Scimly · Identity & data software

We build software that proves its own trustworthiness.

Every Scimly product runs entirely in your browser — your directory data, access logs, and spreadsheets never touch a server we operate. You get an executive-grade report back in under a minute.

01

Runs where your data already is

No file leaves the browser tab. Connectors to Google Workspace and Microsoft Entra ID authenticate directly against your own app registration — we never see a token.

02

Answers, not dashboards to interpret

Every product ends in a decision-ready output: a readiness score, a phased remediation plan, a chart your team actually asked for.

03

Built for the people who get paged

IT admins, compliance consultants, and the analyst who owns "why is this dashboard wrong" — Scimly is scoped to their week, not a platform migration.

Why teams pick Scimly

Three things every Scimly product holds itself to

Under 60 secondsFrom raw export to a report you could hand an auditor.

Nothing routed through usNo remote backend sees your client's directory or dataset.

Exports that hold upPrint-ready PDF, structured Markdown, or clean CSV — every time.

Scimly · Products

Two products, built for two different Tuesdays.

Each one has its own interface, its own colors, its own release timeline. Open one to see the full picture — we don't cram them onto one page just because they share a name.

Scimly · Blog

Notes on access governance & data work

Short, specific write-ups from building Scimly Guard and Scimly Insight — not marketing copy.

Jul 2026
Access governance

The SCIM external ID nobody checks — until an audit

A missing SCIM external ID is one of the clearest signals that an account was never provisioned through your identity provider (IdP). While it might seem like a minor data gap, it's a red flag for auditors and a real risk to your access governance. Here's why it matters more than it looks like it should.

The externalId is the unique identifier that links a user's account in a service provider (like your app) back to their identity in an IdP like Okta, Azure AD, or Google Workspace. When an account is created via SCIM, this ID is automatically populated. If it's missing, it almost always means the account was created manually — outside of your standard, automated process.

This "shadow IT" account won't be deprovisioned when the user leaves the company, because the IdP doesn't know it exists. It won't be included in automated access reviews. It's a ghost in the machine, and during a SOC 2 or ISO 27001 audit, these are exactly the kinds of discrepancies that lead to findings. Scimly Guard flags these immediately, giving you a chance to remediate them before they become an audit headache.

Jul 2026
Building Scimly

Why we refuse to add a backend

Every Scimly product runs entirely in the browser. That's a real architectural cost, but it's a deliberate one. Here's what it buys back for the people trusting us with their directory data.

When you run an analysis in Scimly Guard, your user data is never uploaded to a server we control. It's processed locally, in the browser tab, on your machine. This means there is zero risk of a data breach on our end exposing your sensitive information. For access governance, where you're dealing with employee lists, roles, and permissions, that's not a small thing.

This constraint forces us to build simpler, more robust tools. It also means the base editions can't support multi-user collaboration or saved state out of the box. We think that's the right trade-off. For teams that need more, the architecture is designed to be extended with your own backend or database, keeping you in control.

Jun 2026
Access governance

The real cost of a dormant paid seat

A single dormant seat — a paid license for a user who hasn't logged in for 90 days — might seem like a rounding error. But it's rarely just one. If a single seat costs $19/month, that's $228 a year. Across a sales team of 50 people, if just 10% of those seats are dormant (a conservative estimate), that's $2,280 a year in pure waste for one department.

This isn't a budgeting failure; it's a provisioning one. When an employee leaves or changes roles, their access to major platforms is usually revoked automatically via SSO. But smaller, manually-provisioned tools are often forgotten. The license remains active, the credit card keeps getting charged, and nobody notices until the next annual audit.

Scimly Guard's license waste analysis flags these accounts by combining last-login dates with per-seat cost data. It gives you an exact dollar amount for monthly and annualized waste, making it easy to justify the cleanup effort and demonstrate immediate ROI to finance.

These are starter posts to launch with — swap in your own writing whenever you're ready, this structure will hold any number of posts.

Scimly Guard · Access review & SCIM readiness

Every stale account, MFA gap, and wasted seat — found before your auditor finds it.

Drop in a raw user-access export, or connect Google Workspace and Microsoft Entra ID live. Guard reads it, cleans it, and hands back a readiness score and remediation plan in under a minute — entirely in your browser.

findings.log ● analysis complete — 4.2s
Admin account "j.romero" active with no MFA enrolledEngineering
Missing SCIM external ID — account not provisioned via SSOFinance
Paid seat inactive 96 days — $228/mo wasteSales
Duplicate email address across two user recordsMarketing
Manager field unset for 3 usersOperations
Ingestion

Bring a CSV, or connect the real thing

Every edition reads your data the way you already have it — messy export or live directory.

