Introducing SCIM Provisioning in ClickHouse Cloud
Blog post from ClickHouse
ClickHouse Cloud has introduced SCIM 2.0 provisioning to automate organization membership and role management through identity providers such as Okta and Microsoft Entra ID, complementing existing SAML SSO authentication. After configuring SAML, administrators can enable SCIM, generate endpoint-scoped API credentials, and connect their identity provider so user assignments, removals, and group changes are synchronized automatically. IdP groups can map to ClickHouse custom roles, with stable external group IDs preserving mappings through group renames, while default SAML-assigned roles continue to apply to provisioned users. SCIM is limited to verified-domain SSO users and custom roles, cannot assign system roles such as Admin, does not manage manually invited members or passwords, and records provisioning actions in the organization audit log. The feature is generally available for Enterprise and BYOC organizations and supports any compliant SCIM 2.0 identity provider.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Platform Engineering | 12 | 358 | 65 | 25 | -70% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.