People sync (SCIM)
Optional — identity already works without it. People who reach your agents through Slack, Teams, SharePoint or an embedded widget are recognized on their first message with nothing to set up (see How end-user identity works). People sync uses SCIM (a standard way for an identity provider to send its list of people to another system) so your provider — Okta, Microsoft Entra ID, Google Workspace and others — can create, update and deactivate end-user records in Cobalt automatically. It adds two things: people are known before they ever message, which helps reporting and reaching someone who hasn’t used an agent yet, and Cobalt hears when someone leaves (see When someone leaves for exactly what that ends). Where People sync has linked a person, it stays authoritative: a person it created who later messages from Slack or Teams is the same person, never a duplicate.People sync is for end users (the people your agents serve). It doesn’t
give anyone access to the console — administrators are governed by
admin sign-in, SSO and
roles. It also doesn’t read groups; that’s what a
directory is for. Like SSO, People sync is available
on plans that include it — talk to us if you don’t see it in Settings.
Set it up
1
Open Settings › Identity › Directories › People sync
At the bottom of the Directories list, select People sync ›.
Requires the Admin or Owner role.
2
Copy the SCIM base URL
Under Connection details, copy the SCIM base URL to give your provider
(it ends in
/api/v1/scim/v2).3
Generate a token
Under Bearer tokens, select Generate token and give it a name you’ll
recognize, such as “Okta — production”. The token (a password your
provider uses to talk to Cobalt) is shown once — copy it straight into
your provider’s SCIM settings. Cobalt stores only a scrambled copy and
can’t show it again. If you lose it, revoke it and generate a new one.
4
Configure your provider's SCIM app
Point your provider at the base URL with the token, and assign the users
(or groups of users) you want sent to Cobalt. Use email as the main
attribute.
Cobalt supports the SCIM operations for creating, updating and
deactivating users. It doesn’t yet support listing or searching users
(
GET /Users), which some providers’ setup wizards use to “match existing
users” first — if yours offers that step, skip it and let assignment create
the records. Groups aren’t sent over SCIM; assign users directly or through
a group in your provider, and the provider sends one operation per user.What People sync does
- Create / update — each person your provider sends becomes one canonical person in your tenant, keyed by their email. Their Slack, Teams and web identities for that email link to them automatically.
- Deactivate — when your provider deactivates or deletes someone, Cobalt deprovisions them: the same cascade as Deprovision on their page. Their history is kept.
- No reactivation over SCIM — if your provider later reactivates someone Cobalt has deprovisioned, Cobalt refuses the change and your provider shows an error. Add them back from the Cobalt console instead.
- An established identity — a person People sync created counts as identified, the same as someone recognized through Slack, Teams, SharePoint or an embedded token (see End-user identity).
When someone leaves
When your provider deactivates someone, here is what ends, and when:- Slack and Teams: their next message is refused.
- Privileged tools (tools that act with an integration’s admin credentials): refused on their next attempt, everywhere.
- Their connected accounts: the integration authorizations they granted are revoked.
- Web chat: their next message is refused, including in a chat they already have open. Signing in again doesn’t get them back in, and doesn’t create a new person for them.
- The admin console: not affected. People sync never removes an administrator — do that on Settings › Team.
What Cobalt stores
Cobalt keeps a person’s name, email address, phone number and whether they are active. Other directory attributes your provider sends — including the enterprise extension’sdepartment, title and manager — are accepted and
not stored. Group membership is read from your
directory at the moment it’s needed rather than copied
into Cobalt, so it’s never stale here.
The People sync page names any attributes your provider is currently sending
that Cobalt doesn’t store, so a sync that looks clean in your provider isn’t
hiding anything from you.
Manage tokens
- Revoke token on the People sync page at any time; requests using it stop working immediately. Your other tokens keep working.
- The page also shows Accept incoming users and Event queue health. If incoming users are turned off, Cobalt tells your provider so and keeps its changes in a queue, then applies them when it’s turned back on.
Related
- How people are recognized in each channel: How end-user identity works.
- Where groups come from: Directories.
- Administrator sign-in: Enterprise SSO.