CSV engine

Base Edition

Parses any raw user-access export — handles messy formatting, inconsistent dates, and alternate cost structures without a template.

Live sync

Google Workspace

Pulls your real-time user and admin structure via secure browser OAuth — no client secret required, no data leaves the tab.

Live sync

Microsoft Entra ID

Connects via MSAL.js + PKCE to query Microsoft Graph directly, with no backend infrastructure in between.

What it flags

Security risk analytics, run automatically

Guard runs the same checks a senior consultant would — just faster, and every time.

Stale & dormant accounts

Users and admins past a configurable inactivity threshold.

Privileged access gaps

Admin accounts operating without multi-factor authentication.

Provisioning vulnerabilities

Missing SCIM external IDs — accounts never provisioned through SSO/SCIM.

Orphaned & misconfigured records

Missing department metadata, unassigned managers, duplicate emails.

Financial license waste

Exact monthly and annualized cost of active-but-inactive paid seats.

Department breakdown

User counts, high-risk flags, and wasted dollars by team.

The report

An executive-style output, not a raw data dump

Everything below is generated automatically once analysis finishes — no manual chart-building.

Readiness at a glance

  • Overall readiness score (e.g. 51/100)
  • Risk distribution donut & bar charts
  • MFA coverage gauge

Action, not just findings

  • Severity-ranked findings with business impact
  • Phased plan: Immediate / This Week / This Month / This Quarter
  • High-risk table: Top 20, Top 50, or full dataset — in sync with export

Take it with you

  • Print-ready PDF with its own cover page
  • Structured Markdown report
  • Full analyzed dataset as CSV

Not a mockup — an actual run

These are the real files Scimly Guard produced from a 125,000-row directory export: the raw input, the full per-user results, the Markdown report, and the polished executive PDF. Tap any file to download it straight to your device.

Editions & pricing

Start free, connect what you need

Each option below is presented with a short detail view so you can see what changes before you click through.

Scimly product preview
Demo

Scimly — Access Review & SCIM Readiness Dashboard (Free Demo, CSV Edition)

What you get

A file, not a platform

index.htmlThe entire application, self-contained
sample-data.csv14-row demo dataset for quick runs
README.mdSetup & usage notes
PRICING.md / TRANSFER_NOTES.mdLicensing & handoff details

See your own directory scored in under a minute

Run the free demo first — no account, no upload leaves your browser.

Run the demo
Scimly Insight is in active development — this page previews what's coming.
Scimly Insight · In development

Upload a spreadsheet. Get a dashboard. No analyst required for the first pass.

Insight cleans your data, works out what each column actually is, and recommends the chart that fits — a KPI card, a pie, a line — then lets you rearrange, filter, and ask it questions from there.

Auto-recommended · Insight looks at each column and picks a chart
column: revenue
↓ recommended
KPI Card
$482K
column: country
↓ recommended
Pie Chart
column: order date
↓ recommended
Line Chart
How it works

Four steps, one upload

This is a real pipeline — each step depends on the one before it, so we're building and shipping it in this order.

01

Upload

Drag in a CSV or Excel file. Insight validates it and confirms it's readable before anything else happens.

02

Clean & understand

Duplicates removed, gaps filled, and every column's real type worked out automatically.

03

Recommend

Each column gets matched to the chart that actually fits it — not a generic template.

04

Dashboard

Everything renders automatically. From there you can rename, resize, recolor, and rearrange.

Coming after launch

What we're building next

In the order we're building it — each one only starts once the step before it is solid.

Editing

Make the dashboard yours

Rename, delete, resize, or swap the chart type on any widget — right on the canvas.

Layout

Drag, resize, save

Arrange widgets exactly how your team reads them, and it stays that way next time.

Filters

One filter, every chart

Change the date range or the country once — every widget on the dashboard updates together.

Saving

Save, duplicate, share

Keep dashboards for each dataset, duplicate one as a starting point, or hand it to a teammate.

Exporting

Take it with you

Export as PDF, PNG, CSV, Excel, or JSON — whatever the next meeting needs.

Ask Insight

Ask your data a question

Type "show monthly revenue" and get the chart back, no formula required.

Be the first to try Scimly Insight

We'll email you the day the first version is ready to run.

Get notified