**Session Date/Time:** 24 Jul 2026 14:00 # [SCIM](../wg/scim.html) ## Summary The SCIM Working Group met at IETF 126 to discuss several active drafts, including the Protocol Interoperability Profile, the IPSIE Account Lifecycle Draft, the GroupMember Resource Extension, and the AI Agent Resource draft. The group also evaluated the future of the Use Cases draft and engaged in a strategic discussion regarding working group rechartering, focusing on whether to revise core specifications or pivot entirely toward extension mechanisms. --- ## Key Discussion Points ### 1. SCIM Protocol Interoperability Profile * **Presenter:** Danny Zollner * **Slides:** [SCIM Protocol Interoperability Profile](https://datatracker.ietf.org/meeting/126/materials/slides-126-scim-scim-protocol-interoperability-profile-01) * **Draft:** `draft-zollner-scim-interface-implementation-profile` Danny Zollner presented a protocol interoperability profile aimed at addressing common implementation and interoperability issues. Key elements of the profile include: * **Patch Restrictions:** Prohibits "pathless patch" operations to simplify parsing and logic expressions, reducing syntax variations. * **Normative Clarifications:** Consolidates and clarifies requirements from RFC 7643 and RFC 7644 regarding case sensitivity, uniqueness, and pagination. * **Discovery Requirements:** Enforces support for service provider configuration, schemas, and resource type endpoints. **Discussion:** * Pamela Dingle supported the profile, noting its opinionated stance is necessary for interoperability, and agreed that it is in scope. * Nancy Cam-Winget confirmed that the work falls within the current charter's scope under incorporating implementation experience and interoperability feedback. * Mike Kiser, Maxwell Gerber, and Pamela Dingle volunteered to review the draft and provide feedback on the mailing list before November. --- ### 2. SCIM IPSIE Account Lifecycle Draft * **Presenter:** Jenna * **Slides:** [SCIM IPSIE Account Lifecycle Draft](https://datatracker.ietf.org/meeting/126/materials/slides-126-scim-scim-ipsie-account-lifecycle-draft-00) * **Draft:** `draft-zollner-scim-ipsie-account-lifecycle` Jenna introduced the IPSIE (Interoperable Profile for Secure Identity in the Enterprise) SCIM 2.0 Profile. The profile sets conformance criteria across three assurance levels (AL1 for deprovisioning, AL2 for user/membership synchronization, and AL3 for roles/entitlements). **Discussion:** * **SDO Coordination:** Jeff Lombardo raised questions regarding the division of labor and synchronization between the IETF and the OpenID Foundation (OIDF). Danny Zollner clarified that while OIDF manages conformance testing, IPSIE’s working group prefers to submit foundational profiles to the native standards body (IETF for SCIM). * **Authentication Constraints:** Pamela Dingle raised concerns regarding the strict requirements for OAuth 2.0 client credentials and JWT client authentication, noting that these best practices are shifting rapidly and might conflict with other emerging token patterns (e.g., transaction tokens). Danny Zollner welcomed feedback to make these authentication requirements more abstract or adaptable. * **Charter Fit:** Nancy Cam-Winget and Aaron Parecki noted that while the Interoperability Profile is in scope, the compliance/conformance focus of the IPSIE draft is currently out of scope under the current SCIM charter. --- ### 3. SCIM Use Cases * **Presenter:** Paulo * **Slides:** [SCIM use cases for IETF 126](https://datatracker.ietf.org/meeting/126/materials/slides-126-scim-scim-use-cases-for-ietf-126-00) * **Draft:** `draft-ietf-scim-use-cases` Paulo presented updates on the Use Cases draft, specifically addressing terminology changes such as "resource object" vs. "resource attribute" vs. "schema resource object" based on historical feedback. **Discussion:** * **Utility of Use Case Documents:** Justin Richer suggested that use case documents should not be published in archival formats (like RFCs) but should instead be abandoned or left as unpublished references once they have served their purpose. He noted that terminology documents quickly become outdated. * **Apathy and Document Status:** Danny Zollner agreed with Justin Richer, stating that the draft was cognitively taxing and that the group should move on. Nancy Cam-Winget noted the general apathy toward continuing formal publication steps for this draft. #### Session Poll 1 * **Question:** Should we move on from the use cases draft with no plans to publish? * **Results:** Yes: 4, No: 4, No Opinion: 6 (Total: 29) --- ### 4. SCIM GroupMember Resource Extension * **Presenter:** Danny Zollner * **Slides:** [SCIM GroupMember Resource