By

Cédric van Ravesteijn

Why You Need SCIM Provisioning for Enterprise Scheduling

A customer books a demo with your sales rep for Tuesday. The problem? The rep left the company three weeks ago. IT turned off their Okta account on their last day, so they can't sign in through Okta. But nobody deactivated their scheduling account, so their booking link is still on the website, in old email signatures, and in a dozen proposals your customers saved.

That's the gap SCIM provisioning closes. The average company now uses 101 apps, according to Okta's Businesses at Work 2025 report. Every one of them is a place where a leaver's access can survive, and a scheduling tool is one of the few your customers use directly.

This guide covers what SCIM is, why a scheduling tool needs it, and what to ask any scheduling tool before you buy.

Why You Need SCIM Provisioning for Enterprise Scheduling
Why You Need SCIM Provisioning for Enterprise Scheduling

SCIM provisioning in short: SCIM provisioning lets your identity provider, such as Okta, create, update and deactivate user accounts in other apps automatically. When someone joins, changes role or leaves, every connected app follows. It's different from single sign-on (SSO): SSO controls how people sign in, and SCIM controls whether their account exists.

Key takeaways

  • SCIM keeps app accounts in step with your identity provider across joiners, movers and leavers, so nobody has to add or remove people by hand.

  • SSO alone doesn't close the offboarding gap. It stops a leaver signing in, but it leaves their account, and anything that works without signing in, in place.

  • In a scheduling tool, a forgotten account stays visible to customers through booking links, team routing and invites.

  • Cal.com includes SCIM and SAML SSO on the Organizations plan and Enterprise, with Okta as the documented identity provider.

What is SCIM provisioning?

SCIM provisioning is the automatic creation, updating and deactivation of user accounts in an app, driven by your identity provider. SCIM stands for System for Cross-domain Identity Management. It's an open standard, first created in 2011 and now at version 2.0, according to Okta.

Two systems take part:

  • The identity provider (IdP) holds the list of people in your company and what they're allowed to use. Okta is one example. When something changes, the identity provider sends that change out.

  • The app, in this case your scheduling tool, receives the change and applies it. It creates the account, updates the name or team, or deactivates the account.

Provisioning means giving someone an account and access. Deprovisioning means taking it away.

Diagram showing Okta, the identity provider, sending create, update and deactivate changes to Cal.com and other connected apps through SCIM

An everyday comparison helps. Think of the HR system that issues and cancels building badges. When someone is hired, a badge appears. When they leave, it stops working, and nobody at the front desk has to remember to cancel it. SCIM does the same for app accounts.

In a scheduling tool, SCIM doesn't schedule meetings. It manages who can use the scheduling tool and which team they're on.

Microsoft's SCIM explainer covers the protocol in more depth. For a scheduling tool, the part that matters is what SCIM does at each stage of someone's time at your company.

What does SCIM do across the user lifecycle?

SCIM handles the three moments when an account needs to change: someone joins, someone moves, and someone leaves. Identity teams call this the joiner, mover and leaver lifecycle.

Here's what each stage looks like in a scheduling tool:

Stage

What happens in the identity provider

What SCIM does in the scheduling tool

Joiner

A new hire is assigned the app

Their account is created and they're added to their mapped team

Mover

Someone moves to a new role or team, which puts them in a new group

They're added to the team mapped to that group

Leaver

Someone leaves or loses access

Their account is deactivated

Diagram of the joiner, mover and leaver stages: what happens in Okta and what SCIM then does in Cal.com, ending with the account deactivated, not deleted

The leaver stage is called deprovisioning, and it's the one that matters most for security. It's also the easiest one to miss when it's done by hand. A joiner who doesn't get an account files a ticket the same morning. A leaver who keeps one doesn't complain, so the account can sit there until someone notices.

Many teams assume single sign-on already covers leavers. It doesn't, and the difference is worth understanding before you sign off on any tool.

What's the difference between SCIM and SSO?

SSO controls how people sign in. SCIM controls whether their account exists. You need both, because each one covers what the other can't.

Single sign-on (SSO) lets people sign in to many apps with one company login. The two common ways to do it are SAML (Security Assertion Markup Language) and OIDC (OpenID Connect). Both pass a signed message from the identity provider to the app that says who the person is. Neither one changes the account itself.


SSO (SAML or OIDC)

SCIM

What it answers

"Who are you?"

"Should this account exist, and on which team?"

