Skip to main content

People sync (SCIM)

Optional — identity already works without it. People who reach your agents through Slack, Teams, SharePoint or an embedded widget are recognized on their first message with nothing to set up (see How end-user identity works). People sync uses SCIM (a standard way for an identity provider to send its list of people to another system) so your provider — Okta, Microsoft Entra ID, Google Workspace and others — can create, update and deactivate end-user records in Cobalt automatically. It adds two things: people are known before they ever message, which helps reporting and reaching someone who hasn’t used an agent yet, and Cobalt hears when someone leaves (see When someone leaves for exactly what that ends). Where People sync has linked a person, it stays authoritative: a person it created who later messages from Slack or Teams is the same person, never a duplicate.
People sync is for end users (the people your agents serve). It doesn’t give anyone access to the console — administrators are governed by admin sign-in, SSO and roles. It also doesn’t read groups; that’s what a directory is for. Like SSO, People sync is available on plans that include it — talk to us if you don’t see it in Settings.

Set it up

1

Open Settings › Identity › Directories › People sync

At the bottom of the Directories list, select People sync ›. Requires the Admin or Owner role.
2

Copy the SCIM base URL

Under Connection details, copy the SCIM base URL to give your provider (it ends in /api/v1/scim/v2).
3

Generate a token

Under Bearer tokens, select Generate token and give it a name you’ll recognize, such as “Okta — production”. The token (a password your provider uses to talk to Cobalt) is shown once — copy it straight into your provider’s SCIM settings. Cobalt stores only a scrambled copy and can’t show it again. If you lose it, revoke it and generate a new one.
4

Configure your provider's SCIM app

Point your provider at the base URL with the token, and assign the users (or groups of users) you want sent to Cobalt. Use email as the main attribute.
Cobalt supports the SCIM operations for creating, updating and deactivating users. It doesn’t yet support listing or searching users (GET /Users), which some providers’ setup wizards use to “match existing users” first — if yours offers that step, skip it and let assignment create the records. Groups aren’t sent over SCIM; assign users directly or through a group in your provider, and the provider sends one operation per user.

What People sync does

  • Create / update — each person your provider sends becomes one canonical person in your tenant, keyed by their email. Their Slack, Teams and web identities for that email link to them automatically.
  • Deactivate — when your provider deactivates or deletes someone, Cobalt deprovisions them: the same cascade as Deprovision on their page. Their history is kept.
  • No reactivation over SCIM — if your provider later reactivates someone Cobalt has deprovisioned, Cobalt refuses the change and your provider shows an error. Add them back from the Cobalt console instead.
  • An established identity — a person People sync created counts as identified, the same as someone recognized through Slack, Teams, SharePoint or an embedded token (see End-user identity).

When someone leaves

When your provider deactivates someone, here is what ends, and when:
  • Slack and Teams: their next message is refused.
  • Privileged tools (tools that act with an integration’s admin credentials): refused on their next attempt, everywhere.
  • Their connected accounts: the integration authorizations they granted are revoked.
  • Web chat: their next message is refused, including in a chat they already have open. Signing in again doesn’t get them back in, and doesn’t create a new person for them.
  • The admin console: not affected. People sync never removes an administrator — do that on Settings › Team.

What Cobalt stores

Cobalt keeps a person’s name, email address, phone number and whether they are active. Other directory attributes your provider sends — including the enterprise extension’s department, title and manager — are accepted and not stored. Group membership is read from your directory at the moment it’s needed rather than copied into Cobalt, so it’s never stale here. The People sync page names any attributes your provider is currently sending that Cobalt doesn’t store, so a sync that looks clean in your provider isn’t hiding anything from you.

Manage tokens

  • Revoke token on the People sync page at any time; requests using it stop working immediately. Your other tokens keep working.
  • The page also shows Accept incoming users and Event queue health. If incoming users are turned off, Cobalt tells your provider so and keeps its changes in a queue, then applies them when it’s turned back on.
Treat a SCIM token like a password. Anyone holding it can add and deprovision people in your tenant. Revoke it and generate a new one if it may have leaked.