insight

The Enterprise tier requires custom pricing with per-user licensing plus Domino Cloud Consumption Units—a complex cost model that scales with both users and compute usage. If you need the advanced MLOps governance and security controls, the upgrade delivers value. If you just want automated user provisioning for your data science team, you're paying for extensive platform capabilities you likely won't use. We estimate ~75% of Enterprise features are irrelevant for teams that only need SCIM provisioning.

What IT admins are saying

Community sentiment on Domino Data Lab's SCIM implementation is mixed, with frustrations centered on enterprise-only access and deployment complexity. Common complaints:

  • Enterprise pricing requirement locks out smaller data science teams
  • Complex deployment model with VPC vs. managed cloud decisions
  • Azure AD integration requires precise SAML attribute mapping
  • Role mapping breaks with any group name changes in IdP

The role mapping is brittle - if you rename a group in Azure AD, provisioning just stops working until you manually fix the configuration.

Reddit, r/sysadmin

We're a 20-person data team and they want us to pay enterprise pricing just to get automated user provisioning. The ROI doesn't work for our size.

IT Admin, Healthcare startup

The recurring theme

Enterprise-only SCIM pricing excludes smaller teams, while the technical implementation requires ongoing manual maintenance that defeats the automation purpose.

The decision

Your SituationRecommendation
On Pro or Business, need SCIMUse Stitchflow: avoid the Enterprise upgrade costs
Already on EnterpriseUse native SCIM: you're paying for it
Need advanced ML governance beyond SCIMEvaluate Enterprise: SCIM comes bundled with compliance features
Self-managed deployment with complex SSOUse Stitchflow: avoid SAML attribute mapping complexities
Small data science team, low user churnManual may be tolerable: but monitor for security gaps

The bottom line

Domino Data Lab gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Make Domino Data Lab workflows AI-native

Domino Data Lab gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

None

Key limitations

  • Enterprise pricing with per-user licensing
  • Deployment options: Domino Cloud (managed SaaS) or self-managed VPC
  • Azure AD requires Enterprise application with SAML SSO
  • Role mapping requires exact group name matches

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Where to enable

Okta Admin Console → Applications → Domino Data Lab → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Okta integration supports Create, Update, and Deactivate provisioning. SSO via SAML 2.0 or OIDC. Supports role assignment via Okta groups.

Domino Data Lab gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Where to enable

Entra admin center → Enterprise applications → Domino Data Lab → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

SSO via SAML 2.0 with Azure AD. User provisioning supported through SSO integration. Must configure SAML attribute claims.

Domino Data Lab gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Domino Data Lab

Domino Data Lab gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Domino Data Lab logo
Domino Data Lab
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Alteryx logo

Alteryx

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Alteryx supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (7+ users minimum). The feature requires SSO (SAML or OIDC) to be configured first and completely overrides manual user management. For teams on Professional ($5,000/user/year) or Business ($10,000-$20,000/user/year) plans, accessing SCIM means upgrading to Enterprise - often a significant cost increase for functionality that should be table stakes. This creates a provisioning gap for most Alteryx deployments. Without automated user lifecycle management, IT teams face manual onboarding/offboarding workflows, delayed access provisioning, and compliance risks around orphaned accounts. The high per-user costs make Alteryx particularly expensive to scale, and forcing an Enterprise upgrade just for basic provisioning automation compounds that challenge.

View full guide
Atlan logo

Atlan

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Atlan supports native SCIM 2.0 provisioning with full user and group management capabilities. However, SCIM is only available on Enterprise tier, which requires custom pricing negotiations. Additionally, SSO must be enabled before SCIM can be configured, and Atlan's pricing tiers (Starter, Premier, Enterprise) are not publicly disclosed, making cost planning difficult for IT teams. This creates a significant barrier for organizations wanting automated provisioning without committing to enterprise-level contracts. For data teams evaluating Atlan, the lack of transparent pricing means you can't budget for provisioning capabilities upfront. The SSO prerequisite also forces organizations into a specific implementation sequence that may not align with their rollout timeline.

View full guide
Benchling logo

Benchling

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Benchling supports SCIM provisioning, but only on Enterprise plans with custom pricing that typically starts at $1M+ annually. This creates a massive barrier: organizations on Professional plans ($20,000+/year) face a 50x+ price increase to unlock automated user provisioning. Even mid-sized life sciences teams end up paying enterprise-level licensing just to automate basic user lifecycle management. The pricing gap is so extreme that most organizations either stick with manual provisioning or delay Benchling adoption entirely. This creates a significant operational burden for IT teams managing researchers across multiple lab environments. Manual user provisioning in a platform that handles sensitive R&D data introduces compliance risks and delays researcher onboarding. When a scientist joins or leaves, IT must manually coordinate access across Benchling's complex permission structure for notebooks, entities, and workflows. For organizations with frequent collaborator access or seasonal research teams, this becomes unmanageable.

View full guide