Stitchflow
Whatfix logo

Whatfix SCIM guide

Connector Only

How to automate Whatfix user provisioning, and what it actually costs

Native SCIM not available

Summary and recommendation

Whatfix, the digital adoption platform, offers no SCIM provisioning capabilities on any plan, including Enterprise. While Whatfix supports SAML-based SSO through both Okta and Microsoft Entra ID, this only handles authentication—not user lifecycle management. IT administrators must manually provision and deprovision users in Whatfix, creating significant operational overhead for organizations deploying digital adoption experiences across their workforce.

This gap becomes particularly problematic for enterprises using Whatfix to onboard employees or drive software adoption at scale. Without automated provisioning, IT teams face manual account creation, role assignment, and cleanup processes. When employees join, leave, or change roles, their Whatfix access must be managed separately from other business applications, creating compliance risks and administrative burden that scales poorly with organization size.

The strategic alternative

Whatfix has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaSSO only via SAML
Microsoft Entra IDSSO via SAML only
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Whatfix accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Whatfix pricing problem

Whatfix gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
ProNot disclosed
BusinessNot disclosed
EnterpriseCustom quote

Pricing and provisioning availability

PlanPriceSSOSCIM
ProNot disclosed
BusinessNot disclosed
EnterpriseCustom quote

Even Enterprise customers with custom contracts exceeding $50,000+ annually get no automated provisioning options.

What this means in practice

Manual account management at scale: Every user addition, role change, or deactivation requires manual intervention in the Whatfix admin console. For organizations deploying Whatfix across hundreds or thousands of employees, this creates significant administrative overhead.

No automated deprovisioning: When employees leave, their Whatfix accounts remain active until manually disabled. This creates both security risks and unnecessary license costs, particularly problematic given Whatfix's per-user pricing model.

Identity system disconnect: Your IdP becomes a record-keeping system rather than a source of truth. User attributes, department changes, and role modifications don't sync automatically, leading to access governance gaps.

Additional constraints

Enterprise-only SSO
SAML authentication requires Enterprise-tier contracts, blocking mid-market customers from basic identity integration
No API provisioning alternative
Whatfix doesn't offer API-based user management as a workaround for missing SCIM
Manual role mapping
User roles and permissions must be assigned individually in Whatfix, with no way to sync from IdP group memberships
License waste
Inactive users continue consuming licenses until manually identified and removed

Summary of challenges

  • Whatfix does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Whatfix actually offers for identity

SAML SSO Only

Whatfix provides basic SAML 2.0 authentication across all plans, but stops there:

FeatureAvailable
SAML SSO✓ Yes
User provisioning❌ No
User deprovisioning❌ No
Group management❌ No
Attribute sync❌ No
SCIM protocol❌ No

IdP Integration Status

Both major identity providers show the same story:

Okta Integration Network:

SSO
SAML 2.0 supported
Provisioning
Not available
Status
Authentication only

Microsoft Entra (Azure AD):

SSO
SAML 2.0 supported
Provisioning
Not available
Status
Authentication only

The Manual Reality

Without provisioning capabilities, IT teams must:

Create every Whatfix account manually before users can authenticate
Manually remove access when employees leave
Manually update user attributes and group memberships
Maintain separate user lists in Whatfix and your IdP

This creates the exact identity sprawl and security gaps that SCIM is designed to eliminate. Users get federated login, but IT gets stuck with manual account lifecycle management.

What IT admins are saying

Whatfix's lack of automated provisioning creates significant operational overhead for IT teams managing digital adoption platforms:

  • Manual user creation required despite SSO being available
  • No way to automatically sync user attributes or group memberships
  • Deprovisioning requires manual intervention across systems
  • Time-intensive onboarding process for new employees accessing training content

Even though we have SSO set up with Whatfix, we still have to manually create every user account before they can access our guided tours and training materials. It defeats the purpose of having identity management.

IT Director, Reddit discussion

The lack of SCIM support means we're constantly playing catch-up with user management in Whatfix. When someone changes departments or leaves, we have to remember to update their access manually.

System Administrator, community forum

The recurring theme

Whatfix treats user provisioning as a secondary concern, forcing IT teams to maintain dual processes for user lifecycle management even after implementing SSO authentication.

The decision

Your SituationRecommendation
Small team (<10 users) with low turnoverManual user management is workable
Growing digital adoption team (15+ users)Use Stitchflow: automation prevents bottlenecks
Enterprise with multiple Whatfix instancesUse Stitchflow: automation essential for scale
Compliance-focused organizationUse Stitchflow: automated audit trail required
High user churn (onboarding/offboarding)Use Stitchflow: manual processes create security risks

The bottom line

Whatfix offers powerful digital adoption tools but zero provisioning automation—even with enterprise pricing, you're stuck with manual user management. For organizations that need automated user lifecycle management and proper audit trails, Stitchflow delivers SCIM-level provisioning that Whatfix simply doesn't offer.

Make Whatfix workflows AI-native

Whatfix has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No SCIM support availableManual user provisioning requiredSSO available for authentication

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No SCIM support available
  • Manual user provisioning required
  • SSO available for authentication

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Where to enable

Okta Admin Console → Applications → Whatfix → Sign On

SSO only via SAML

Use Stitchflow for automated provisioning.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app

Where to enable

Entra admin center → Enterprise applications → Whatfix → Single sign-on

SSO via SAML only

Use Stitchflow for automated provisioning.

Unlock SCIM for
Whatfix

Whatfix has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
Whatfix logo
Whatfix
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide