Stitchflow
Orca Security logo

Orca Security SCIM guide

Native SCIM

How to automate Orca Security user provisioning, and what it actually costs

Native SCIM requires Custom plan

Summary and recommendation

Orca Security supports native SCIM 2.0 provisioning with full functionality through both Okta and Microsoft Entra. However, SCIM is only available on Enterprise plans with custom pricing, and requires SSO to be configured first as a prerequisite. This creates a significant barrier for organizations that want automated user provisioning but don't need the full enterprise feature set.

The custom pricing model means you'll need to go through a sales process to even understand the cost, and enterprise security platforms typically start in the tens of thousands annually. For mid-market organizations or those with smaller security teams, paying enterprise rates just to unlock basic user lifecycle management creates unnecessary budget strain. SSO alone doesn't solve the operational overhead of manually managing user accounts as your team grows.

The strategic alternative

Orca Security gates SCIM behind Custom. Skip the Custom plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredCustom
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Orca Security accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Orca Security pricing problem

Orca Security gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
ProCustom
BusinessCustom
EnterpriseCustom

Note: All Orca Security pricing is custom, making cost comparison difficult for IT teams during budget planning cycles.

What this means in practice

The custom pricing model creates several challenges:

Budget uncertainty
No published pricing means extended sales cycles and unpredictable costs during annual planning
Negotiation leverage
Vendors with opaque pricing often extract higher fees from organizations that need specific features like SCIM
Procurement friction
Custom contracts require legal review, extending deployment timelines
Scaling complexity
Future user growth costs are unclear without transparent per-user rates

Additional constraints

SSO prerequisite
SCIM configuration requires SSO to be enabled and configured first, adding implementation complexity.
Enterprise-only bundling
SCIM access is bundled with other enterprise features you may not need, potentially inflating costs.
Contract negotiation
Custom pricing requires dedicated procurement resources and extended sales processes.

Summary of challenges

  • Orca Security supports SCIM but only at Custom tier (Custom)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Orca Security doesn't sell SCIM à la carte. It's bundled with their Enterprise tier at custom pricing:

SCIM 2.0 automated provisioning
SAML single sign-on (SSO) - required before SCIM setup
Advanced role-based access controls
Custom security policies and compliance frameworks
Priority support and dedicated customer success
Advanced reporting and analytics
API access for custom integrations
Enhanced data retention policies

Stitchflow Insight

The custom pricing model means you're negotiating for an enterprise security platform, not just user provisioning. If you need comprehensive cloud security posture management anyway, the bundle makes sense. If you just want automated user provisioning for your existing security stack, you're paying enterprise rates for capabilities you won't use. We estimate ~60% of Enterprise features are overkill for teams that only need SCIM provisioning.

What IT admins are saying

Community sentiment on Orca Security's SCIM implementation is mixed, with cost and complexity being primary concerns:

  • Custom pricing creates budget uncertainty and lengthy procurement cycles
  • SSO prerequisite adds configuration complexity and potential failure points
  • Enterprise-only SCIM excludes growing security teams on smaller budgets
  • Lack of transparent pricing makes ROI calculations difficult

Another security vendor that won't show pricing until you're deep in a sales process. Makes it impossible to budget properly.

r/sysadmin

Had to implement SSO first before SCIM would work. One more thing that can break and take down user access.

Spiceworks Community

The recurring theme

While Orca Security offers solid SCIM functionality, the custom pricing model and SSO dependency create adoption barriers that force teams into complex sales cycles just to understand their provisioning costs.

The decision

Your SituationRecommendation
Need SCIM but don't qualify for custom pricingUse Stitchflow: avoid the enterprise sales process
Want SCIM without SSO complexityUse Stitchflow: bypass the SSO prerequisite
Already on Enterprise with custom pricingUse native SCIM: you're paying premium rates
Large security organization, need enterprise featuresEvaluate Enterprise: SCIM comes with the territory
Small security team, low user churnManual may suffice: but prepare for audit gaps

The bottom line

Orca Security gates SCIM behind Custom. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Make Orca Security workflows AI-native

Orca Security gates SCIM behind Custom. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Custom upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Custom

Prerequisites

SSO must be configured first

Key limitations

  • Custom pricing only
  • SSO configuration required before SCIM

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Orca Security → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Full SCIM provisioning support

Orca Security gates SCIM behind Custom. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Orca Security → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Full SCIM provisioning support

Orca Security gates SCIM behind Custom. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Orca Security

Orca Security gates SCIM behind Custom plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Orca Security logo
Orca Security
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Alteryx logo

Alteryx

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Alteryx supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (7+ users minimum). The feature requires SSO (SAML or OIDC) to be configured first and completely overrides manual user management. For teams on Professional ($5,000/user/year) or Business ($10,000-$20,000/user/year) plans, accessing SCIM means upgrading to Enterprise - often a significant cost increase for functionality that should be table stakes. This creates a provisioning gap for most Alteryx deployments. Without automated user lifecycle management, IT teams face manual onboarding/offboarding workflows, delayed access provisioning, and compliance risks around orphaned accounts. The high per-user costs make Alteryx particularly expensive to scale, and forcing an Enterprise upgrade just for basic provisioning automation compounds that challenge.

View full guide
Atlan logo

Atlan

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Atlan supports native SCIM 2.0 provisioning with full user and group management capabilities. However, SCIM is only available on Enterprise tier, which requires custom pricing negotiations. Additionally, SSO must be enabled before SCIM can be configured, and Atlan's pricing tiers (Starter, Premier, Enterprise) are not publicly disclosed, making cost planning difficult for IT teams. This creates a significant barrier for organizations wanting automated provisioning without committing to enterprise-level contracts. For data teams evaluating Atlan, the lack of transparent pricing means you can't budget for provisioning capabilities upfront. The SSO prerequisite also forces organizations into a specific implementation sequence that may not align with their rollout timeline.

View full guide
Benchling logo

Benchling

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Benchling supports SCIM provisioning, but only on Enterprise plans with custom pricing that typically starts at $1M+ annually. This creates a massive barrier: organizations on Professional plans ($20,000+/year) face a 50x+ price increase to unlock automated user provisioning. Even mid-sized life sciences teams end up paying enterprise-level licensing just to automate basic user lifecycle management. The pricing gap is so extreme that most organizations either stick with manual provisioning or delay Benchling adoption entirely. This creates a significant operational burden for IT teams managing researchers across multiple lab environments. Manual user provisioning in a platform that handles sensitive R&D data introduces compliance risks and delays researcher onboarding. When a scientist joins or leaves, IT must manually coordinate access across Benchling's complex permission structure for notebooks, entities, and workflows. For organizations with frequent collaborator access or seasonal research teams, this becomes unmanageable.

View full guide