Skip to main content

Supported IGA platforms and capabilities

Overview · Identity Governance Platforms

Written by Agent Bob

StackBob.ai extends your identity governance platform's provisioning to apps that have no native SCIM support. Your IGA platform connects to StackBob.ai over SCIM 2.0 as it would to any SCIM-enabled app, while StackBob NCAP™ handles the connection to the app.

StackBob.ai offers a natively integrated flow for the most common enterprise IGA platforms, and a custom setup flow for virtually any IGA platform with a SCIM 2.0 client.


Your primary IGA

You select a primary IGA when you create your StackBob.ai organization. It defines the organization's SCIM settings, setup flow, and the structure of the SCIM URL issued for each managed app.

ℹ️ To change your primary IGA in an existing StackBob.ai organization, or to connect more than one governance platform, contact your onboarding representative.


SailPoint

SailPoint connects to each managed app as a SCIM 2.0 source via a dedicated SCIM endpoint StackBob.ai provides for each. The app's entitlements are exposed as SCIM groups, so SailPoint can aggregate them and govern them through access profiles and roles.

  • Automated SCIM setup creates or maps the source through the SailPoint API [Coming soon]

  • Manual SCIM setup provides the SCIM URL and token for you to configure the source in SailPoint.

  • Existing accounts are reconciled through aggregation and correlation. SailPoint handles uncorrelated accounts natively, so there is no Rogue user review step.

  • Once SCIM is set up, StackBob.ai handles user provisioning, updates, deactivation, and ongoing rogue user detection.

See also: Set up SCIM provisioning from SailPoint

Okta

Okta connects to each managed app as a SCIM 2.0 app integration via a dedicated SCIM endpoint StackBob.ai provides for each. The app's entitlements are exposed as SCIM groups, so Okta can import them, then link and govern through Okta Groups.

  • Automated SCIM setup option creates (or maps existing) application in Okta, exposes entitlements as SCIM groups for import, then creates and links Okta Groups, through the Okta Management API.

  • Manual SCIM setup option exposes entitlements as SCIM groups for import and provides a CSV export of groups and memberships in case the flow needs to be tested manually before connecting Okta API.

  • Existing accounts are reconciled through Okta SCIM import, Okta Push Group linking, and Rogue user detection/review.

  • In the automated SCIM setup flow, existing app user accounts are reconciled by comparing with existing active Okta users. In case app's user account don't have corresponding user identity in Okta or if corresponding user identity is deactivated in Okta → those app accounts will be marked as Rogue in StackBob and presented for review.

  • Once SCIM is set up, StackBob.ai handles user provisioning, updates, deactivation, and ongoing Rogue user detection.

  • Okta can also be used as SSO provider for StackBob.ai and as discovery source for apps.

See also: Set up SCIM provisioning from Okta

Microsoft Entra ID

Entra ID connects to each app as an enterprise application via a dedicated SCIM endpoint StackBob.ai provides for each. The app's entitlements are exposed as SCIM groups, so Entra ID can provision access to the app via SCIM.

  • The automated SCIM setup option creates, or maps to an existing, enterprise application, creates groups corresponding to the app's entitlements, and adds current active app users as members, using the Microsoft Graph API.

  • The manual SCIM setup option exposes entitlements as SCIM groups and provides a CSV export of groups and memberships, in case the flow needs to be tested manually before connecting the Microsoft Graph API.

  • In the automated SCIM setup flow, existing app user accounts are reconciled by comparing them with active Entra ID users. If an app account has no corresponding user in Entra ID, or its corresponding user is deactivated, the account is marked as Rogue in StackBob.ai and presented for review.

  • Once SCIM is set up, StackBob.ai handles user provisioning, updates, deactivation, and ongoing Rogue user detection.

  • Entra ID can also be used as an SSO provider for StackBob.ai and a discovery source for enterprise apps.

Other IGA platforms

Any identity governance platform that acts as a SCIM 2.0 client can connect and manage any web app through SCIM endpoint provided for it by StackBob.ai. StackBob.ai issues a dedicated SCIM URL and token for each app; you configure the platform's SCIM connector with them.


The custom flow provides:

  • User provisioning, updates, and deactivation, as well as ongoing rogue user detection.

  • A CSV export of the app's entitlements and memberships, for initial reconciliation in the IGA platform.

The custom flow does not provide:

  • Automated setup. There is no platform API integration, so the app, groups, and mappings are configured in the platform manually.

  • Guided reconciliation. The initial review and reconciliation of the users that exist in the app must be performed manually.

ℹ️ If you want to set up SCIM provisioning for a custom IGA, contact your StackBob.ai onboarding representative.


Capabilities by platform

Capability

SailPoint

Okta

Entra ID

Other IGA

User provisioning over SCIM 2.0

Group provisioning over SCIM 2.0

Automated SCIM setup via API

[Coming soon]

Native group creation via API

Not required

Guided reconciliation of existing accounts

Not required

Ongoing Rogue user detection

CSV export for manual reconciliation

Discovery source for managed apps

Can be used as SSO provider for StackBob.ai

Access Logs


Next steps

  • How StackBob.ai works

  • Quickstart: Connect your first managed app — set up a managed app and run the first NCAP™ sync before connecting a governance platform.

  • Terminology — StackBob.ai terms used across all platform sections.

Did this answer your question?