Admin and bulk provisioning
Company Admin entry is supported. Bulk CSV employee upload is available on entitled plans.
Integration documentation
A public architecture overview—not a claim that every internal endpoint is a supported public developer API.
CardIQ has a SAML metadata configuration foundation, while automatic redirect, enforced login and native SCIM are not currently active.
Availability depends on plan, API scope and configuration.
Company Admin entry is supported. Bulk CSV employee upload is available on entitled plans.
Company-scoped API-key workflows and selected employee/company integration surfaces exist. Exact scopes and production access must be confirmed during integration setup; this is an overview, not a complete API reference.
Signed outbound lead_created webhook delivery to an HTTPS receiver is supported where configured. CRM-oriented integrations exist; lifecycle-event webhook coverage is not claimed.
Use authorized admins, least-privilege scopes, protected and revocable API keys, HTTPS receivers, signature validation, tenant boundaries and audit review. No public rate limit is promised here.
Availability below distinguishes read-only identity preview from provisioning connectors.
Phase 2B adds controlled synchronization: administrators can use mapped-user OIDC login and selected-group preview, then explicitly approve employee linking, non-login provisioning, selected profile-field updates, or non-destructive deactivation. Nothing applies automatically. Scheduled sync, group-to-role automation, unrestricted JIT provisioning, native SCIM and direct LDAP/LDAPS are not supported.
No native Okta connector is represented as available.
CardIQ does not currently provide native SCIM provisioning or deprovisioning.
Enterprise SSO foundations exist, but provider/protocol support and entitlement must be confirmed for the deployment; this is not SCIM.
No native directory-provisioning connector is documented. Generic import or an approved custom API workflow may be evaluated.
No native Workday connector is documented. Generic import or an approved custom API workflow may be evaluated.
Use only the path confirmed for the deployment.
Admins create/update/deactivate employees; entitled teams can bulk import. Supported API workflows may automate selected fields or statuses.
HR / Directory / Admin Source → approved API or import layer → CardIQ company identity → employee identity → supported public surfaces.
Employee disabled/deactivated → CardIQ identity inactive → public verification no longer presents active company identity.
Do not design around SCIM, Entra, Okta, Google Workspace or Workday automation until CardIQ explicitly confirms a supported connector or custom scope.
Explore the CardIQ platform or review the workflow from verification through identity deactivation.
See how CardIQ works View pricing