Directory Sync (SCIM)
Directory Sync keeps an Enterprise organization’s Mindsmith membership aligned with an identity provider that supports SCIM 2.0. It can provision, reactivate, and remove members without requiring an Admin to repeat those changes by hand.
Directory Sync is a beta Enterprise feature. An organization Admin must configure it, and it appears under Settings → Security only when the feature is enabled for the organization. Mindsmith asks the Admin to reauthenticate before enabling, rotating, or disabling a connection.
Enable Directory Sync
Open Settings → Security.
Find Directory Sync (SCIM) and select Enable Directory Sync.
Copy the SCIM Base URL and Bearer Token into your identity provider’s SCIM configuration.
The token is shown only when the connection is created or rotated. Save it before closing the dialog. The Base URL remains visible in Mindsmith.
Configure your identity provider to:
Use the displayed Base URL
Send the token as an HTTP bearer token
Use email as the user identifier
Provision, update, and deactivate users
Use the URL from the correct Mindsmith region. US and EU organizations have separate connections and credentials.
Choose the default role
The Default role for new members setting controls how newly provisioned people join:
Author can create and edit content and uses an author seat.
Viewer can view and take content and does not use an author seat.
Directory Sync never assigns Admin access. Grant Admin access manually in Mindsmith.
The default role is applied when a person first joins or rejoins. Directory updates preserve a higher role that was assigned in Mindsmith. Changing the default from Viewer to Author can raise synced Viewers on a later sync; changing it to Viewer does not demote existing Authors or Admins.
If no author seat is available, a person whose default is Author joins as a Viewer. Mindsmith promotes waiting synced members when seats later become available.
What is and is not synchronized
Directory Sync uses user assignments to control organization membership. Group objects may be accepted by the connection, but they do not create Mindsmith groups or map groups to roles.
For an existing Mindsmith account, a directory update does not replace the person’s global name or email address. If an email change is legitimate, contact Mindsmith Support.
When a person is deactivated
Deleting or deactivating a synced person in the identity provider removes that person’s access to the organization. Their author seat is released and integrations they personally authorized for that organization are revoked.
Mindsmith does not delete the person’s account, content, or history. Reactivating the person in the directory can restore their membership.
Before deactivating an Admin, make sure another active Admin remains. Directory Sync does not block removal of the last Admin.
Monitor provisioning
The Directory Sync card shows synced user and group counts plus Recent provisioning activity. Check this list after configuration changes or bulk directory updates. It highlights events such as:
A person being added as a Viewer because no author seat was available
An email mismatch that Mindsmith did not apply
A person being matched by email
A person Mindsmith could not match to an account
Mindsmith also performs periodic reconciliation, so a change may be repaired on a later sync. If an expected change is still absent after an hour, review the activity list and contact Support with the affected email address and approximate time of the change.
Rotate or disable the connection
Select Rotate Token when a credential may have been exposed or your security policy requires rotation. Rotation creates a new Base URL and token and invalidates the previous pair, so replace both values in your identity provider.
Select Disable Directory Sync to remove the connection and stop future synchronization. Members who were already provisioned keep their current access. Re-enabling creates a new connection and new credentials.
Troubleshooting
The card is not visible: confirm the organization is on Enterprise, you are an Admin, and Directory Sync has been enabled for the organization.
The identity provider reports an authorization error: confirm both the Base URL and bearer token belong to the current connection. Rotate the token if it is no longer available.
Group changes do not affect roles: this is expected; use the default provisioning role and manage exceptions in Mindsmith.
A deactivated person still has access: check Recent provisioning activity. Remove the person manually if Mindsmith could not match the directory identity.
For vendor-specific setup details, see the BoxyHQ Directory Sync documentation.
