Summary and recommendation
HireRight, the background screening platform, does not support SCIM provisioning on any plan. While HireRight offers SAML 2.0 SSO integration with identity providers like Okta, Azure AD, and OneLogin, this only handles authentication for existing users. The platform's provisioning capabilities are limited to API integrations designed for ATS (Applicant Tracking System) platforms through HireRight Connect, not for general user lifecycle management. For IT teams managing access to background check workflows, this means manual user provisioning and deprovisioning—particularly problematic given that background check access often involves sensitive compliance data.
The lack of automated provisioning creates significant operational overhead for HR and compliance teams. While SSO prevents password-related security issues, IT admins must still manually create and remove user accounts, assign appropriate permissions based on role (HR generalist vs. recruiter vs. compliance officer), and ensure timely deprovisioning when employees change roles or leave. For organizations running frequent background checks or managing large recruiting teams, this manual process becomes a bottleneck that can delay hiring workflows and create compliance risks around data access.
The strategic alternative
HireRight has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | Via third-party | ❌ | OIN integration available with SSO and provisioning features. Supports Group Linking, Schema Discovery, and Attribute Writeback. |
| Microsoft Entra ID | Via third-party | ❌ | SAML SSO possible via custom enterprise app. No native Entra provisioning tutorial. Multiple IdPs supported including Azure AD. |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages HireRight accounts manually. Here's what that costs:
The HireRight pricing problem
HireRight gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Standard | Per-check pricing (varies by volume/type) |
Pricing structure
| Plan | Pricing | SSO | SCIM |
|---|---|---|---|
| Standard | Per-check pricing (varies by volume/type) | ✓ SAML 2.0 | ❌ Not available |
HireRight uses per-check pricing that varies based on background check types and volume, rather than traditional seat-based SaaS pricing.
What this means in practice
Without SCIM support, IT teams must:
The SSO integration requires custom SAML configuration through your IdP, but users still need to be provisioned manually before they can authenticate.
Additional constraints
Summary of challenges
- HireRight does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What HireRight actually offers for identity
SAML SSO (Custom Configuration)
HireRight supports SAML 2.0 integration for single sign-on:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, Azure AD, OneLogin, generic SAML providers |
| Configuration | Custom SAML application setup required |
| JIT Provisioning | ❌ Not supported |
| User Management | Manual provisioning required |
Key limitation: HireRight's SSO requires custom SAML configuration and does not include just-in-time provisioning. Users must be manually created in HireRight before they can authenticate.
Okta Integration (via OIN)
The official Okta Integration Network listing for HireRight shows surprising provisioning capabilities:
| Feature | Supported? |
|---|---|
| SAML SSO | ✓ Yes |
| Create users | ✓ Yes |
| Update users | ✓ Yes |
| Deactivate users | ✓ Yes |
| Group push | ✓ Yes |
| Schema Discovery | ✓ Yes |
| Attribute Writeback | ✓ Yes |
However, this Okta provisioning uses a proprietary connector, not SCIM. Teams using other IdPs (Azure AD, Google Workspace, OneLogin) cannot access these provisioning features.
HireRight Connect API
For ATS platforms, HireRight offers API integration:
The gap: While HireRight has Okta provisioning, it lacks universal SCIM support for multi-IdP environments. Teams using Azure AD or Google Workspace are stuck with manual user management, and the API is built for recruiting workflows, not IT provisioning.
What IT admins are saying
HireRight's limited provisioning capabilities create manual overhead for IT teams managing background check workflows:
- Manual user account creation required despite SSO availability
- Complex custom SAML setup process for identity provider integration
- No standardized user lifecycle management for background check access
- API integration limited to ATS platforms, not general user provisioning
SSO available via custom SAML. Okta setup requires custom SAML app.
HireRight Connect API for ATS integration.
The recurring theme
While HireRight offers SSO through custom SAML configurations, IT teams must manually provision users and manage their lifecycle separately from their identity provider, creating additional administrative burden for what should be an automated HR workflow.
The decision
| Your Situation | Recommendation |
|---|---|
| Small HR team with basic screening needs | Manual management is acceptable for low-volume background checks |
| Established recruiting team using ATS integration | Leverage HireRight Connect API for ATS workflow automation |
| Large enterprise with high-volume screening (100+ checks/month) | Use Stitchflow: automation essential for user lifecycle management |
| Multi-location organization with compliance requirements | Use Stitchflow: automation essential for audit trail and consistent access control |
| HR team managing multiple background check vendors | Use Stitchflow: standardize provisioning across all HR tools |
The bottom line
HireRight provides solid background screening services with SSO authentication, but offers no user provisioning automation beyond ATS API integration. For HR organizations that need systematic user lifecycle management across their screening workflows, Stitchflow delivers the automation that HireRight's platform lacks.
Make HireRight workflows AI-native
HireRight has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- No public SCIM documentation
- SSO via custom SAML setup
- API for ATS integrations
Documentation not available.
Configuration for Okta
Integration type
Okta Integration Network (OIN) app
Where to enable
Docs
OIN integration available with SSO and provisioning features. Supports Group Linking, Schema Discovery, and Attribute Writeback.
Use Stitchflow for automated provisioning.
Unlock SCIM for
HireRight
HireRight has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.
See how it works