When it runs

When someone signs in

In the background, whenever the directory changes

What it can't do

Deactivate an account when someone leaves

Sign anyone in

So SCIM doesn't replace SAML. They do different jobs.

Diagram comparing SSO, which runs when someone signs in, with SCIM, which runs in the background whenever the directory changes

Some apps also offer just-in-time (JIT) provisioning. A new employee signs in to an app with Okta for the first time, and the app creates their account on the spot. That's convenient for joiners, but it runs only at sign-in, so it can't deactivate anyone. A person who has left never signs in again, and nothing tells the app they're gone.

That's the point the rest of this guide builds on. SSO alone leaves the account in place. Turning off someone's Okta account stops them signing in through SSO, but anything in the app that works without signing in can keep working. Cal.com's Organizations plan includes both: SSO for sign-in and SCIM for accounts.

Why does a scheduling tool need SCIM?

A scheduling tool needs SCIM because it's public-facing. In most apps, a leaver's forgotten account sits unused. In a scheduling tool, your customers are the ones using it.

Comparison of offboarding without SCIM, where booking links, round robin and invites can stay active, and with SCIM, where the Cal.com account is deactivated in the same step

Three things can happen when a leaver's scheduling account is left active.

Every person on your team has a booking link, and those links spread. They sit on your website, in email signatures, in proposals and in your customers' bookmarks. If the account stays active, prospects and customers can still book time with someone who's gone, and nobody is there to take the call.

Round robin keeps routing

Sales, Customer Success and Recruiting teams often share one booking link that hands meetings out across the team. That's round robin scheduling. If a former employee is still a team member, the shared link can keep sending meetings their way, and a qualified lead lands in an empty calendar.

The stakes grow with the team. Storyblok uses Cal.com's fixed round robin to spread demos across engineers in more than 40 countries, and saw a 50% increase in demo efficiency. Routing like that is only as good as the list of people it routes to.

Invites carry the wrong name

Customers get meeting invites and reminders from a person who no longer works for you. It tells them nobody noticed the person left, which is the wrong message to send a customer you're trying to keep.

With SCIM, the scheduling account is deactivated in the same step that removes the person from your identity provider. Offboarding the scheduling tool no longer depends on someone remembering to do it.

One practical habit applies whichever tool you use: when someone leaves, reassign their upcoming meetings to a colleague before their last day.

Want to see how a leaver is handled in Cal.com before you commit? Bring your offboarding checklist to our team, and we'll walk you through what happens to the account step by step.

What should you ask a scheduling tool about SCIM?

Look for a scheduling tool that offers SSO and SCIM on the same plan, deactivates accounts automatically when someone leaves your identity provider, and maps identity-provider groups to teams.

Those three points decide the purchase, but your security review will ask for more. Two people usually need answers. The buyer owns the rollout and the budget. The approver owns the identity provider, which usually means the IT manager, the Director of IT or, at tech companies, the CTO.

Question

Who asks it

Why it matters

Which plan includes SCIM and SSO?

Buyer

SCIM is often only on the top plan, which changes the price per seat

What happens to seats when someone leaves?

Buyer

Decides whether leavers keep costing money

Which identity providers are supported?

Approver

It has to match the one your company runs

Is the account deactivated automatically when someone leaves?

Both

This is the offboarding gap from the section above

Can identity-provider groups map to teams?

Approver

New hires land on the right team without a ticket

Is there a domain check?

Approver

Stops accounts being created for outside email addresses

Which profile fields sync?

Approver

Tells IT what still has to be managed inside the app

Can we download the security reports?

Approver

The security review will ask for SOC 2 or ISO 27001

If you're comparing plans across tools, Cal.com plans shows where each feature sits, and our secure scheduling infrastructure covers the wider security review.

Already have security questions? Bring them to our team, and we'll answer every row of this table for your set-up before your review meeting.

How does SCIM work in Cal.com?

Your Okta admin connects Okta to Cal.com once. From then on, Okta decides who has a Cal.com account and which team they're on, and Cal.com follows whatever Okta says.

Here are our answers to the questions above, split by who's asking.

For the buyer

SCIM and SAML SSO are included on the Organizations plan, at $28 per user a month billed yearly, and on Enterprise.

Every team, from Sales to Recruiting, is managed through Okta, and admins control them from one dashboard. That's how Cal.com Enterprise runs scheduling across a whole company. Deel, for example, has more than 1,000 employees using Cal.com. At that size, adding and removing people by hand stops being a small admin task.

