> ## Documentation Index
> Fetch the complete documentation index at: https://docs.introw.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Provisioning

> Set up how partners, contacts, and your team get into Introw: CRM sync, portal access from a CRM field, team invites, single sign-on, and SCIM.

export const Rail = ({children}) => <div className="not-prose" data-overview="rail">
    {children}
  </div>;

## Where it lives

Provisioning sits under **Settings**, at [Integrations](https://app.introw.io/settings/integrations).

<Frame>
  <img src="https://assets.introw.io/docs/features/access/provisioning/shots/scim.png" alt="The Internal SSO page scrolled to allowed domains and SCIM provisioning, where directory sync is turned on." />
</Frame>

## Before you start

| You need                    | Why                                     | Fix it                                                                            |
| --------------------------- | --------------------------------------- | --------------------------------------------------------------------------------- |
| A connected CRM             | Partners and contacts provision from it | [Connect a CRM](/features/integrations/crm/guides/connect-hubspot)                |
| Team management permission  | To invite users and define roles        | [Internal roles](/features/access/team-management/guides/create-an-internal-role) |
| SSO permission on your role | SCIM rides on the SSO add-on            | [Set up SSO](/features/access/sso/guides/set-up-internal-sso)                     |

## How it works

Provisioning is not one screen, it is four paths that put people into Introw and keep their access correct. Most of it is automatic once the CRM is connected:

* **From the CRM.** The partner accounts you select become partners. Each partner's CRM account owner is suggested as an internal team member you accept with one click, and set as the partner's manager; a new owner appears as **Requested** on the **Users** tab. Any partner managers you assign through a CRM owner property are matched to existing team members. Every contact associated with the partner's company is imported automatically under the partner's **People**. This all runs off the CRM sync, with no SSO required.
* **Partner portal access.** A partner contact can log in once you grant access, either with the **Portal access** toggle on the partner's **People** tab, or automatically from a CRM field so access is granted and revoked without touching Introw. Dynamic segments built on synced CRM fields then decide which portal tabs and content each contact sees.
* **Your internal team.** You invite colleagues on **Settings, Team**, or let them sign in through your identity provider, where a matching team member is created the first time they log in.
* **SCIM.** Your identity provider creates, updates, and deactivates internal team members on its own, so leavers lose access without a manual step.

The sources of truth stay outside Introw, and the roster inside Introw follows them:

```mermaid theme={"theme":{"light":"github-light","dark":"github-dark"}}
flowchart LR
  crm["CRM accounts, owners, contacts"] -->|"sync"| introw["Introw"]
  idp["Identity provider"] -->|"SSO and SCIM"| introw
  introw --> team["Internal team"]
  introw --> people["Partner contacts"]
  people --> portal["Partner portal access"]
```

## Settings & configuration

Provisioning is configured across a few surfaces, one per path.

### Partners and contacts from the CRM

In **Integrations** (the CRM and Data settings), **How do you store partners in your CRM?** sets the partner object, and **Find partners in your CRM** filters that object down to real partners. Turn on **Automatically sync new partners** so any future record that matches becomes a partner on its own. When a partner is created this way, Introw provisions the people around it too, all from the CRM and with no SSO required:

* **Account owner to internal team.** The partner's CRM account owner is added as the partner's manager and suggested as an internal team member. If they are not yet on your team, they appear as **Requested** on the **Users** tab under **Settings, Team**, where an admin accepts them with one click (or declines).
* **Assigned partner managers.** If you map a partner team role to a CRM owner property, the people named there are auto-assigned to that role on each partner. This matches existing team members only; it does not create new users. See [Set up partner team roles](/features/access/team-management/guides/set-up-partner-team-roles).
* **Company contacts.** Every contact associated with the partner's company is imported automatically and appears under the partner's **People**, ready to be given access, with no per-contact action needed.

Full walkthrough: [Sync partners and contacts from your CRM](/features/integrations/crm/guides/sync-partners-and-contacts) and [Detect partners from your CRM](/features/partners/partner-management/guides/detect-partners-from-your-crm).

### Partner portal access

On a partner's **People** tab (under [Partners](https://app.introw.io/partners)), the **Portal access** column toggles each contact's access, shown as **Grant access** and **Revoke access**. To let the CRM decide instead, open **Configure** and, on the portal-access property, select **Sync** to open **Sync contact fields with \[your CRM]**. There you set:

* **Access property** - the CRM contact field that controls access. A positive value keeps the contact's access active; a negative value revokes it. This makes the CRM the source of truth for who can log in.
* **Role property** - a CRM contact field used to group contacts by role, which feeds segments and reports. Optional.

Reference: [Drive contact portal access and roles from your CRM](/features/integrations/crm/guides/map-contact-portal-access).

Access is not only one contact at a time. **Dynamic segments** group partners and contacts by their synced CRM fields (tier, region, role, lifecycle stage, and more) and update themselves as the CRM changes. Segments then decide who sees which portal tabs and content, so visibility is governed by live CRM data with no separate list to maintain. This is where syncing and access management meet: the same fields that flow in from the CRM also drive who can see what. See [Segments](/features/partners/segments) and [Build dynamic segments on account and contact fields](/features/integrations/crm/guides/sync-partners-and-contacts).

### Your internal team

On **Settings, Team**, the **Users** tab is where you **Invite team member** and manage seats, **Roles** defines the internal roles built from permission categories, and **Partner team roles** defines the roles people hold on a partner. See [Invite a team member](/features/access/team-management/guides/invite-a-team-member) and [Create an internal role](/features/access/team-management/guides/create-an-internal-role).

### Single sign-on and SCIM

On **Internal SSO** (Settings, Developers), turning on SSO lets your team sign in through your identity provider; on first sign-in a matching team member is created just in time, governed by the **Allowed domains** list and the **Default role** in the attribute mapping. The same page has a **SCIM provisioning** section: after you **Enable SCIM provisioning**, copy the **Base URL** and **Bearer token** into your identity provider and it will create, update, and deactivate team members automatically. **Portal SSO** provides the same sign-in for partner contacts.

<Note>
  SCIM provisions internal team members only. Partner contacts are provisioned from the CRM and, if you use partner portal SSO, created the first time they sign in. There is no SCIM for partner contacts.
</Note>

## How-to guides

<Rail>
  * [**Provision your team with SCIM**](/features/access/provisioning/guides/provision-your-team-with-scim)

    Connect your identity provider to Introw over SCIM to automatically create, update, and deactivate internal team members and their access.
</Rail>

## Troubleshooting

<Warning>
  Single sign-on and SCIM are a paid add-on and must be enabled on your plan. SCIM provisions internal team members only, not partner contacts. When you drive portal access from a CRM field, that field is the source of truth: setting it to a negative value revokes the contact's access on the next sync.
</Warning>

<AccordionGroup>
  <Accordion title="A partner's contacts are missing">
    Confirm the contacts are associated with the partner's company in the CRM, and that a sync has run since they were added.
  </Accordion>

  <Accordion title="A contact can't be toggled on">
    The partner has no portal yet, so create or assign one first.
  </Accordion>

  <Accordion title="A team member was not created on SSO login">
    Check that their email domain is in **Allowed domains** and that the attribute mapping and **Default role** are set.
  </Accordion>

  <Accordion title="The identity provider cannot provision users">
    Confirm **SCIM provisioning** is enabled and the token is current; rotate the token and update the identity provider if in doubt.
  </Accordion>
</AccordionGroup>
