Knowledge base SSO & provisioning
Gusto and other platforms without SCIM
Gusto — like many smaller HR tools — doesn't offer outbound SCIM provisioning, so it can't push hires and terminations to us directly. Rather than pretend otherwise, here's the path that actually works, and it's short.
Getting everyone in: export your people from Gusto as a CSV (any export with name and email columns works, and column order doesn't matter when headers are present), then upload it under Settings → Organization → Roster import. Everyone is added in one pass, seats permitting. New accounts come back with a one-time setup link apiece for you to distribute; the details and edge cases are in the roster import guide.
Keeping it current: for a steady trickle of hires, the invite link in your onboarding checklist is usually simpler than re-exporting — new people add themselves. Re-running a fresh CSV periodically also works, since existing members are skipped automatically and only the new rows do anything. Departures you remove by hand, and their certificates stay on record just as they do under SCIM.
If your identity layer is separate from your HR platform — say Gusto for payroll but Google Workspace for accounts — you can still get automatic account creation through single sign-on: first-time SSO sign-ins provision people into your organization on their own, seats permitting, which covers the "new hire" half of the problem without any roster file at all.