Summary and recommendation
Tessian (now Proofpoint) does not offer SCIM provisioning, and with the acquisition by Proofpoint completed in December 2023, the integration landscape remains unclear. While Tessian supports SAML 2.0 SSO through major identity providers like Okta and Azure AD, provisioning documentation is not publicly available. The platform integrates with Okta for identity-based risk visibility in email security workflows, but this integration focuses on risk assessment rather than user lifecycle management. Enterprise customers must contact Proofpoint directly for any provisioning capabilities.
This creates a significant operational gap for IT teams managing email security across large organizations. Email security platforms like Tessian require accurate user provisioning to ensure comprehensive protection coverage—when users can't be automatically provisioned or deprovisioned, security gaps emerge as employees join, change roles, or leave the company. Manual user management in email security tools increases the risk of both under-protection (new users without coverage) and over-licensing (departed users still consuming licenses).
The strategic alternative
Tessian has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | ✓ | ❌ | Tessian + Okta integration for identity-based risk visibility. Uses Okta directory information and groups with Tessian Risk Hub. |
| Microsoft Entra ID | ✓ | ❌ | Azure AD supported for SSO. Contact Proofpoint for provisioning options. |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Tessian accounts manually. Here's what that costs:
The Tessian pricing problem
Tessian gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Enterprise | Contact Proofpoint for pricing |
Pricing structure
| Plan | Price | SCIM |
|---|---|---|
| Enterprise | Contact Proofpoint for pricing | ❌ Not available |
Market reality
What this means in practice
Without native SCIM, your IT team faces these manual processes:
For a 500-person company with 15% annual turnover, this creates ~90 manual provisioning tasks per year just for Tessian.
Additional constraints
Summary of challenges
- Tessian does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What Tessian actually offers for identity
SAML SSO (Enterprise tier)
Following Tessian's acquisition by Proofpoint in December 2023, identity features are now managed through Proofpoint Core Email Protection:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, Azure AD/Entra ID, generic SAML providers |
| Pricing | Contact Proofpoint for enterprise pricing |
| Documentation | In transition - contact vendor directly |
Key limitation: No public documentation exists for Tessian's identity capabilities. The acquisition means integration details must be obtained directly from Proofpoint sales.
Okta Partnership (Identity-based risk)
Tessian's Okta integration focuses on risk management rather than traditional provisioning:
| Feature | Purpose |
|---|---|
| Directory sync | Pulls user and group data for risk analysis |
| Risk Hub integration | Identifies high-risk users based on Okta signals |
| Identity context | Enhances email security with user behavior data |
Translation: This isn't SCIM provisioning. It's a data feed that helps Tessian understand user risk profiles based on your Okta directory.
What's actually missing
For IT teams evaluating email security with proper identity integration, Tessian's current state creates significant uncertainty around provisioning capabilities.
What IT admins are saying
Tessian's recent acquisition by Proofpoint has left IT admins in limbo regarding provisioning capabilities:
- Documentation is in transition after the Proofpoint acquisition - unclear what features remain
- No public SCIM documentation or clear provisioning path
- Enterprise-only access requires going through Proofpoint sales for basic integration info
- Limited IdP support compared to modern email security platforms
SSO/SCIM not publicly documented
Contact vendor for enterprise features
The recurring theme
The Proofpoint acquisition has created a documentation black hole. IT teams can't evaluate provisioning options without entering a sales process, and it's unclear which Tessian features will survive the integration into Proofpoint's platform.
The decision
| Your Situation | Recommendation |
|---|---|
| Small security team (<20 users) | Manual management acceptable given limited scope |
| Stable IT team with infrequent changes | Manual provisioning with SAML SSO for authentication |
| Growing organization (50+ users) | Use Stitchflow: automation essential as you scale |
| Enterprise with compliance requirements | Use Stitchflow: automation critical for audit trails |
| Multi-department email security deployment | Use Stitchflow: manual provisioning becomes unmanageable |
The bottom line
Tessian has no native SCIM. Stitchflow automates complete workflows across every app, including the ones without APIs.
Make Tessian workflows AI-native
Tessian has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- SSO/SCIM not publicly documented
- Acquired by Proofpoint - documentation in transition
- Contact vendor for enterprise features
Documentation not available.
Unlock SCIM for
Tessian
Tessian has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.
See how it works


