Stitchflow
TriNet logo

TriNet SCIM guide

Connector Only

How to automate TriNet user provisioning, and what it actually costs

Summary and recommendation

TriNet, the PEO (Professional Employer Organization) platform, offers SCIM provisioning but with a critical architectural limitation: it's designed as an HR source system that provisions users to other applications, not to be provisioned from your identity provider. While TriNet supports SCIM via OneLogin/Aquera connectors and offers SAML SSO integration, this setup creates an identity management conflict. Your IdP (Okta, Entra ID) expects to be the authoritative source for user identities, but TriNet functions as its own HR system of record.

This architectural mismatch creates operational complexity for IT teams. You're forced to either maintain dual identity sources or implement custom synchronization logic between your IdP and TriNet's HR data. The OneLogin/Aquera connector dependency also limits your IdP flexibility—you can't simply use standard SCIM endpoints with any identity provider. For organizations trying to centralize identity management, TriNet's role as an HR source system rather than a downstream application disrupts clean provisioning workflows.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation for TriNet that resolves these architectural conflicts. We handle the complex synchronization logic between your authoritative IdP and TriNet's HR system, maintaining consistency across both platforms. Works with any IdP (Okta, Entra, Google Workspace, OneLogin) regardless of TriNet's connector limitations. Flat pricing under $5K/year, regardless of employee count.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOProvisioningNotes
OktaVia APIOkta OIN integration with provisioning. Group import and schema discovery. Also available: TriNet by Aquera HR-as-a-Master connector.
Microsoft Entra IDVia APITriNet to Entra ID sync available via Aquera connector. Automatic joiner/mover/leaver sync. Third-party solution.
Google WorkspaceSSO only, no provisioning
OneLoginSSO only

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages TriNet accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The TriNet pricing problem

TriNet gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
StandardFrom ~$80/employee/mo (PEPM)

Pricing structure

PlanPricingSCIMSSO
StandardFrom ~$80/employee/mo (PEPM)❌ Via connectors only✓ SAML 2.0

Market context

Industry average PEO cost
~$1,395/employee/year (NAPEO)
TriNet's flat PEPM pricing (not percentage of payroll)
5 employee minimum required
Custom pricing based on company size, industry, location

What this means in practice

For most organizations using TriNet

TriNet serves as your HR system of record, not a target for provisioning
You'll likely need TriNet to provision users TO other SaaS apps in your stack
SCIM INTO TriNet is primarily needed for new hire onboarding workflows

If you do need SCIM provisioning into TriNet

Okta
Works via native OIN integration with API provisioning
OneLogin
Direct connector available
Entra ID
Requires Aquera third-party connector
Google Workspace
No documented SCIM support

Additional constraints

Third-party dependencies
Entra ID users must rely on Aquera connector for SCIM sync
HR source system complexity
TriNet is typically the authoritative source for employee data, creating circular provisioning challenges
Industry restrictions
Not available for hazardous industries, limiting applicability
Minimum commitment
5 employee minimum may not work for smaller organizations
Connector limitations
SCIM availability depends on your IdP having the right third-party integrations

Summary of challenges

  • TriNet does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What TriNet actually offers for identity

SAML SSO (Standard Plan)

TriNet supports SAML 2.0 integration with major identity providers:

SettingDetails
ProtocolSAML 2.0
Supported IdPsOkta, OneLogin, custom SAML providers
JIT Provisioning✓ Yes
SP-initiated✓ Yes
IdP-initiated✓ Yes

SCIM Provisioning (Via Third-Party Connectors)

TriNet doesn't offer native SCIM but supports provisioning through connector platforms:

FeatureOneLogin ConnectorAquera/Okta Connector
Create users✓ Yes✓ Yes
Update attributes✓ Yes✓ Yes
Deactivate users✓ Yes✓ Yes
Group sync✓ Yes✓ Yes
Schema discoveryLimited✓ Yes

The real limitation: These connectors only work with specific IdPs. You're locked into OneLogin or using Aquera's platform for Okta/Entra ID integration. No direct SCIM API means no support for Google Workspace, direct Entra ID, or other identity providers.

HR-as-a-Source Workflow

Important context: TriNet is typically the identity source system, not the target. Most organizations use TriNet to provision users into other applications (Slack, Google Workspace, etc.) rather than provisioning users into TriNet itself.

The connector solutions are designed for:

Syncing TriNet employee data to downstream applications
Automatic joiner/mover/leaver workflows from HR changes
Maintaining TriNet as the authoritative employee record

What IT admins are saying

Community sentiment on TriNet's provisioning reveals typical PEO platform challenges:

  • SCIM provisioning only works through specific connectors (OneLogin/Aquera), limiting IdP flexibility
  • As an HR source system, TriNet often needs to provision other apps rather than being provisioned itself
  • High per-employee pricing (~$80/month minimum) makes any additional integration costs feel expensive
  • 5-employee minimum creates barriers for smaller organizations

Price is biggest complaint from users

User review analysis

Higher end pricing compared to market

Community feedback on TriNet costs

The recurring theme

TriNet functions more as an identity source than a target application, but when you do need inbound provisioning, you're locked into specific connector solutions that may not match your existing IdP setup.

