SCIM (System for Cross-domain Identity Management) automates user account creation, updates, and deprovisioning across services. It’s efficient, standardized, and supported by major identity providers. But SCIM endpoints often expose sensitive attributes. Without privacy-preserving mechanisms, provisioning can leak personal data, role hierarchies, or organizational structure to third parties.
Core Requirements