Best Practices for using SCIM for Admin Management and SCIM for Content Access
Using SCIM for both Admin Management (“Admin SCIM”) and Content Access (“Content SCIM”) creates a synchronized ecosystem where identity, licensing, and collaboration are managed from a single source of truth.
The Core Advantage: "Dual-Layer Automation"
While Admin SCIM handles the individual (licensing and hierarchy), Content SCIM handles the workflow (collaboration and documents). Using them together provides:
1. Zero-Touch Onboarding & Offboarding:
A user added to the IdP can instantly receive a license based on their group’s setting (via Admin SCIM) and is auto-joined to their Lucid team hub (via Content SCIM). Upon termination, removing them from the IdP revokes the license and wipes document access simultaneously, closing security gaps.
2. Clean Governance
| Feature | Admin SCIM (The "Who") | Content SCIM (The "What") |
| Focus | Licensing | Document & Folder Permissions |
| Grouping | Organizational Groups (e.g., "Engineering") | Teams (e.g., "Product Launch 2026") |
| Potential Benefits |
|
|
Best Practices
- Should I manage users in Lucid or my IdP?
- To keep both applications aligned, use your IdP as the single source of truth and avoid manual user or group management directly within Lucid Software.
- Use Admin SCIM for organizational groups, and license management workflows.
- Use Content SCIM for team membership and document sharing workflows.
- Automate group membership through your IdP to prevent configuration drift and avoid manual user or group management within Lucid Software.
- To keep both applications aligned, use your IdP as the single source of truth and avoid manual user or group management directly within Lucid Software.
- Who should be granted a license?
- We strongly encourage all users that are part of a Team to be granted a license to maximize their ability to use the Team’s content.
- We strongly encourage all users that are part of a Team to be granted a license to maximize their ability to use the Team’s content.
- Do I need both applications?
- Not always. Your configuration depends on your organization's goals.
- Use SCIM for admin management if you want:
- Organizational group management which supports:
- Automated license assignment and removal
- Automatically assigning users into groups with different security settings
- Organizational group management which supports:
- Add SCIM for content access if you want:
- Lucid Teams management which supports:
- Team-based document sharing workflows
- Automatic removal of team document access from former employees
- Lucid Teams management which supports:
Keep in Mind
- If you want to delete or deactivate a user that is synced with both apps, you must delete and deactivate them from both apps.
- Avoid syncing the same user with conflicting or different attributes between the two apps.
- If a user is synced only by Content SCIM, they will be in the Default Organizational Group. If a user is synced only by Admin SCIM, then they will not be a member of any Lucid Teams.
- Entra ID limitation: Nested IdP groups for Entra ID are flattened upon import to Lucid teams, but Lucid org groups can be nested. Entra will create the corresponding org groups and teams in Lucid, but their memberships will be blank unless the child groups are explicitly assigned to the Lucid app in Entra.