Provisioning and invites
Provisioning is who is allowed to create a user, change a role, or accept an invite. Test SCIM, directory sync, and invite acceptance with two orgs you belong to. An invite token in a URL is a lead, not a takeover.
Skill: Provisioning and invites
Ask: Can a token I hold create a user or change a role in an org I belong to, when that route should refuse me?
Stop: Two orgs you belong to are named, and one write is either refused or stored. No user was created in a third org.
Checklists
None linked for this class yet.
Disclosures
No public card yet.
Playbooks
- SCIM, directory sync, and invites - Provisioning bugs are authorization bugs on user creation. Compare two orgs you belong to. Do not create users in a tenant that is not yours.
Tools
- Burp Suite - The industry-standard intercepting proxy for manual web testing. Community edition is free; Pro adds the active scanner and automation.
Questions
SCIM is an admin API. Do I need an admin account?
Use the role the program gave you. The question is whether a member token can call a route that should be admin, or whether an invite for org A is accepted inside org B. Both orgs have to be yours.
The invite link has a token. Which hunt is that?
Start here for who can issue it and which org it joins. If the question is reuse or a second browser, open the reset brief as well and say which behavior you showed.
This page is the linked pack hunt_brief("provision") returns on the MCP connector. Authorized testing only.