Coming soon · design previewThis page mocks up an unreleased capability with realistic data. It is not yet wired to live providers. Back to demo home
Coming soon · SSO + SCIM directory sync
Your real org chart, flowing in automatically.
One connector via WorkOS covers Okta, Microsoft Entra ID, Google Workspace, Rippling, OneLogin, and Ping. Joiners, movers, and leavers reflect in the dashboard within minutes. Group memberships drive GreyScape.ai teams; SAML/OIDC SSO handles admin login.
Okta — connected
Domain acme.okta.com · provisioning + login both active
Last sync: 2 min ago
SAML login: healthy
Users synced
234
Groups mapped
7 / 8
One group ignored — see mapping
Recent directory events
Auto-refresh every 60s- 10:42Priya ShahAdded to Engineering · Senior Engineer · email [email protected]
- 10:38Maya ReyesMoved from Customer Success → Sales Engineering
- 10:31Tom ReillyDeactivated in Okta · API keys auto-revoked · open requests reassigned to manager
- Today 09:14Connor McElroyAdded to Sales · BDR · group Sales-AMER
- YesterdayAda LeePromoted from IT → Head of Platform
- YesterdayJin ParkAdded to Marketing · Content Lead
Group → Team mapping
How identity-provider groups become GreyScape.ai teams. Edit the mapping to reorganise attribution without touching the directory itself.
| IdP group | → GreyScape.ai team | Members |
|---|---|---|
| Engineering | Engineering | 38 |
| Customer Success | Customer Success | 22 |
| Sales-AMER | Sales | 18 |
| Sales-EMEA | Sales | 11 |
| Marketing | Marketing | 9 |
| Finance | Finance | 6 |
| IT-Platform | IT / Platform | 7 |
| All-Employees | (ignored — too broad) | 234 |
Without SCIM (today)
- · Users list is a manual snapshot — engineers who left in Q1 still appear.
- · Spend gets attributed to people who don't work here anymore.
- · New hires have no AI access for days while IT manually adds them.
- · Service-account keys live forever — no automatic revocation when someone leaves.
With SCIM (coming soon)
- · Joiner appears in GreyScape.ai within minutes of being added in Okta.
- · Mover's team changes propagate — attribution always current.
- · Leaver's open service-account keys are auto-revoked at the source.
- · Chargeback by cost centre stays accurate, audit-defensible.
How you'd use this
- One-time WorkOS setup (~10 minutes). Pick your IdP, complete the SCIM and SAML wizards.
- GreyScape.ai auto-populates users + groups. Map IdP groups → GreyScape.ai teams from this page.
- Forget about it. The dashboard, Users, and Teams views stay accurate as your org changes.
Sample output
234 users synced from Okta. Last sync 2 minutes ago. This week: 3 joiners, 1 leaver, 2 team changes — all reflected in the dashboard without any admin touching it.
What this unlocks
Attribution that doesn't go stale. Auto-revocation of keys for leavers. Chargeback you can defend to a finance auditor. One connector covers every major identity provider — no per-IdP integration to maintain.