Stitchflow
Workiva logo

Workiva SCIM guide

Native SCIM

How to automate Workiva user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Workiva supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing averaging $36K-$156K per year. The implementation requires specific technical setup: a dedicated SCIM API user with admin roles, and for Azure Entra users, manual configuration of a custom enterprise app since the gallery app doesn't support provisioning. This creates a significant barrier for organizations on lower-tier plans who need automated user management.

For mid-market companies, this pricing structure creates a tough choice: either manually manage Workiva user accounts (risking compliance gaps and security vulnerabilities) or commit to Enterprise-level spend that may far exceed their actual feature needs. Manual provisioning in financial compliance tools like Workiva is particularly problematic since user access directly impacts audit trails and SOX compliance requirements.

The strategic alternative

Workiva gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Workiva accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Workiva pricing problem

Workiva gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
ProN/A
BusinessN/A
EnterpriseCustom (~$36K-$156K/year avg)

Plan Structure

PlanPriceSCIM
ProN/A
BusinessN/A
EnterpriseCustom (~$36K-$156K/year avg)

What this means in practice

Workiva's custom Enterprise pricing makes it difficult to calculate exact upgrade costs, but based on reported averages:

Minimum commitment
~$36,000/year just to access SCIM provisioning
Scaling costs
Enterprise pricing can reach $156,000+/year for larger deployments
All-or-nothing
No middle tier option - you either pay enterprise rates or manage users manually

The pricing gap between Business and Enterprise tiers is substantial, often representing a 3-5x cost increase purely to unlock automated provisioning.

Additional constraints

Custom pricing opacity
No transparent pricing makes budget planning difficult and requires lengthy sales cycles.
Azure Entra complexity
While Okta has a certified integration, Azure Entra requires custom enterprise app setup since the gallery app doesn't support SCIM.
SAML dependency
Workiva recommends SAML SSO alongside SCIM, adding configuration complexity.
Admin role requirements
SCIM setup requires a dedicated API user with specific admin permissions, creating additional security management overhead.

Summary of challenges

  • Workiva supports SCIM but only at Enterprise tier (Custom (~$36K-$156K/year avg))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Workiva doesn't sell SCIM separately. It's bundled with Enterprise plan features starting at ~$36K annually:

SCIM 2.0 automated provisioning
SAML single sign-on (SSO)
Advanced user role management
Enterprise security controls
Audit logs and compliance reporting
Dedicated customer success manager
Priority support
Advanced workflow permissions
Custom branding options

The catch? Azure Entra users need custom enterprise app setup since Workiva's gallery app doesn't support provisioning. You're also locked into SCIM 2.0 only—no flexibility for legacy systems.

Stitchflow Insight

If you need enterprise-grade financial reporting controls anyway, the upgrade makes sense. If you just want automated user provisioning for a finance team, you're paying for executive dashboards, compliance features, and premium support you'll likely never use. We estimate ~60% of Enterprise features are irrelevant for teams that only need SCIM provisioning.

What IT admins are saying

Community sentiment on Workiva's SCIM implementation reveals significant deployment challenges. Common complaints:

  • Enterprise-only pricing that excludes mid-market teams from automated provisioning
  • Complex setup requirements with dedicated SCIM API users and specific admin roles
  • Azure Entra complications requiring custom enterprise app configuration instead of the gallery app
  • High barrier to entry with custom pricing averaging $36K-$156K annually

The Azure gallery app doesn't support SCIM provisioning - you have to create a custom enterprise application and configure everything manually. Not exactly the seamless experience we expected from a major finance platform.

IT Administrator, LinkedIn

Workiva's SCIM requires a dedicated API user with very specific admin permissions. One misconfiguration and your entire provisioning stops working. The documentation helps but it's still a complex setup.

Identity Management Forum

The recurring theme

Workiva's SCIM is technically solid but locked behind expensive Enterprise tiers and requires significant technical expertise to deploy correctly.

The decision

Your SituationRecommendation
On Pro/Business, need SCIMUse Stitchflow: avoid the Enterprise upgrade premium
Already on Enterprise with SCIMUse native SCIM: you're paying $36K-156K/year for it
Using Azure Entra IDUse Stitchflow: simpler than custom app setup
Need Enterprise features beyond SCIMEvaluate Enterprise: SCIM comes bundled with other capabilities
Small team, low user churnManual may work: but watch for compliance gaps

The bottom line

Workiva gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Make Workiva workflows AI-native

Workiva gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

None

Key limitations

  • SCIM 2.0 only - older SCIM versions not supported
  • Requires dedicated SCIM API user with specific admin roles
  • SAML SSO recommended alongside SCIM for full security
  • Azure Entra requires custom app setup - gallery app doesn't support provisioning

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Where to enable

Okta Admin Console → Applications → Workiva → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Official Okta integration supports SSO and SCIM provisioning

Workiva gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Where to enable

Entra admin center → Enterprise applications → Workiva → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Workiva gallery app doesn't support SCIM - requires custom enterprise app setup for SCIM provisioning

Workiva gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Workiva

Workiva gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Workiva logo
Workiva
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Alteryx logo

Alteryx

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Alteryx supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (7+ users minimum). The feature requires SSO (SAML or OIDC) to be configured first and completely overrides manual user management. For teams on Professional ($5,000/user/year) or Business ($10,000-$20,000/user/year) plans, accessing SCIM means upgrading to Enterprise - often a significant cost increase for functionality that should be table stakes. This creates a provisioning gap for most Alteryx deployments. Without automated user lifecycle management, IT teams face manual onboarding/offboarding workflows, delayed access provisioning, and compliance risks around orphaned accounts. The high per-user costs make Alteryx particularly expensive to scale, and forcing an Enterprise upgrade just for basic provisioning automation compounds that challenge.

View full guide
Atlan logo

Atlan

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Atlan supports native SCIM 2.0 provisioning with full user and group management capabilities. However, SCIM is only available on Enterprise tier, which requires custom pricing negotiations. Additionally, SSO must be enabled before SCIM can be configured, and Atlan's pricing tiers (Starter, Premier, Enterprise) are not publicly disclosed, making cost planning difficult for IT teams. This creates a significant barrier for organizations wanting automated provisioning without committing to enterprise-level contracts. For data teams evaluating Atlan, the lack of transparent pricing means you can't budget for provisioning capabilities upfront. The SSO prerequisite also forces organizations into a specific implementation sequence that may not align with their rollout timeline.

View full guide
Benchling logo

Benchling

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Benchling supports SCIM provisioning, but only on Enterprise plans with custom pricing that typically starts at $1M+ annually. This creates a massive barrier: organizations on Professional plans ($20,000+/year) face a 50x+ price increase to unlock automated user provisioning. Even mid-sized life sciences teams end up paying enterprise-level licensing just to automate basic user lifecycle management. The pricing gap is so extreme that most organizations either stick with manual provisioning or delay Benchling adoption entirely. This creates a significant operational burden for IT teams managing researchers across multiple lab environments. Manual user provisioning in a platform that handles sensitive R&D data introduces compliance risks and delays researcher onboarding. When a scientist joins or leaves, IT must manually coordinate access across Benchling's complex permission structure for notebooks, entities, and workflows. For organizations with frequent collaborator access or seasonal research teams, this becomes unmanageable.

View full guide