The decision

Your SituationRecommendation
Using OneLogin as your IdPNative connector may work for basic provisioning
Using Okta, Entra, or Google WorkspaceUse Stitchflow: native options are limited or complex
TriNet as HR source system provisioning other appsUse Stitchflow: streamline outbound provisioning workflows
Enterprise with 100+ employees on TriNetUse Stitchflow: automation essential at scale
Compliance-heavy industry requiring audit trailsUse Stitchflow: comprehensive logging and SOC 2 compliance

The bottom line

TriNet offers SCIM provisioning primarily through OneLogin/Aquera connectors, leaving other IdP users with limited automation options. As an HR platform that often serves as the identity source for other applications, TriNet customers need robust provisioning capabilities. Stitchflow provides universal IdP support and managed automation for under $5K/year—essential for organizations relying on TriNet as their HR foundation.

Automate TriNet without third-party complexity

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for TriNet at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

Not specified

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • SCIM via OneLogin/Aquera connectors (not all IdPs)
  • HR source system - typically provisions other apps
  • 5 employee minimum
  • Not available for hazardous industries

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → TriNet → Sign On

Okta OIN integration with provisioning. Group import and schema discovery. Also available: TriNet by Aquera HR-as-a-Master connector.

Use Stitchflow for automated provisioning.

Unlock SCIM for
TriNet

TriNet doesn't offer SCIM. Get an enterprise-grade SCIM endpoint in your IdP, even without native support.

See how it works
Admin Console
Directory
Applications
TriNet logo
TriNet
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

6sense logo

6sense

No SCIM

B2B Revenue Intelligence / ABM

ProvisioningNot Supported
Manual Cost$11,754/yr

6sense, the B2B revenue intelligence platform, has paused SCIM provisioning for new customers until Q4 2026. While existing customers with SCIM enabled can continue using it, new implementations are limited to JIT (Just-In-Time) provisioning through SAML SSO. This creates a significant gap for IT teams managing revenue intelligence access, as JIT only creates users on first login and provides minimal attribute mapping (email, first name, last name only). For an enterprise platform with typical pricing of $55,000-$130,000 annually, the absence of automated user lifecycle management is a substantial limitation. The lack of SCIM until Q4 2026 forces IT teams into manual provisioning workflows for a platform handling sensitive revenue data. While SAML SSO handles authentication, it doesn't address user lifecycle events like role changes, department transfers, or offboarding. This creates compliance risks in revenue teams where access to prospect data and sales intelligence must be tightly controlled. The nearly two-year wait for SCIM restoration means organizations implementing 6sense today face manual user management for the foreseeable future.

View full guide
Aha! logo

Aha!

No SCIM

Product Management / Roadmapping

ProvisioningNot Supported
Manual Cost$11,754/yr

Aha! Roadmaps, the product roadmapping platform, does not support SCIM provisioning on any plan. While Aha! offers SAML 2.0 SSO integration with identity providers like Okta, Entra ID, and OneLogin, this only handles authentication through JIT (Just-In-Time) provisioning. The critical limitation: JIT provisioning creates user accounts with no default role or access permissions, requiring administrators to manually configure access for each user after they first sign in. For product teams managing strategic roadmaps and stakeholder access, this creates significant operational overhead. Since product roadmaps contain sensitive strategic information and stakeholder access typically varies by product area, IT administrators must manually assign appropriate roles and workspace permissions after each user is provisioned. There's no automatic deprovisioning when users leave the organization, creating potential security gaps. This manual process becomes particularly problematic for larger product organizations where dozens of stakeholders across different business units need carefully managed access to specific roadmaps.

View full guide
Appcues logo

Appcues

No SCIM

Product Adoption / User Onboarding

ProvisioningNot Supported
Manual Cost$11,754/yr

Appcues, the product adoption platform used by product managers and growth teams, explicitly does not support SCIM provisioning on any plan—not even Enterprise. While Appcues offers SAML 2.0 SSO integration starting at the Enterprise tier with just-in-time (JIT) provisioning, this only creates users during first login and provides no automated deprovisioning capabilities. For product teams where access needs change frequently as people move between projects or leave the company, this creates a significant security gap. The lack of SCIM means IT teams must manually manage user lifecycle for Appcues accounts, even though the platform handles sensitive product analytics and user flow data. When employees leave or change roles, their Appcues access remains active until manually revoked—a compliance risk that's particularly problematic given Appcues' role in tracking user behavior and product metrics. With MAU-based pricing starting at $300/month and scaling significantly with usage, paying for orphaned accounts also creates unnecessary cost bloat.

View full guide