Stitchflow
Panther logo

Panther SCIM guide

Native SCIM

How to automate Panther user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Panther supports SCIM 2.0 on Enterprise plans, but with critical limitations that undermine automated provisioning workflows. SCIM cannot create new users—only JIT (Just-In-Time) provisioning via SSO can create accounts. Users must complete their first login through SSO before SCIM can manage their profiles, role assignments, or deactivation. The /Groups endpoint isn't supported, and changes made directly in Panther Console get overwritten by IdP sync.

This creates a problematic gap for IT teams. You can't fully automate user lifecycle management because every new user still requires manual coordination—they must know to log in via SSO first, and you can't pre-provision accounts for new hires or assign them to security groups before they arrive. For a security platform where timely access control is critical, this JIT-only approach introduces unnecessary delays and manual touchpoints that defeat the purpose of SCIM automation.

The strategic alternative

Panther gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDSSO only
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Panther accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Panther pricing problem

Panther gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
Community (Free)$0 (limited)
EnterpriseCustom (usage-based)

Note: Panther doesn't publish standard Pro/Business tiers with transparent pricing. All production deployments require Enterprise engagement with custom usage-based pricing negotiations.

What this means in practice

Without published pricing, organizations face several challenges:

Sales-gated access
No transparent path to SCIM without entering Enterprise sales cycle
Usage complexity
Pricing based on data ingestion volume, making cost prediction difficult
No mid-tier option
Jump from free/limited directly to full Enterprise commitment
Budget uncertainty
Custom pricing makes annual planning and approval processes more complex

Additional constraints

SSO dependency
SCIM requires SSO to be configured first, as user creation only happens through Just-In-Time (JIT) provisioning during first login.
Limited user creation
SCIM cannot create new users directly - users must complete their first login via SSO before SCIM can manage their profiles and role assignments.
Okta-centric
While Panther supports SAML SSO with other IdPs, SCIM documentation and testing focus primarily on Okta integration.
No group support
The /Groups SCIM endpoint is not supported, limiting organizational structure management.
Cognito limitations
Built on Amazon Cognito, which constrains some standard SCIM capabilities and user lifecycle management options.

Summary of challenges

  • Panther supports SCIM but only at Enterprise tier (Custom (usage-based))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Panther doesn't sell SCIM standalone. It's locked behind Enterprise pricing with usage-based billing:

SCIM automated provisioning (with major limitations)
SAML single sign-on (SSO)
Enterprise security controls
Advanced detection rules
Custom data models
Dedicated customer success
Premium support SLAs
Data retention controls

The SCIM implementation itself is severely limited - it can't create users (only JIT via SSO), can't manage groups, and only works after users manually log in first. This means you're paying Enterprise rates for a partial provisioning solution that still requires manual intervention.

Stitchflow Insight

If you need enterprise security features anyway, the upgrade has value. But if you just want reliable user provisioning, you're paying for enterprise complexity while getting basic automation that doesn't actually automate user creation. We estimate ~80% of Enterprise features are irrelevant for teams that simply need complete SCIM provisioning.

What IT admins are saying

Community sentiment on Panther's SCIM implementation reveals significant frustration with architectural limitations. Common complaints:

  • SCIM cannot create new users - forcing reliance on JIT provisioning through SSO
  • Users must complete their first login via SSO before SCIM can manage their profiles
  • No support for group provisioning via SCIM endpoints
  • Changes made directly in Panther Console get overwritten by identity provider sync
  • Enterprise tier requirement creates high barrier to entry for basic provisioning

The fact that SCIM can't actually create users defeats the purpose of automated provisioning. We still have to manage the initial onboarding manually through SSO.

Reddit r/sysadmin

Having to tell new hires to log in first before their account can be properly managed is backwards. That's not how modern provisioning should work.

IT Admin, Security Forum

The recurring theme

Panther's Amazon Cognito-based architecture creates a broken provisioning experience where SCIM feels like an afterthought rather than a core identity management capability.

The decision

Your SituationRecommendation
On Pro/Business plan, need SCIMUse Stitchflow: avoid the expensive Enterprise upgrade
Have Enterprise but hit SCIM limitationsUse Stitchflow: bypass the no-user-creation restriction
Using Entra ID as your IdPUse Stitchflow: Panther's SCIM only supports Okta
Already on Enterprise with OktaEvaluate native SCIM: but prepare for JIT-only user creation
Small security team, minimal user changesManual may work: but security tools need reliable access control

The bottom line

Panther's SCIM requires Enterprise pricing and still can't create users directly—only through JIT SSO login first. For teams that need true automated provisioning without Enterprise costs or Okta lock-in, Stitchflow delivers complete user lifecycle management at a fraction of the price.

Make Panther workflows AI-native

Panther gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SCIM cannot create new users - only JIT provisioning via SSO creates users
  • Users must complete first login via SSO before SCIM can manage their profiles
  • /Groups SCIM endpoint is not supported
  • Users can only be deactivated, not deleted via SCIM
  • Changes made directly in Panther Console will be overwritten by Okta sync
  • Built on Amazon Cognito which limits some SCIM capabilities

Documentation not available.

Unlock SCIM for
Panther

Panther gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Panther logo
Panther
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Alteryx logo

Alteryx

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Alteryx supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (7+ users minimum). The feature requires SSO (SAML or OIDC) to be configured first and completely overrides manual user management. For teams on Professional ($5,000/user/year) or Business ($10,000-$20,000/user/year) plans, accessing SCIM means upgrading to Enterprise - often a significant cost increase for functionality that should be table stakes. This creates a provisioning gap for most Alteryx deployments. Without automated user lifecycle management, IT teams face manual onboarding/offboarding workflows, delayed access provisioning, and compliance risks around orphaned accounts. The high per-user costs make Alteryx particularly expensive to scale, and forcing an Enterprise upgrade just for basic provisioning automation compounds that challenge.

View full guide
Atlan logo

Atlan

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Atlan supports native SCIM 2.0 provisioning with full user and group management capabilities. However, SCIM is only available on Enterprise tier, which requires custom pricing negotiations. Additionally, SSO must be enabled before SCIM can be configured, and Atlan's pricing tiers (Starter, Premier, Enterprise) are not publicly disclosed, making cost planning difficult for IT teams. This creates a significant barrier for organizations wanting automated provisioning without committing to enterprise-level contracts. For data teams evaluating Atlan, the lack of transparent pricing means you can't budget for provisioning capabilities upfront. The SSO prerequisite also forces organizations into a specific implementation sequence that may not align with their rollout timeline.

View full guide
Benchling logo

Benchling

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Benchling supports SCIM provisioning, but only on Enterprise plans with custom pricing that typically starts at $1M+ annually. This creates a massive barrier: organizations on Professional plans ($20,000+/year) face a 50x+ price increase to unlock automated user provisioning. Even mid-sized life sciences teams end up paying enterprise-level licensing just to automate basic user lifecycle management. The pricing gap is so extreme that most organizations either stick with manual provisioning or delay Benchling adoption entirely. This creates a significant operational burden for IT teams managing researchers across multiple lab environments. Manual user provisioning in a platform that handles sensitive R&D data introduces compliance risks and delays researcher onboarding. When a scientist joins or leaves, IT must manually coordinate access across Benchling's complex permission structure for notebooks, entities, and workflows. For organizations with frequent collaborator access or seasonal research teams, this becomes unmanageable.

View full guide