Skip to content
Help Center home
InboxAsk a human

How to set up directory sync (SCIM)

Directory sync automates how users are created, updated and removed in Plain. Set it up in Settings, then SSO, then Directory sync. Plain uses WorkOS to power directory sync, so this sends you to its dashboard to complete the integration.

Instead of inviting teammates by hand and disabling accounts when someone leaves, Plain syncs with your identity provider to keep access up to date. You can also map roles in your identity provider to roles in Plain to make onboarding easier.

Directory sync is available on the Frontier plan.

Role assignment

If a user is provisioned through SCIM and no role mapping applies, Plain:

  • Assigns them the None role.
  • Lists them in the Others tab, under Settings, then Members.
  • Does not charge for an additional seat.

    You can change their role at any time in Settings, then Members, or in the admin dashboard linked from Settings, then SSO.

    If a user maps to more than one Plain role, the most permissive role wins. For example, a user who maps to both Admin and Support gets the Admin role.

Multiple workspaces

If you have several Plain workspaces and want one directory for all of them, see How to set up SSO and SCIM across multiple workspaces.