HIPAAFluent

Knowledge base SSO & provisioning

SCIM provisioning from Rippling

Rippling can manage your training roster the way it manages the rest of your stack: an employee added in Rippling gets an account and a seat here, and a termination deprovisions them, without anyone maintaining a second list.

First, in Settings → Organization here, generate a provisioning token under Automatic provisioning and copy the SCIM base URL and bearer token — the token is shown once.

  1. In Rippling, add a custom app with SCIM provisioning support.
  2. Provide our SCIM base URL and your bearer token, and map the employee's work email to userName — email is how we match people.
  3. Choose which employees Rippling should manage here — everyone, or a group such as a department or location.

Hires then flow through on Rippling's schedule: accounts arrive verified, enrolled in the course, and occupying a seat. Terminations deprovision the person — their seat frees up while their account and any Certificate of Completion stay on record, per our deprovisioning policy, which is the paper trail you want when a reviewer asks about a former employee. If a hire can't be provisioned because seats are full, Rippling surfaces the error and the row succeeds on retry once you've added seats.

Pairing Rippling provisioning with single sign-on gives staff one-click access from their Rippling dashboard, though provisioning works fine on its own — people who arrive by SCIM before any SSO exists can use a password set through the ordinary reset flow, or your admin can send them the invite link to establish their sign-in.