> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tekma.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Admit members with Directory Sync

> Connect an Enterprise directory for controlled workspace admission and deprovisioning when the deployment enables it.

Directory Sync is a separate Enterprise feature from SAML. It requires deployment support and an owner. It synchronizes verified people and group membership; it does not create arbitrary accounts or bypass workspace admission.

## Connect a directory

1. Open **Settings → Access → Directory Sync** and enter the company email domain.
2. Choose **Create directory connection**. Tekma shows the SCIM base URL, a one-time token and a DNS proof.
3. Configure the token and base URL in your identity provider, then publish the `_tekma-directory` proof.
4. Choose **Verify directory DNS**. The proof expires after seven days and must be manually reverified when requested. When verification or Enterprise expires, new access pauses while removals continue.
5. Choose **All active directory users** or select groups, then choose **Save directory selection**. With group selection, membership is the union of selected active groups; an empty selection grants none.

New or unverified people remain pending until they complete the approved Tekma invitation/admission and email verification flow. Directory-created members use creator seats. Manual roles and memberships are retained; directory deprovisioning removes only grants it owns and cannot remove the last workspace owner. Provisioning requests retry automatically; owners can use **Retry** or **Cancel** on an individual pending request. Use **Issue replacement token** to rotate a SCIM token, then **Revoke token** on an old active credential.

Nested groups and provider-specific compatibility are not guaranteed. If synchronization stops, check domain proof, token status, selected groups and the provider's SCIM logs before rotating credentials again.
