Stitchflow
HireRight logo

HireRight SCIM guide

Connector Only

How to automate HireRight user provisioning, and what it actually costs

Summary and recommendation

HireRight, the background screening platform, does not support SCIM provisioning on any plan. While HireRight offers SAML 2.0 SSO integration with identity providers like Okta, Azure AD, and OneLogin, this only handles authentication for existing users. The platform's provisioning capabilities are limited to API integrations designed for ATS (Applicant Tracking System) platforms through HireRight Connect, not for general user lifecycle management. For IT teams managing access to background check workflows, this means manual user provisioning and deprovisioning—particularly problematic given that background check access often involves sensitive compliance data.

The lack of automated provisioning creates significant operational overhead for HR and compliance teams. While SSO prevents password-related security issues, IT admins must still manually create and remove user accounts, assign appropriate permissions based on role (HR generalist vs. recruiter vs. compliance officer), and ensure timely deprovisioning when employees change roles or leave. For organizations running frequent background checks or managing large recruiting teams, this manual process becomes a bottleneck that can delay hiring workflows and create compliance risks around data access.

The strategic alternative

HireRight has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaVia third-partyOIN integration available with SSO and provisioning features. Supports Group Linking, Schema Discovery, and Attribute Writeback.
Microsoft Entra IDVia third-partySAML SSO possible via custom enterprise app. No native Entra provisioning tutorial. Multiple IdPs supported including Azure AD.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages HireRight accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The HireRight pricing problem

HireRight gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
StandardPer-check pricing (varies by volume/type)

Pricing structure

PlanPricingSSOSCIM
StandardPer-check pricing (varies by volume/type)✓ SAML 2.0❌ Not available

HireRight uses per-check pricing that varies based on background check types and volume, rather than traditional seat-based SaaS pricing.

What this means in practice

Without SCIM support, IT teams must:

Manually create user accounts for each new hire in HR/recruiting
Handle all user updates (role changes, department moves) manually
Rely on manual processes for offboarding background check access
Coordinate account management across HR systems and HireRight separately

The SSO integration requires custom SAML configuration through your IdP, but users still need to be provisioned manually before they can authenticate.

Additional constraints

ATS-focused architecture
HireRight Connect API is designed for ATS platform integration, not user provisioning
Specialized workflow
Background check processes don't follow typical SaaS user lifecycle patterns
Custom SAML setup required
No pre-built IdP integrations beyond basic SAML templates
Limited user management features
Platform optimized for background check workflows, not user administration

Summary of challenges

  • HireRight does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What HireRight actually offers for identity

SAML SSO (Custom Configuration)

HireRight supports SAML 2.0 integration for single sign-on:

SettingDetails
ProtocolSAML 2.0
Supported IdPsOkta, Azure AD, OneLogin, generic SAML providers
ConfigurationCustom SAML application setup required
JIT Provisioning❌ Not supported
User ManagementManual provisioning required

Key limitation: HireRight's SSO requires custom SAML configuration and does not include just-in-time provisioning. Users must be manually created in HireRight before they can authenticate.

Okta Integration (via OIN)

The official Okta Integration Network listing for HireRight shows surprising provisioning capabilities:

FeatureSupported?
SAML SSO✓ Yes
Create users✓ Yes
Update users✓ Yes
Deactivate users✓ Yes
Group push✓ Yes
Schema Discovery✓ Yes
Attribute Writeback✓ Yes

However, this Okta provisioning uses a proprietary connector, not SCIM. Teams using other IdPs (Azure AD, Google Workspace, OneLogin) cannot access these provisioning features.

HireRight Connect API

For ATS platforms, HireRight offers API integration:

Purpose
Integrates background checks into hiring workflows
Target users
ATS platforms and recruiting software
User provisioning
Not designed for IT admin user management
Authentication
API keys, not federated identity

The gap: While HireRight has Okta provisioning, it lacks universal SCIM support for multi-IdP environments. Teams using Azure AD or Google Workspace are stuck with manual user management, and the API is built for recruiting workflows, not IT provisioning.

What IT admins are saying

HireRight's limited provisioning capabilities create manual overhead for IT teams managing background check workflows:

  • Manual user account creation required despite SSO availability
  • Complex custom SAML setup process for identity provider integration
  • No standardized user lifecycle management for background check access
  • API integration limited to ATS platforms, not general user provisioning

SSO available via custom SAML. Okta setup requires custom SAML app.

Okta support documentation

HireRight Connect API for ATS integration.

