Summary and recommendation
HireRight, the background screening platform, does not support SCIM provisioning on any plan. While HireRight offers SAML 2.0 SSO integration with identity providers like Okta, Azure AD, and OneLogin, this only handles authentication for existing users. The platform's provisioning capabilities are limited to API integrations designed for ATS (Applicant Tracking System) platforms through HireRight Connect, not for general user lifecycle management. For IT teams managing access to background check workflows, this means manual user provisioning and deprovisioning—particularly problematic given that background check access often involves sensitive compliance data.
The lack of automated provisioning creates significant operational overhead for HR and compliance teams. While SSO prevents password-related security issues, IT admins must still manually create and remove user accounts, assign appropriate permissions based on role (HR generalist vs. recruiter vs. compliance officer), and ensure timely deprovisioning when employees change roles or leave. For organizations running frequent background checks or managing large recruiting teams, this manual process becomes a bottleneck that can delay hiring workflows and create compliance risks around data access.
The strategic alternative
HireRight has no native SCIM. That leaves a workflow gap in offboarding, access reviews, and license cleanup unless your team handles the app another way. Stitchflow builds and maintains the IT workflows your team still runs manually, across every app, including the ones without APIs.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | Via third-party | ❌ | OIN integration available with SSO and provisioning features. Supports Group Linking, Schema Discovery, and Attribute Writeback. |
| Microsoft Entra ID | Via third-party | ❌ | SAML SSO possible via custom enterprise app. No native Entra provisioning tutorial. Multiple IdPs supported including Azure AD. |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages HireRight accounts manually. Here's what that costs:
The HireRight pricing problem
HireRight gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Standard | Per-check pricing (varies by volume/type) |
Pricing structure
| Plan | Pricing | SSO | SCIM |
|---|---|---|---|
| Standard | Per-check pricing (varies by volume/type) | ✓ SAML 2.0 | ❌ Not available |
HireRight uses per-check pricing that varies based on background check types and volume, rather than traditional seat-based SaaS pricing.
What this means in practice
Without SCIM support, IT teams must:
The SSO integration requires custom SAML configuration through your IdP, but users still need to be provisioned manually before they can authenticate.
Additional constraints
Summary of challenges
- HireRight does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What HireRight actually offers for identity
SAML SSO (Custom Configuration)
HireRight supports SAML 2.0 integration for single sign-on:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, Azure AD, OneLogin, generic SAML providers |
| Configuration | Custom SAML application setup required |
| JIT Provisioning | ❌ Not supported |
| User Management | Manual provisioning required |
Key limitation: HireRight's SSO requires custom SAML configuration and does not include just-in-time provisioning. Users must be manually created in HireRight before they can authenticate.
Okta Integration (via OIN)
The official Okta Integration Network listing for HireRight shows surprising provisioning capabilities:
| Feature | Supported? |
|---|---|
| SAML SSO | ✓ Yes |
| Create users | ✓ Yes |
| Update users | ✓ Yes |
| Deactivate users | ✓ Yes |
| Group push | ✓ Yes |
| Schema Discovery | ✓ Yes |
| Attribute Writeback | ✓ Yes |
However, this Okta provisioning uses a proprietary connector, not SCIM. Teams using other IdPs (Azure AD, Google Workspace, OneLogin) cannot access these provisioning features.
HireRight Connect API
For ATS platforms, HireRight offers API integration:
The gap: While HireRight has Okta provisioning, it lacks universal SCIM support for multi-IdP environments. Teams using Azure AD or Google Workspace are stuck with manual user management, and the API is built for recruiting workflows, not IT provisioning.
What IT admins are saying
HireRight's limited provisioning capabilities create manual overhead for IT teams managing background check workflows:
- Manual user account creation required despite SSO availability
- Complex custom SAML setup process for identity provider integration
- No standardized user lifecycle management for background check access
- API integration limited to ATS platforms, not general user provisioning
SSO available via custom SAML. Okta setup requires custom SAML app.
HireRight Connect API for ATS integration.
The recurring theme
While HireRight offers SSO through custom SAML configurations, IT teams must manually provision users and manage their lifecycle separately from their identity provider, creating additional administrative burden for what should be an automated HR workflow.
The decision
| Your Situation | Recommendation |
|---|---|
| Small HR team with basic screening needs | Manual management is acceptable for low-volume background checks |
| Established recruiting team using ATS integration | Leverage HireRight Connect API for ATS workflow automation |
| Large enterprise with high-volume screening (100+ checks/month) | Use Stitchflow: automation essential for user lifecycle management |
| Multi-location organization with compliance requirements | Use Stitchflow: automation essential for audit trail and consistent access control |
| HR team managing multiple background check vendors | Use Stitchflow: standardize provisioning across all HR tools |
The bottom line
HireRight has no native SCIM. That means one more workflow gap in offboarding, access reviews, and license cleanup unless your team handles it another way.
Close the HireRight workflow gap
HireRight is one gap in a broader workflow. Stitchflow builds and maintains the offboarding, access review, or license workflow across every app in your environment.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- No public SCIM documentation
- SSO via custom SAML setup
- API for ATS integrations
Documentation not available.
Configuration for Okta
Integration type
Okta Integration Network (OIN) app
Where to enable
Docs
OIN integration available with SSO and provisioning features. Supports Group Linking, Schema Discovery, and Attribute Writeback.
Use Stitchflow for automated provisioning.
Close the workflow gap in
HireRight
HireRight has no native SCIM. That leaves one more workflow gap in offboarding, access reviews, and license cleanup unless your team handles it another way.
Start with the free gap diagnostic


