With SCIM 2.0, your identity provider manages the Yardstick roster for you: assign the app to someone in Okta or Microsoft Entra ID and they get a Yardstick account in your workspace; unassign them (or offboard them) and their access is deactivated automatically. That makes offboarding safe by default, no manual member cleanup.
Setup is owner or admin only, under Settings, in the SCIM card: copy the SCIM base URL and issue a bearer token, then paste both into your IdP's provisioning settings. The token is shown once, so store it in the IdP right away; you can rotate it at any time, which immediately invalidates the old one. SCIM is part of the Enterprise plan and is enabled for every workspace during the beta.
