Stitchflow
Lattice logo

Lattice SCIM guide

Native SCIM

How to automate Lattice user provisioning, and what it actually costs

Native SCIM requires Enterprise (likely) plan

Summary and recommendation

Lattice supports SCIM 2.0 for automated user provisioning, but only on Enterprise plans with custom pricing that typically starts well above their base $11/user/month talent management pricing. More problematically, Lattice's SCIM implementation has significant gaps: no Groups support, no bulk updates, and missing Azure-specific features like patch and filter operations. For people management platforms where accurate manager hierarchies and team structures are critical for performance reviews, these limitations create ongoing provisioning headaches.

The Groups limitation is particularly painful for HR teams who need to provision employees into the right organizational units and reporting structures. Without Groups, you're stuck with manual assignment of team memberships and manager relationships—exactly the kind of repetitive work SCIM should eliminate. For a platform built around performance management and org charts, this creates a disconnect between your identity provider's understanding of your organization and how it's represented in Lattice.

The strategic alternative

Lattice gates SCIM behind Enterprise (likely). Skip the Enterprise (likely) plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Lattice accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Lattice pricing problem

Lattice gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
Talent Management$11/user/mo (annual)
HRIS$10/user/mo (annual)
EnterpriseCustom pricing

Note: SCIM 2.0 API is only available on Enterprise plans. Standard plans require manual user management or CSV imports for bulk operations.

What this means in practice

With Enterprise pricing hidden behind "contact sales," organizations face:

Team SizeAnnual Minimum*Likely Enterprise Cost
50 users$4,000$15,000-25,000+
100 users$4,000$30,000-50,000+
200 users$4,000$60,000-100,000+

Lattice enforces a $4,000 annual minimum contract *Estimates based on typical SaaS Enterprise tier premiums (3-5x standard pricing)

Additional constraints

Sales-gated pricing
No transparent Enterprise pricing means lengthy sales cycles to understand actual costs.
Limited SCIM features
Even with Enterprise access, Lattice doesn't support SCIM Groups, bulk updates, or Azure-specific patch/filter operations.
Azure compatibility gaps
Microsoft customers face additional limitations with patch operations and advanced filtering not supported.
Custom field restrictions
Cannot map SCIM attributes to default Job Architecture or Compensation fields, limiting organizational structure automation.

Summary of challenges

  • Lattice supports SCIM but only at Enterprise tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Lattice doesn't sell SCIM separately. It's bundled with Enterprise-tier features at custom pricing (likely $15K+ annually for most organizations):

SCIM 2.0 automated provisioning (with significant limitations)
SAML single sign-on (SSO)
Advanced people analytics and reporting
Performance calibration tools
Goal alignment across departments
Custom field mapping
Priority support and dedicated customer success

The SCIM implementation itself has notable gaps: no Groups support, no bulk updates, and missing Azure-specific features like patch/filter operations. This means you're paying enterprise prices for incomplete automation.

Stitchflow Insight

If you need comprehensive people management platform features anyway, the upgrade makes sense. If you just want reliable user provisioning for performance reviews and manager hierarchies, you're paying for enterprise HR tools you may not fully utilize. We estimate ~60% of Enterprise features are irrelevant for teams that primarily need automated user lifecycle management.

What IT admins are saying

Community sentiment on Lattice's SCIM implementation is mixed, with specific technical limitations being the primary concern. Common complaints:

  • SCIM Groups functionality is completely missing
  • Azure-specific SCIM features (patch/filter operations) aren't supported
  • Limited attribute mapping for Job Architecture and Compensation fields
  • Enterprise pricing requirement creates cost barriers for smaller teams

SCIM Groups not supported - this is a major limitation for managing team-based access in performance management tools.

IT Admin, Reddit

Azure patch and filter options missing makes automation much more manual than it should be.

Identity Management Forum

The recurring theme

Lattice's SCIM works for basic user provisioning but falls short on advanced features that IT teams expect from enterprise-grade identity automation, particularly for Azure environments.

