What Oleria discovers
User accounts and profile attributes synced from Spotfire’s directory. Oleria uses this data for dormant account detection and access reviews, refreshed on Spotfire’s standard sync schedule.Prerequisites
- Admin access in Spotfire with permission to create a service account and generate API credentials.
- Admin access on the Oleria platform to add a new integration.
The exact location of these settings can change over time. If the steps below don’t match what you see, refer to Spotfire’s own API documentation.
Get your SCIM credentials from Spotfire
1
Create a service account in Spotfire
Sign in to Spotfire as an admin, go to Administration, and create a service account with read permissions.
2
Copy your SCIM Base URL and Authentication token
Generate API credentials for the service account, then copy both values before you leave the page - you’ll paste them into Oleria in the next section:
- SCIM Base URL - the HTTPS API endpoint for your Spotfire deployment.
- Authentication token - the credentials issued for the service account.
Copy the credentials now. Many applications display them only once. Store them securely and rotate per your organization’s security policy.
Connect Spotfire to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations, then select the Spotfire tile.
2
Complete the connection form
Select Continue and fill in the connection form:
3
Save the integration
Select Connect to validate the credentials and save the integration.
Verify the integration
Confirm the new instance appears in your Oleria workspace under Connected Integrations with a status of Healthy. Oleria syncs users from Spotfire on the standard SCIM provisioning schedule once the initial sync completes.If Spotfire rotates your service account credentials, update the Authentication token in Oleria by editing the integration.
Governance actions
Oleria can also invoke lifecycle actions in Spotfire when the credentials you provide have write access:- Enable or disable a user account
- Create a new user
Many teams start with a read-only service account for visibility, then grant write access once they’re ready to automate remediation in Spotfire.

