Current support
OpenWork supports SCIM provisioning through identity providers that can send SCIM requests to the OpenWork SCIM base URL with a bearer token. Google Workspace’s automated user provisioning is app-catalog based: Google provides provisioning setup screens and app-specific guides for supported applications. For a custom SAML app created for OpenWork, Google Admin provides SAML settings, optional SAML attribute mappings, and service access controls, but does not show the SCIM fields OpenWork needs:- SCIM base URL or tenant URL
- Bearer token or secret token
- Create, update, deactivate, or reactivate user actions
- Group push or group provisioning actions
- SCIM attribute mappings such as
userName, work email, given name, family name, and display name
What still works with Google Workspace
Google SAML SSO can authenticate OpenWork members and create first-login members through OpenWork’s just-in-time SSO provisioning. JIT provisioning is not the same as SCIM:- It happens when a user signs in successfully.
- It can create the OpenWork organization membership with the default
Memberrole after successful SAML authentication. - A standalone email/password signup with the same verified domain does not add the user to the organization or replace the SAML sign-in requirement.
- It does not continuously sync profile changes from Google.
- It does not deactivate OpenWork access when a Google user is suspended or deleted.
- It does not create SCIM-managed OpenWork teams from Google groups.
How to confirm in Google Admin
After setting up the OpenWork custom SAML app, open the Google Admin console and check:- Apps → Web and mobile apps → OpenWork.
- The app’s configuration sections and side navigation.
- Any settings named Provisioning, Auto-provisioning, User provisioning, or SCIM.