SCIM auto-provisioning | BondiByte NDIS Software
Security & Identity

Users and roles, provisioned automatically.

SCIM is the open standard identity systems use to manage user accounts in connected apps. Connect it to Microsoft Entra ID and BondiByte stays in step with your directory: people are provisioned when they join, updated when their details change, and deactivated the moment they leave.

SCIM auto-provisioning

What you get with SCIM auto-provisioning.

  • SCIM provisioning

    Provision and remove users automatically from your identity provider, so access stays current.

  • Group to role and site mapping

    Map directory groups to BondiByte roles and sites, so people land in the right place.

  • Entra directory sync

    Keep users in sync with Microsoft Entra, so your directory stays the single source of truth.

Why it exists

The problem it solves.

When people join, move teams and leave, someone has to mirror every change in every system by hand, and the miss that hurts is the departure: an ex-employee whose login quietly keeps working. SCIM connects BondiByte to Microsoft Entra ID so your directory does that work automatically. People are set up when they join, kept current while they stay, and switched off the moment they leave.

How it works

1

Connect your directory

BondiByte issues a dedicated connection token for Microsoft Entra ID. Tokens are yours to manage: rotate them on your schedule or revoke one instantly.

2

People arrive automatically

When your IT team assigns someone in the directory, BondiByte creates their account and a linked staff profile from their directory details, ready for rostering.

3

Groups place people correctly

Map directory groups to the Manager role and to your sites, so a new coordinator lands with the right access at the right locations without manual setup.

4

Changes keep flowing

Updates to names, job titles and reporting lines sync through, and a regular directory check with Microsoft Entra keeps everything aligned.

5

Leavers are switched off automatically

Remove someone in your directory and their BondiByte access is deactivated. Their records stay in your workspace for history and compliance.

What you can do.

Automatic provisioning from Microsoft Entra ID

Accounts and linked staff profiles are created from your directory, so onboarding a system login stops being a manual chore.

Group-to-role mapping

Directory groups can grant the Manager role automatically; everyone else provisions as Staff until a person decides otherwise.

Group-to-site mapping

Directory groups place staff at the right sites, so rostering sees them where they actually work.

Detail sync

Job titles and manager relationships flow through from the directory and stay current.

A full provisioning log

Every action SCIM takes is recorded and viewable, so you can always see what your directory did and when.

Connection tokens you control

Generate, rotate and revoke the tokens that let your directory talk to BondiByte, with usage tracked.

Diagram showing Microsoft Entra ID provisioning users, roles and sites into BondiByte through SCIM alongside single sign-on
Your directory drives BondiByte access; BondiByte enforces its own roles.

How it connects.

  1. Your Microsoft Entra ID directory
  2. SCIM provisions accounts and staff profiles
  3. Sign-in via Microsoft Entra SSO
  4. BondiByte roles and permissions still apply
  5. Staff profiles ready for rostering
  6. Governed by your security settings

You stay in control.

Sensitive roles never come from the directory

SCIM can never grant Owner, Admin or billing-level roles. Those are only ever assigned by a person inside BondiByte, by deliberate design.

Your staff allowance is respected

New activations are checked against your plan's staff allowance, so a directory change cannot silently grow your bill.

Mappings stay editable

Group-to-role and group-to-site mappings can be changed or removed by your admins at any time.

Instant shut-off

Revoking a connection token immediately stops your directory from making further changes, without touching existing users.

Learn how to use this feature.

Frequently asked questions.

What is SCIM, in plain terms?

SCIM is the open standard identity systems use to create, update and deactivate user accounts in the apps a business runs. It is how your directory manages BondiByte access for you.

Which identity providers are supported?

Microsoft Entra ID. Both SCIM provisioning and Microsoft single sign-on are built around it.

Can SCIM make someone an Owner or Admin?

No, deliberately. Group mapping can grant the Manager role at most; Owner, Admin and billing roles can only be granted by a person inside BondiByte.

What happens when someone leaves?

When their assignment is removed in your directory, their BondiByte access is deactivated automatically. Their records remain in your workspace for history and compliance.

Is setup self-service?

It is configured for your organisation with your Microsoft administrator involved and BondiByte coordinating, so identity details are handed over safely rather than through email or chat. The SSO and SCIM guide walks through the process.

See SCIM auto-provisioning in BondiByte

Start your free trial, or book a demo to see it with your own operation in mind.

Start free trial