HireRight official documentation

The recurring theme

While HireRight offers SSO through custom SAML configurations, IT teams must manually provision users and manage their lifecycle separately from their identity provider, creating additional administrative burden for what should be an automated HR workflow.

The decision

Your SituationRecommendation
Small HR team with basic screening needsManual management is acceptable for low-volume background checks
Established recruiting team using ATS integrationLeverage HireRight Connect API for ATS workflow automation
Large enterprise with high-volume screening (100+ checks/month)Use Stitchflow: automation essential for user lifecycle management
Multi-location organization with compliance requirementsUse Stitchflow: automation essential for audit trail and consistent access control
HR team managing multiple background check vendorsUse Stitchflow: standardize provisioning across all HR tools

The bottom line

HireRight provides solid background screening services with SSO authentication, but offers no user provisioning automation beyond ATS API integration. For HR organizations that need systematic user lifecycle management across their screening workflows, Stitchflow delivers the automation that HireRight's platform lacks.

Make HireRight workflows AI-native

HireRight has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No public SCIM documentationSSO via custom SAML setupAPI for ATS integrations

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No public SCIM documentation
  • SSO via custom SAML setup
  • API for ATS integrations

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Where to enable

Okta Admin Console → Applications → HireRight → Sign On

OIN integration available with SSO and provisioning features. Supports Group Linking, Schema Discovery, and Attribute Writeback.

Use Stitchflow for automated provisioning.

Unlock SCIM for
HireRight

HireRight has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
HireRight logo
HireRight
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

6sense logo

6sense

No SCIM

B2B Revenue Intelligence / ABM

ProvisioningNot Supported
Manual Cost$11,754/yr

6sense, the B2B revenue intelligence platform, has paused SCIM provisioning for new customers until Q4 2026. While existing customers with SCIM enabled can continue using it, new implementations are limited to JIT (Just-In-Time) provisioning through SAML SSO. This creates a significant gap for IT teams managing revenue intelligence access, as JIT only creates users on first login and provides minimal attribute mapping (email, first name, last name only). For an enterprise platform with typical pricing of $55,000-$130,000 annually, the absence of automated user lifecycle management is a substantial limitation. The lack of SCIM until Q4 2026 forces IT teams into manual provisioning workflows for a platform handling sensitive revenue data. While SAML SSO handles authentication, it doesn't address user lifecycle events like role changes, department transfers, or offboarding. This creates compliance risks in revenue teams where access to prospect data and sales intelligence must be tightly controlled. The nearly two-year wait for SCIM restoration means organizations implementing 6sense today face manual user management for the foreseeable future.

View full guide
Aha! logo

Aha!

No SCIM

Product Management / Roadmapping

ProvisioningNot Supported
Manual Cost$11,754/yr

Aha! Roadmaps, the product roadmapping platform, does not support SCIM provisioning on any plan. While Aha! offers SAML 2.0 SSO integration with identity providers like Okta, Entra ID, and OneLogin, this only handles authentication through JIT (Just-In-Time) provisioning. The critical limitation: JIT provisioning creates user accounts with no default role or access permissions, requiring administrators to manually configure access for each user after they first sign in. For product teams managing strategic roadmaps and stakeholder access, this creates significant operational overhead. Since product roadmaps contain sensitive strategic information and stakeholder access typically varies by product area, IT administrators must manually assign appropriate roles and workspace permissions after each user is provisioned. There's no automatic deprovisioning when users leave the organization, creating potential security gaps. This manual process becomes particularly problematic for larger product organizations where dozens of stakeholders across different business units need carefully managed access to specific roadmaps.

View full guide
Appcues logo

Appcues

No SCIM

Product Adoption / User Onboarding

ProvisioningNot Supported
Manual Cost$11,754/yr

Appcues, the product adoption platform used by product managers and growth teams, explicitly does not support SCIM provisioning on any plan—not even Enterprise. While Appcues offers SAML 2.0 SSO integration starting at the Enterprise tier with just-in-time (JIT) provisioning, this only creates users during first login and provides no automated deprovisioning capabilities. For product teams where access needs change frequently as people move between projects or leave the company, this creates a significant security gap. The lack of SCIM means IT teams must manually manage user lifecycle for Appcues accounts, even though the platform handles sensitive product analytics and user flow data. When employees leave or change roles, their Appcues access remains active until manually revoked—a compliance risk that's particularly problematic given Appcues' role in tracking user behavior and product metrics. With MAU-based pricing starting at $300/month and scaling significantly with usage, paying for orphaned accounts also creates unnecessary cost bloat.

View full guide