The SCIM external ID nobody checks — until an audit
A missing SCIM external ID is one of the clearest signals that an account was never provisioned through your identity provider (IdP). While it might seem like a minor data gap, it's a red flag for auditors and a real risk to your access governance. Here's why it matters more than it looks like it should.
The externalId is the unique identifier that links a user's account in a service provider (like your app) back to their identity in an IdP like Okta, Azure AD, or Google Workspace. When an account is created via SCIM, this ID is automatically populated. If it's missing, it almost always means the account was created manually — outside of your standard, automated process.
This "shadow IT" account won't be deprovisioned when the user leaves the company, because the IdP doesn't know it exists. It won't be included in automated access reviews. It's a ghost in the machine, and during a SOC 2 or ISO 27001 audit, these are exactly the kinds of discrepancies that lead to findings. Scimly Guard flags these immediately, giving you a chance to remediate them before they become an audit headache.