> ## Documentation Index
> Fetch the complete documentation index at: https://statsig-4b2ff144-mintlify-add-local-eval-country-note-96362.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SCIM Org Roles

## Update Okta User Org Role

For every user, Statsig surfaces a SCIM field named `statsigOrgRole`. Through this field, you can manage organization user roles.
Currently, Okta can only push role updates to Statsig. We currently support the following org roles: `Member` `Admin` `Owner`

### Step 1. Create the Custom Attribute in Okta

Navigate to `Directory > Profile Editor` and select the User (default) Okta profile. This represents all of the Okta users' attributes.
Scroll down and press `Add Attribute` and fill out the new attribute to have the variable name `statsigOrgRole`.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step1.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=e47856f4dc8b9d10e147c083e6a4a390" alt="Okta profile editor showing custom statsigOrgRole attribute being added" width="1396" height="1514" data-path="images/okta_scim_steps/org_steps/step1.png" />
</Frame>

### Step 2. Create the Custom Attribute in the Statsig SCIM Integration

Now Navigate to the `Statsig SCIM Integration's User Profile` in the `Profile Editor`.
Add an new attribute that matches the following format:

* Variable name: `statsigOrgRole`
* External namespace: `urn:ietf:params:scim:schemas:core:2.0:User`
* Attribute type: either `Personal` or `Group`, depending if using groups for app assignment

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step2.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=9467f50c8009b7abab3c416cb252bf80" alt="Statsig SCIM integration user profile with statsigOrgRole attribute definition" width="1292" height="1954" data-path="images/okta_scim_steps/org_steps/step2.png" />
</Frame>

### Step 3. Create a Mapping from Statsig to Okta for the Custom Attribute

On the same Statsig SCIM profile editor, navigate to the `Mappings` button.
Scroll down to the new attribute `statsigOrgRole` and map `user.statsigOrgRole` to the Okta attribute `statsigOrgRole`.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step3.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=d50e834ee17193bb0a798e597663c20c" alt="Okta mapping editor linking statsigOrgRole between Statsig and Okta profiles" width="2004" height="830" data-path="images/okta_scim_steps/org_steps/step3.png" />
</Frame>

### Step 4. Create a mapping from Okta to Statsig for the Custom Attribute

Now navigate to the Okta User to Statsig SCIM user mapping.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step4_1.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=ea4b0f12941bd2d66523fa9a40126e6d" alt="Okta to Statsig user mapping screen for statsigOrgRole attribute" width="1930" height="614" data-path="images/okta_scim_steps/org_steps/step4_1.png" />
</Frame>

Scroll down to the `statsigOrgRole` attribute and map `user.statsigOrgRole` to the Okta attribute `statsigOrgRole`.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step4_2.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=21ad0927e3d69971e6b36f43cbcf8b8d" alt="statsigOrgRole attribute mapping row pointing from user field to Okta attribute" width="1822" height="522" data-path="images/okta_scim_steps/org_steps/step4_2.png" />
</Frame>

Now all users will be synced with their organization role. On the Statsig SCIM integration you can modify a user's role directly as well.

### Step 5. Modify Integration Mappings

Navigate to the Statsig SCIM integration provisioning section.
Under the "To App" tab, scroll down to the `statsigOrgRole` attribute.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step5_1.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=914b6ee06d1dcbb2fafcab3e86437e91" alt="Provisioning To App tab showing statsigOrgRole attribute settings" width="1394" height="480" data-path="images/okta_scim_steps/org_steps/step5_1.png" />
</Frame>

Set the attribute value to `Map from Okta Profile` and `statsigOrgRole`.
Set apply on `Create and update`.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step5_2.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=670b3ad5fb8d219d6f061c219f1eb33d" alt="Set value dialog choosing Map from Okta Profile for statsigOrgRole" width="1548" height="622" data-path="images/okta_scim_steps/org_steps/step5_2.png" />
</Frame>

Navigate to the "To Okta" tab and scroll down to the `statsigOrgRole` attribute.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step5_3.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=f1f92ef8d532da6fdbe3b915a818834b" alt="Provisioning To Okta tab listing statsigOrgRole attribute" width="1386" height="456" data-path="images/okta_scim_steps/org_steps/step5_3.png" />
</Frame>

Set the attribute value to `Map from Statsig Profile` and `statsigOrgRole`.
Set apply on `Create`.

<Frame>
  <img src="https://mintcdn.com/statsig-4b2ff144-mintlify-add-local-eval-country-note-96362/ahYmxJnFD3AOogdM/images/okta_scim_steps/org_steps/step5_4.png?fit=max&auto=format&n=ahYmxJnFD3AOogdM&q=85&s=4716868ea65c35c1d4c4f84ef347ab56" alt="Set value dialog mapping statsigOrgRole from Statsig profile back to Okta" width="1548" height="526" data-path="images/okta_scim_steps/org_steps/step5_4.png" />
</Frame>