Here's how SCIM ties into meetings in practice. 

A new account executive joins the "Sales EMEA" group in Okta. SCIM creates their Cal.com account and adds them to the Sales EMEA team. The team has a managed "Customer demo" event set to assign all team members, so on day one the new rep gets their own copy of the team's demo, with the same length and booking questions as everyone else. When they leave, Okta removes them and SCIM deactivates the account.

Diagram of a new account executive joining the Sales EMEA group in Okta, SCIM creating their Cal.com account, and a managed Customer demo event giving them their own copy of the team's demo on day one

Managed event types are meeting templates an admin sets up once. With Assign all team members turned on, they apply to current and future members of the team, which is what makes the day-one part work. Role-based access control then decides what each person can change.

What your IT team should know

  • Okta is the documented identity provider.

  • Your company verifies its email domain first. Cal.com only creates accounts for addresses on that domain or its subdomains, so nobody can use SCIM to create an account for an outside address.

  • SCIM is set up together with SAML or OIDC single sign-on. Once their account exists, members sign in with their work email through SSO.

  • Five fields sync: username, first name, last name, email and display name.

  • Okta groups map to Cal.com teams. The group name has to match Okta exactly.

  • Leavers are deactivated, not deleted.

  • Audit logs are included with every organization plan. They record security events such as SSO sign-ins, and the developer guide to audit logs lists membership changes too.

  • Our security and compliance reports, including SOC 2 Type II and ISO 27001, are available to download.

The full technical walkthrough is in our SCIM set-up guide for developers.

Cal.com compliance settings listing the Data Processing Agreement, ISO 27001 certificate and report, penetration testing report, SOC 2 Type 2 report, and breach notification policy, available to organizations

What does setting up SCIM with Okta involve?

Your Okta admin connects it once, and after that nobody manages Cal.com accounts by hand. On the Cal.com side, the person setting it up needs to be an organization admin.

For the approver, the order looks like this:

  1. Set up SAML or OIDC single sign-on. For Okta, follow setting up OIDC with Okta.

  2. Verify your company's email domain in Cal.com.

  3. Turn on Directory Sync in Cal.com, then paste the SCIM URL and secret token into Okta.

  4. Map Okta groups to Cal.com teams.

  5. Test with one user.

  6. Assign everyone else.

The six steps to set up SCIM with Okta in Cal.com, from single sign-on and domain verification to assigning everyone

To follow each step with screenshots, see how to set up SCIM with Okta in our help center.

Close the offboarding gap where customers can see it

A scheduling tool is where a leaver's access stays visible to your customers. The fix is to stop managing those accounts in two places and let your identity provider decide. With SCIM, someone who leaves Okta leaves Cal.com in the same step, and new hires arrive on the right team with the right meeting links.

If your security review has asked "does it support SCIM?", bring the rest of its questions to us. Talk to our team about your Okta set-up, your teams and your seat count, or see what's included with Organizations.

FAQs

What does SCIM stand for?
SCIM stands for System for Cross-domain Identity Management. It's an open standard that lets an identity provider create, update and deactivate user accounts in other apps automatically.

Is SCIM the same as SSO?
No. SSO controls how people sign in, while SCIM controls whether their account exists and which team it belongs to.

Does SCIM replace SAML?
No. SAML is a way to do single sign-on, and SCIM manages accounts, so you need both.

Which Cal.com plan includes SCIM?
SCIM is included on Cal.com's Organizations plan, at $28 per user a month billed yearly, and on Enterprise. Both plans also include SAML SSO.

Which identity providers work with Cal.com SCIM?
Okta is the identity provider Cal.com documents for SCIM. Cal.com's docs don't cover other identity providers yet.

What happens when someone is removed from Okta?
SCIM deactivates their Cal.com account automatically. The account is deactivated, not deleted.

Do I need SSO to use SCIM in Cal.com?
Cal.com's documented set-up starts with a SAML or OIDC single sign-on app in Okta, as the SSO set-up guide describes. You turn on SCIM provisioning in that same app, so plan to set up both.

Get started with Cal.com for free today!

Experience seamless scheduling and productivity with no hidden fees. Sign up in seconds and start simplifying your scheduling today, no credit card required!

Recommended reads

Recommended reads

Want to keep going? These reads dig deeper into the topics we touched on above. They’ll help you connect the dots and learn more.

Want to keep going? These reads dig deeper into the topics we touched on above. They’ll help you connect the dots and learn more.