Haystack’s user provisioning model may be different from other implementations you’ve used in the past (for example, SCIM). This is due to specific requirements that satisfy various privacy regulations around the world (such as GDPR).
Rather than provisioning user accounts directly, Haystack provisions Haystack cards, which themselves have membership of your organization.
Users authenticate with one of your allowed sign-in methods into their user account, which by way of a matching email address is granted access to their card and the organization.
Removal of the card from the user’s account, or of the card from the organization, removes the user’s access to all organization resources.
Cards can be provisioned and deprovisioned manually through our Admin Dashboard UI, or, for Enterprise customers, automatically with an integration, including through Azure AD/Entra ID, file uploads, or our API.
| Free | Pro | Business | Enterprise |
Manual provisioning |
| ✅ | ✅ | ✅ |
Automatic provisioning |
|
|
| ✅ |
Provisioning with Azure AD/Entra ID |
|
|
| ✅ |
Provisioning via API |
|
|
| ✅ |
Provisioning via CSV/bucket uploads |
|
|
| ✅ |
