For a long time, one of the top requests from our enterprise customers was SCIM provisioning. It’s a standard across many businesses, and a major need for Airbyte. We understand that this is table stakes for many of our customers, and we’re excited to finally deliver this critical update.
Today, SCIM provisioning and user groups are live on Airbyte Pro and Enterprise Flex plans.
What SCIM does in Airbyte SCIM (System for Cross-domain Identity Management) is an open standard that lets identity providers like Okta and Microsoft Entra ID manage user accounts automatically. For Airbyte, that means:
When someone joins your company and gets added to your identity provider, their Airbyte account is created automatically. When someone leaves and gets deactivated in your identity provider, their Airbyte account is deactivated too You can assign permissions to teams instead of individuals, as groups from your identity provider are synced into Airbyte This is especially important for a data infrastructure product like ours.
Airbyte connects to the most sensitive systems in your organization. It is unacceptable for an account that should have been deactivated three months ago to retain access.
SCIM removes that risk entirely.
User groups: permissions at scale The other part of this release is user groups.
A user group is a named set of organization members. You assign organization and workspace permissions to a group instead of managing them person by person.
The design splits ownership cleanly. Your identity provider owns group names and membership, while Airbyte owns permissions. Groups in Airbyte mirror the groups from Okta or Entra ID.
When someone gets added to "Data Engineering" in your identity provider, they automatically get whatever Airbyte permissions you've assigned to that group. When they move teams, their permissions update.
Your organization now has one place to add people, remove people, and reorganize teams.
Why this kept coming up If you sell to (or buy software for) enterprises, you know SCIM is table stakes. It’s required for:
SOC 2 audits Security questionnaires Internal compliance standards For data infrastructure, the bar is higher. Auditors want to know that the tool orchestrating data movement between your most sensitive systems is governed by the same identity controls as everything else. It’s definitely been a blocker for our team. We've had prospective Airbyte customers tell us they couldn't move forward until SCIM was in place.
I’m happy to say that we will never need to have that conversation again.
Getting started SCIM and user groups are available on Pro and Flex plans. If you use Okta or Microsoft Entra ID, configure SCIM from your organization settings.
If you're evaluating Airbyte for an enterprise deployment and SCIM was a question mark, it's answered. Talk to our team to get started with Pro or Flex.