The decision

Your SituationRecommendation
Need SCIM but not on Enterprise tierUse Stitchflow: avoid the Enterprise upgrade and minimum $4K/year commitment
On Enterprise but hitting SCIM limitationsUse Stitchflow: get full Groups support and Azure patch/filter capabilities
Already on Enterprise with SCIM workingStick with native: you're paying for it and it covers basic provisioning
Need manager hierarchies synced accuratelyUse Stitchflow: critical for performance review cycles and reporting structures
Small team with infrequent changesManual may work: but monitor for missed updates during review periods

The bottom line

Lattice gates SCIM behind Enterprise (likely). Stitchflow automates complete workflows without that SCIM Tax upgrade.

Make Lattice workflows AI-native

Lattice gates SCIM behind Enterprise (likely). We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise (likely) upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • No SCIM Groups support
  • No SCIM bulk updates
  • Azure patch and filter options not supported
  • Cannot map to default Job Architecture or Compensation fields

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Lattice → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

SCIM API enabled via Admin > Settings > Platform > Integrations. Lattice HRIS can also act as profile source for Okta.

Lattice gates SCIM behind Enterprise (likely). Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Lattice → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

No official Azure gallery app - requires custom non-gallery setup. Does not support SCIM Groups, bulk updates, or Azure patch/filter options.

Lattice gates SCIM behind Enterprise (likely). Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Lattice

Lattice gates SCIM behind Enterprise (likely) plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Lattice logo
Lattice
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Amplitude logo

Amplitude

SCIM Tax

Product Analytics

SCIM StatusIncluded
Manual Cost$11,754/yr

Amplitude supports SCIM provisioning, but only on Growth plans (starting around $36K/year) or Enterprise plans with custom pricing. While Amplitude's SCIM implementation covers the core functionality—creating, updating, and deactivating users—it requires SCIM to be specifically enabled for your organization, and regenerating the SCIM key immediately invalidates existing integrations without warning. For product teams on Plus plans ($49/month), upgrading to Growth just to unlock SCIM means jumping from under $600/year to $36,000+/year—a 60x increase. That's often more than the entire analytics budget for smaller product teams. The gap becomes particularly problematic for cross-functional product teams where analysts, PMs, and engineers need varying levels of access to user behavior data, but manual provisioning creates security risks around sensitive analytics permissions.

View full guide
Bugsnag logo

Bugsnag

SCIM Tax

Error Monitoring / Observability

SCIM StatusIncluded
Manual Cost$11,754/yr

Bugsnag supports native SCIM provisioning, but only on Enterprise plans with custom pricing. This creates a significant cost barrier since you must upgrade from Business ($475/month for 1M events) to Enterprise just to unlock automated user provisioning. For many engineering teams, this represents a substantial price jump for provisioning features that should be standard across all paid plans. The Enterprise requirement is particularly problematic for mid-size development teams who need error monitoring automation but don't require Enterprise-level features. Without SCIM, IT teams must manually provision developer accounts and manage team memberships for project access—creating security gaps when developers change teams or leave the company. OneLogin users face an additional limitation: SCIM isn't supported on Enterprise instances, forcing a workaround through the standard Bugsnag app.

View full guide
Greenhouse logo

Greenhouse

SCIM Tax

HR / Recruiting

SCIM StatusIncluded
Manual Cost$11,754/yr

Greenhouse supports SCIM provisioning, but only on Advanced or Expert tiers (starting around $6,000/year, quote-based). The bigger issue: Greenhouse's SCIM implementation only provisions users—not groups—meaning you lose the organizational structure and permission inheritance that makes identity management scalable. Additionally, you cannot fully delete users via SCIM (only deactivate), and Azure Entra users face a 40-minute sync delay. For recruiting teams managing hiring managers, interviewers, and HR staff across different departments and access levels, the lack of group provisioning creates a significant operational burden. You're forced to manually assign permissions and manage access changes for every user individually. With recruiting involving sensitive candidate data and frequent access changes during hiring cycles, this manual overhead increases both security risk and administrative workload.

View full guide