What Oleria discovers
- User accounts and profile attributes synced from Keeper Security’s directory.
- Groups and their memberships.
- Roles assigned to each user.
Prerequisites
- Admin access in the Keeper Security Admin Console with permission to enable SCIM provisioning.
- Admin access on the Oleria platform to add a new integration.
The exact location of these settings can change over time. If the steps below don’t match what you see, refer to Keeper Security’s own SCIM provisioning documentation.
Get your SCIM credentials from Keeper Security
1
Enable SCIM provisioning in Keeper Security
Sign in to the Keeper Security Admin Console as an admin, go to Provisioning, and enable SCIM.
2
Copy your SCIM Base URL and Authentication token
Keeper Security generates a SCIM endpoint and token when you enable provisioning. Copy both values before you leave the page - you’ll paste them into Oleria in the next section:
- SCIM Base URL - the HTTPS SCIM endpoint for your Keeper Security account.
- Authentication token - the SCIM token Keeper Security generates.
Keeper Security displays the token only once. Copy and store it securely, and rotate it per your organization’s security policy.
Connect Keeper Security to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations, then select the Keeper Security tile.
2
Complete the connection form
Select Continue and fill in the connection form:
3
Save the integration
Select Connect to validate the credentials and save the integration.
Verify the integration
Confirm the new instance appears in your Oleria workspace under Connected Integrations with a status of Healthy. Oleria syncs users, groups, and roles from Keeper Security on the standard SCIM provisioning schedule once the initial sync completes.If Keeper Security rotates your SCIM token, update the Authentication token in Oleria by editing the integration.
Governance actions
Oleria can also invoke lifecycle actions in Keeper Security when the token you provide has write access:- Enable or disable a user account
- Add or remove a user from a group
- Create a new user or group
Many teams start with a read-only token for visibility, then grant write access once they’re ready to automate remediation in Keeper Security.

