Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-docs

Identity and access changedgovernment/tenant-admin/identity-and-access

Nearest release: v2.1.295, published an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 8 Oct 2026 17:13 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 8 Oct 2026 17:37 UTC.

Upstream edited
Recorded here
Lines+54added
Lines−0removed
From line 75 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits6to this page, all time

The whole hunk

from line 75, old and new numbered
/
lines
from line 75
7575 
7676## SCIM provisioning
7777 
78<Frame caption="Video: Directory sync (SCIM) and group mappings (2 min 3 s). Narrated with an AI-generated voice, with on-screen captions.">
79 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-04-directory-sync-scim-and-group-mappings.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=e254e02786c5f309b5c5c240c7752c4e" aria-label="Video walkthrough: Directory sync (SCIM) and group mappings" data-path="images/government/videos/admin-04-directory-sync-scim-and-group-mappings.mp4" />
80</Frame>
81 
82<Accordion title="Transcript">
83 Directory sync is optional, and without it accounts are created at first sign-in. With it, your identity provider pushes users and groups, provisioning rules place them in organizations, and each organization maps groups to seat tiers and roles.
84 
85 On Identity and access, open SCIM provisioning. Copy the SCIM base URL, which your provider may call the Tenant URL, and select Generate token.
86 
87 The token is shown once. Copy it for your provider's secret token field, then select Done. You can revoke a token here at any time.
88 
89 In your provider's provisioning settings, paste both values, assign the groups you want to sync, and turn provisioning on.
90 
91 After the first sync, your groups appear under Directory groups with member counts, and people not yet placed wait under Synced, not routed.
92 
93 Under Provisioning rules, route groups to organizations. Send research-staff to Research Office, and claude-users to Operations Bureau. The first match wins, so add the narrower group first or drag it to the top.
94 
95 Once a rule covers them, they are placed in its organization, and the list clears on its own.
96 
97 In the organization's admin view, People now includes Group mappings. Map claude-users to a seat tier, here Standard, and claude-owners to the Owner role. Each change is applied right away.
98 
99 On Users, the provisioned members now hold their mapped seat tier and role.
100 
101 While sync is connected, your directory is the source of truth. Change groups in your provider, because role or seat tier edits made by hand are overwritten by the group mappings.
102</Accordion>
103 
78104SCIM is the standard protocol identity providers use to push users and groups to a connected service automatically, so that accounts are created, updated, and deactivated in step with your agency's directory. Connecting SCIM is optional; without it, users are created the first time they sign in. With SCIM connected, a person your directory has never sent still gets an account the first time they sign in, if a [sign-in rule](#sign-in-rules) covers them.
79105 
80106[Provisioning rules](#provisioning-rules-scim), [group mappings](/docs/government/org-admin/provisioning), and [group-specific settings](/docs/government/config/overview#group-specific-settings) need SCIM, because they act on the [directory groups](#directory-groups) your identity provider pushes. Model access and usage limits come from each person's [seat tier](/docs/government/org-admin/seat-tiers), which an organization owner can assign on the [Users](/docs/government/org-admin/users) page without SCIM.
from line 128
102128Once your identity provider has pushed groups over SCIM, they appear here with their member counts. To change the order, drag a group by the handle at the start of its row or use the **…** menu at the end. The order you set here is the priority used for group-level configuration on the [Config](/docs/government/config/overview#group-specific-settings) page.
103129 
104130## Routing rules
131 
132<Frame caption="Video: Organizations, seats, and routing rules (2 min 14 s). Narrated with an AI-generated voice, with on-screen captions.">
133 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-03-organizations-seats-and-routing-rules.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=3b4fdf17a38f17ace0a31daff24dd678" aria-label="Video walkthrough: Organizations, seats, and routing rules" data-path="images/government/videos/admin-03-organizations-seats-and-routing-rules.mp4" />
134</Frame>
135 
136<Accordion title="Transcript">
137 Routing rules decide which organization each person lands in. Organizations hold users, seats, and settings, and their seats come from a billing account.
138 
139 Marcus, a tenant administrator, signs in and opens the tenant view from the footer.
140 
141 A new colleague, Rosa, tries to sign in. No routing rule covers Rosa yet, so the page says Almost there. The attempt is recorded for tenant administrators.
142 
143 On Identity and access, Rejected sign-ins lists the attempt. Select Test in preview to check whether any rule covers Rosa.
144 
145 The preview says refused at sign-in, because no rule matches Rosa yet.
146 
147 Under Sign-in routing, add the first rule. Set If to Anyone with email domain, and choose example.gov. Set Then place in to Operations Bureau, and select Add rule. Rules run top to bottom, and the first match wins.
148 
149 Run the preview again. Rosa would now be placed in Operations Bureau.
150 
151 Rosa selects Try again and signs in once more. Rosa lands in Operations Bureau and gets a seat, because one was free.
152 
153 On Organizations, expand Add organization. Enter a name and the Primary Owner's email, choose the billing account, then select Add. The owner does not automatically become a tenant administrator.
154 
155 On Seats, the billing account shows its pool and the organizations it funds. Give Research Office seats and select Save. Its first seats also seat its Primary Owner, and the setup banner clears.
156 
157 To send people to Research Office, add an identity provider group rule for them and drag it above the domain rule. Each person belongs to exactly one organization.
158</Accordion>
105159 
106160A **routing rule** is an instruction of the form "if a person matches this condition, place them in this organization." Routing rules are the **only** way a new person gets into your deployment; there is no default organization and no fallback.
107161 
Feedback