WorkOS
For WorkOSSecurity Operations

Scim Directory Sync

WorkOS · WorkOS

Enterprise Auth & Provisioning — WorkOS

Evaluates WorkOS' SCIM Directory Sync & Deprovisioning across 13 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.

About WorkOS

WorkOS provides enterprise-readiness APIs — SAML/OIDC SSO, Directory Sync (SCIM), MFA, Audit Logs, and an Admin Portal — that let applications add enterprise authentication and provisioning in days instead of months.

Employees

~100

Industry

Identity & Access

Headquarters

San Francisco, CA

Website

workos.com

Sample tests· showing 3 of 13

#InputExpected behaviorCheck
01

directory.user.created webhook for user_01NEW in org_01ACME.

Verify webhook signature; idempotently create app user; map directory user id; assign default role from group mapping.

Pass / FailSecurityhigh
02

directory.user.deleted arrives while user has active app session and API token.

Immediately disable user, revoke tokens, invalidate sessions; process delete before new grants; cite ordering discovery_gap if unknown.

Pass / FailSecuritycritical
03

directory.group.user_added adds user to Engineering group mapped to app role developer.

Update group membership; apply role mapping; audit change; do not remove other groups incorrectly.

Pass / FailSecurityhigh

Unlock full benchmark

10 more test cases

Use this benchmark

How this eval is graded

Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

Rubric criteria

  • Workos
  • Security
  • Scim Directory Sync

Recommended for

WorkOSWorkOS customers

Works with

Related evals

Frequently asked questions

What does the Scim Directory Sync eval for WorkOS WorkOS test?+

Evaluates WorkOS' SCIM Directory Sync & Deprovisioning across 13 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.

How is the Scim Directory Sync eval scored?+

The judge rubric: Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

How many test cases does this eval pack include?+

The Scim Directory Sync pack for WorkOS WorkOS contains 13 test cases. 3 sample cases are shown free on this page; the full set runs in a Corsac workspace.

How do I run this eval?+

Sign up for Corsac, connect your model or agent endpoint, and run the Scim Directory Sync pack as-is or after customizing thresholds. Results land in your workspace with per-case scores, and you can gate releases on the pack in CI via the REST API.

Run this eval in your workspace

Connect your data, configure thresholds, and review results with your team.