Audit trail for every SCIM provisioning event SkillsDB receives. Filter by event type, source, group, and date to verify sync activity or troubleshoot problems.
Quick Summary: The SCIM Event Log records every provisioning event SkillsDB receives, including user creation, updates, deactivations, group changes, and career assignments. Use it to verify a sync worked or to diagnose why a user did not appear.
The SCIM Event Log is an audit trail for every SCIM event that SkillsDB processes. Each row represents one action triggered by your identity provider, the SCIM background sync, or an administrator.Use the event log to:
Verify that a specific user or group change was processed
Diagnose why a user is missing, deactivated, or has the wrong permission level
Track permission changes and manager reassignments over time
Export a filtered audit trail for compliance reporting
The event log is admin-only and covers events from your company only. Events from other SkillsDB customers are not visible.
The event log has ten event types, each representing a specific action. The Event Type filter in the toolbar lets you filter by one or more types simultaneously.
Event type
What it means
Provisioned
A new user was created in SkillsDB from a SCIM event.
Updated
An existing SCIM-provisioned user had their attributes, manager, or group membership updated.
Deprovisioned
A user was deactivated because they were removed from SCIM, disabled in the IdP, or had all groups removed.
Group Created
A new SCIM group was registered in SkillsDB (either default, auto-created from an IdP event, or admin-created).
Group Updated
An existing SCIM group was modified (permission level, description, or automations).
Group Deleted
A custom SCIM group was deleted or deactivated. (Default groups cannot be deleted — see SCIM Groups and Permissions.)
The Source column shows where the event originated:
Webhook — The event came from your identity provider through Stytch. This is the most common source for real-time provisioning activity.
Cron Sync — The event came from SkillsDB’s scheduled background sync. This sync retries manager assignments that failed during the initial provisioning and periodically reconciles group memberships.
Manual — The event was triggered by a SkillsDB administrator action, such as creating or editing a custom SCIM group.
Problem: A user who should be in SkillsDB is missing
1
Filter by Event Type: Provisioned
Set the Event Type filter to Provisioned and set a Date range covering when the user was added in your identity provider.
2
Look for the user
If you see a Provisioned event for the user, SCIM created them successfully — check whether they were subsequently deprovisioned. If no Provisioned event appears, the SCIM event for that user never reached SkillsDB.
3
Check your identity provider
In Entra, verify the user is assigned to the SCIM application and belongs to at least one of the provisioning groups. Use Provision on Demand in Entra to push the user immediately. See SCIM Setup and Azure Sync Considerations.
Set Event Type to Permission to see every permission-level change. The Event column shows the old value and the new value.
2
Check group memberships
Filter by the user’s name in a People view filtered by SCIM group membership, or check the Member Added and Member Removed events in the log for that user.
3
Review custom group configuration
If the user is in a custom SCIM group, confirm the group’s permission level in Settings > SSO & SCIM. See SCIM Groups and Permissions.
SkillsDB retains SCIM event log entries for ongoing audit and troubleshooting. Contact SkillsDB Support if you need to export or purge events for compliance reasons.
Why don't I see events for users who signed in but weren't provisioned via SCIM?
The SCIM Event Log only records provisioning events. Sign-in activity is separate from SCIM and does not appear in this log. Users who sign in via SSO but were created manually in SkillsDB will not appear here.
Can I see events from before SCIM was enabled?
No. The event log starts when SCIM is first configured for your company. Events before that point are not available.
What does a Cron Sync event mean?
SkillsDB runs a scheduled background sync to fix manager assignments that couldn’t be made during initial provisioning (because the manager was provisioned after the direct report) and to reconcile group memberships. Events from this background sync are tagged with Cron Sync as their source.
Can non-admins see the event log?
No. The event log is visible only to SkillsDB administrators. Users without admin permission do not see the Event Log button on the SSO & SCIM settings page.
If you see events that do not match what you expect, or need to investigate a specific sync incident, reach out to your organization’s SkillsDB administrator or contact SkillsDB Support.