> ## Documentation Index
> Fetch the complete documentation index at: https://statsig-4b2ff144-serverless-cloudflare.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SCIM User and Project/Role Management

## Import Existing Statsig Users and Groups

<Note>
  Users not assigned to the integration cannot be pushed into groups.
</Note>

* In Okta, go to the Statsig app's "Import" tab
* Click "Import Now" to fetch existing Statsig users and groups
* Process the imported users as needed

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step6-import-existing-users.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=4ee46496174d9425f07f7938bcbdfdc9" alt="img" width="2040" height="1440" data-path="images/okta_scim_steps/step6-import-existing-users.png" />
</Frame>

## Manage User Assignments

* Use the "Assignments" tab in Okta to add or remove users from Statsig
* Adding a user assignment in Okta will create the user in Statsig, while removing the assignment will deactivate the user's Statsig account

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step7-manage-user-assignments.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=acc9ac2b4d96ff70b1ac89fd65c230d9" alt="img" width="2084" height="1366" data-path="images/okta_scim_steps/step7-manage-user-assignments.png" />
</Frame>

## Push Groups to Statsig

1. In Okta, go to the Statsig Integration's "Push Groups" tab
   <Frame>
     <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-1.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=76e61acbaab2579055843517c047cfa8" alt="img" width="2042" height="1428" data-path="images/okta_scim_steps/step8-push-groups-1.png" />
   </Frame>

2. Click the settings button and disable "Rename Groups"
   <Frame>
     <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-2.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=7c5de2d6ce2b19a0d2fae3419e1ae1b0" alt="img" width="2066" height="1336" data-path="images/okta_scim_steps/step8-push-groups-2.png" />
   </Frame>

3. Click "Push Groups" and select the method for finding groups in Okta.
   <Frame>
     <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-3.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=c3ad810991ef7d4bdc858a89153c9580" alt="img" width="2034" height="1436" data-path="images/okta_scim_steps/step8-push-groups-3.png" />
   </Frame>

4. Type in and select the Okta group that will push to a Statsig Project x Role Group.

* You can find Groups in left nav of Okta: `Directory > Groups`. In there, you will see the groups created from Okta and groups created by Statsig.
* The required groups are groups you created from Okta. You can filter by choosing `Group source type` and set to `Okta groups`. If you don't have any, go ahead and create it with members as well.
  <Frame>
    <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-4.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=f06b3dc11dc993c0cce37535fc11e8d3" alt="img" width="2038" height="1054" data-path="images/okta_scim_steps/step8-push-groups-4.png" />
  </Frame>

5. Now let's link/assign Okta group you created from Okta to the Statsig groups with role you want.

* Change `Match Result & Push Action` to `Link Group`
  <Frame>
    <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-5.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=0ad3454b88634a593e374ebd8ea87a06" alt="img" width="2054" height="1616" data-path="images/okta_scim_steps/step8-push-groups-5.png" />
  </Frame>

6. Select the Statsig Project x Role Group that the Okta group will push to.

* We display the Statsig Project x Role Group with the format `Statsig-<Project Name>-<Role Name>` on Okta.
* By default Okta only allows you to map 1 Okta Group to 1 Statsig Group.
  <Frame>
    <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-6.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=304daf4b7921c2890d973e2525ff4bd3" alt="img" width="2052" height="1596" data-path="images/okta_scim_steps/step8-push-groups-6.png" />
  </Frame>

7. Then link the Okta group to a Statsig Project x Role Group. On save the group should push to Statsig. All future group changes on Okta will be pushed to Statsig.
   <Frame>
     <img src="https://mintcdn.com/statsig-4b2ff144-serverless-cloudflare/07-Ip8yoBF41fH_r/images/okta_scim_steps/step8-push-groups-7.png?fit=max&auto=format&n=07-Ip8yoBF41fH_r&q=85&s=f6640fbec26e2503a5ade2123b2cf4f7" alt="img" width="2062" height="1612" data-path="images/okta_scim_steps/step8-push-groups-7.png" />
   </Frame>
