Documentation

Directory sync

Keep members and teams up to date through your identity provider's directory.

Updated Sep 24, 2026

Directory sync keeps withHuman membership aligned with your organization's directory. It brings in people and groups, updates their membership, and ends access when the directory suspends or removes someone. Directory sync is part of the hosted edition.

Directory connection

The Directory sync section in Sign-in and directory provides a setup link for your identity administrator. Guided setup connects a supported directory, including providers that use SCIM, a standard for provisioning users and groups.

The link expires at the time shown. The administrator can complete setup without a withHuman account. A new setup link can replace an existing connection.

Directory sync is configured separately from SSO. SSO confirms who is signing in; directory sync maintains who belongs to the organization.

Members

People assigned through the directory appear in Members with a Directory badge. Make changes to their directory-managed status at the provider.

Deactivating a person suspends their withHuman membership and signs them out of the organization. Removing them deprovisions the membership and revokes their personal API keys. Past decisions and audit history remain.

Directory updates can remove a reviewer even when an active escalation path names them. Keep escalation paths current as people change jobs or leave.

Groups and teams

Each synced group maintains a withHuman team. The directory supplies its name and synced members. That team's permission policies determine the access its members inherit.

Loading diagram…

Diagram source
mermaid
flowchart TD
  Group["Group in your directory"] -->|"Syncs name and members"| Team["Team in withHuman"]
  Policies["Team permission policies"] --> Team
  Team -->|"Members inherit access"| Members["People on the team"]

Directory groups lists the synced groups and links to each team's permissions. Access from a group applies through its team membership. Other team memberships and direct permissions can still provide access when someone leaves a group.

You can add manual members alongside synced members. Removing a manual membership does not remove a membership supplied by the directory. See Directory membership for team management.

Example: Payments reviewers

Our directory has a Payments reviewers group. Its synced team has permission to read, claim and decide requests. We'll select that team in an escalation path, so new group members inherit review access and receive the team's assigned requests.

Sync status

The connection shows its directory and the time of the last full sync. Sync degraded means the last reconciliation did not finish successfully. Ask the identity or deployment administrator to check the connection. Check again refreshes the displayed status; it does not force a directory sync.

If a person is missing, check that they are assigned to withHuman in the provider, then check Audit log for rejected directory changes. Hosted seat limits can block new members; add capacity in Billing before retrying provisioning. withHuman also prevents removal of the last active owner.

Viewing the connection and managing its setup require separate permissions. Team permission changes require access to manage those policies. If Connector not enabled appears, the deployment administrator needs to enable directory support.