Configure Google Workspace SAML first so provisioned users can sign in. SCIM manages workspace membership; SAML handles authentication.
Prerequisites
- Google Workspace admin access
- Antsfield workspace owner role
- Enterprise plan with SCIM enabled
- SAML SSO configured (recommended)
Set up Google Workspace SCIM
1
Open Antsfield SCIM settings
In Antsfield, go to Settings → Security and open SCIM configuration. Generate or copy your:
- SCIM endpoint URL
- Bearer token (shown once — store in a secrets manager)
2
Enable provisioning in Google
In the Google Admin console, open your Antsfield SAML app (or create a provisioning integration if your Google edition supports automated user provisioning for custom apps).Enable Automatic provisioning and enter the Antsfield SCIM endpoint URL and bearer token when prompted.
3
Map attributes
Map Google directory attributes to Antsfield SCIM fields:
Ensure the email sent by Google matches how users are identified in Antsfield.
4
Assign users or groups
Assign the Antsfield app to Google users or groups who should be provisioned. Google pushes create, update, and deactivate events to Antsfield via SCIM.
5
Verify provisioning
- Assign a test user in Google.
- Confirm they appear under Settings → Members in Antsfield.
- Deactivate the test user in Google and confirm they lose workspace access.

