Knowledge base SSO & provisioning
SCIM provisioning from Rippling
Rippling can manage your training roster the way it manages the rest of your stack: an employee added in Rippling gets an account and a seat here, and a termination deprovisions them, without anyone maintaining a second list.
First, in Settings → Organization here, generate a provisioning token under Automatic provisioning and copy the SCIM base URL and bearer token — the token is shown once.
- In Rippling, add a custom app with SCIM provisioning support.
- Provide our SCIM base URL and your bearer token, and map the employee's work email to
userName— email is how we match people. - Choose which employees Rippling should manage here — everyone, or a group such as a department or location.
Hires then flow through on Rippling's schedule: accounts arrive verified, enrolled in the course, and occupying a seat. Terminations deprovision the person — their seat frees up while their account and any Certificate of Completion stay on record, per our deprovisioning policy, which is the paper trail you want when a reviewer asks about a former employee. If a hire can't be provisioned because seats are full, Rippling surfaces the error and the row succeeds on retry once you've added seats.
Pairing Rippling provisioning with single sign-on gives staff one-click access from their Rippling dashboard, though provisioning works fine on its own — people who arrive by SCIM before any SSO exists can use a password set through the ordinary reset flow, or your admin can send them the invite link to establish their sign-in.