ClickHouse Cloud now supports SCIM 2.0 provisioning, letting Enterprise and BYOC customers manage user access through their identity provider. The practical gain is that new starters, leavers and group changes can flow through without an administrator repeating the work by hand.
ClickHouse Watch analysis
What happened
ClickHouse says its SCIM endpoint lets a connected identity provider create and remove accounts, and keep ClickHouse roles in step with group membership. Provisioning requires an active SAML connection and is available for verified email domains. The company says changes are recorded in the organisation’s audit log.
To set it up, an administrator enables SCIM in the organisation’s SAML and SCIM settings, generates an endpoint key and adds the credentials to the identity provider. The key is limited to the SCIM endpoint, and ClickHouse shows its secret only once. Read ClickHouse’s setup guide.
There are useful boundaries: SCIM manages SSO users, not members invited separately; system roles such as Admin cannot be assigned through it; and removing the SAML connection disables provisioning. Authentication remains with the identity provider, with no password sync to ClickHouse.
Why it matters
Manual account changes are easy to forget, especially when someone leaves or moves teams. SCIM gives organisations one place to manage membership and group-based permissions, reducing the chance that access lingers simply because nobody remembered the extra admin step.
The limits matter too. This is an Enterprise and BYOC feature, not a switch for every plan, and SCIM does not take over every kind of account or role. It is access administration made less fiddly, not a magic wand for identity governance.
Our read
This is a useful, concrete addition for organisations already using SAML: membership and role changes can follow the identity provider instead of relying on a second round of manual housekeeping. Admins should check that their SSO users, verified domains and group-to-role mappings fit the feature’s boundaries before switching it on. The one-time display of the key secret also makes the setup instructions worth following carefully, rather than treating credentials as decorative paperwork.
What to watch
- Whether ClickHouse adds support for managing manually invited members or system roles.
- How organisations map identity-provider groups to custom roles in practice.
- Whether the audit log provides the detail administrators need to review provisioning changes.
Discussion spark: Should identity-provider group membership be the default source of truth for cloud database access, or do the limits around manual users and system roles make that too blunt?
Sources and evidence
- Source update (30 September 2026, 17:23 UTC)
not affiliated with or endorsed by ClickHouse