Extension](https://datatracker.ietf.org/meeting/126/materials/slides-126-scim-scim-groupmember-resource-extension-00) * **Draft:** `draft-zollner-scim-groupmember-resource-extension` Danny Zollner presented a proposed solution to the "large group" scaling problem. Because SCIM represents group members as an array within the Group resource, fetching or updating groups with millions of members results in massive payloads and performance issues. This draft elevates group membership to a first-class resource (`/GroupMembers`), enabling pagination, filtering, and atomic bulk operations. #### Session Poll 2 * **Question:** Who has read the GroupMember draft? * **Results:** Yes: 2, No: 13, No Opinion: 2 (Total: 30) **Discussion:** * Jeff Lombardo, Pamela Dingle, and Hans York volunteered to review the draft. --- ### 5. SCIM AI Agent Resource * **Presenter:** Danny Zollner * **Slides:** [SCIM AI Agent Resource](https://datatracker.ietf.org/meeting/126/materials/slides-126-scim-scim-ai-agent-resource-01) * **Draft:** `draft-peterson-scim-ai-agent-resource` (Converged draft) Danny Zollner presented the converged draft representing AI agents as a first-class SCIM resource. The draft establishes a minimalist core schema for agent identities, focusing on accountability (owner attribution) rather than runtime authorization or authentication. **Discussion:** * **Template vs. Instance:** Danny Zollner explained that the draft targets "templates/blueprints" rather than "ephemeral runtime instances" because the high speed of instance creation makes SCIM an impractical management mechanism compared to authorization frameworks (like signed JWTs). * **Terminology Concerns:** * Flemming Andreasen argued that both templates and instances may need to be supported depending on deployment patterns. * Justin Richer recommended avoiding the word "agent" entirely, as it has become semantically overloaded and meaningless in the industry. He warned against mixing human and non-human identities within SCIM. * Maxwell Gerber and Pieter Kasselman suggested generalizing the draft to "software", "workloads", or "applications" rather than focusing on "AI agents." Pieter Kasselman suggested a "fake user" flag might be sufficient for simpler systems. * AD Chris de Looze suggested "autonomous entity" or "autonomous" as an alternative label that captures the behavior. * Emily Lauber supported solving the core problem, noting that regardless of the exact label, representing these entities alongside users in identity management systems is highly valuable. --- ### 6. WG Rechartering Discussion * **Chairs:** Nancy Cam-Winget, Aaron Parecki * **Slides:** [Chair slides](https://datatracker.ietf.org/meeting/126/materials/slides-126-scim-chair-slides-00) Nancy Cam-Winget initiated a discussion on rechartering the SCIM working group. The core of the current charter—specifically revising the core RFC 7643 and RFC 7644 specifications—has suffered from low participant energy and apathy. **Discussion:** * **Core Updates vs. Extensions:** Danny Zollner noted that while updating the core specifications is a desirable long-term goal, it is highly impractical given the small pool of active contributors. Resolving issues through modular extensions has proven much more viable. * **Forcing Functions:** Pamela Dingle stated that vendors will not implement a "SCIM 3.0" just for the sake of an upgrade; there must be a substantial commercial forcing function or industry goal. * **Real-time & Governance Shifts:** Mike Kiser suggested that SCIM's future lies in real-time synchronization and providing placeholders for governance and workload templates. * **WIMSE Alignment:** Pamela Dingle and Mike Kiser highlighted the need to align SCIM's workload/agent concepts with ongoing work in the WIMSE working group. * **AD Perspective:** AD Chris de Looze observed that while there is interesting work on the horizon (such as autonomous workloads/agents), the group currently struggles to get sufficient document reviews on the mailing list. He noted that the IESG would support a charter focused on extensions and autonomous workloads, but the WG must demonstrate the necessary energy and commit to reviewing drafts. * **Deployment Patterns:** George suggested that compiling common SCIM deployment patterns would help ground future protocol decisions. --- ## Decisions and Action Items * **SCIM Use Cases (`draft-ietf-scim-use-cases`):** The working group will park this document with no plans to publish it as an RFC. It will remain an unpublished reference. * **SCIM Rules Draft:** Danny Zollner to resubmit the expired adopted rules draft to keep it active. * **Rechartering:** The chairs and participants will draft new charter text on the mailing list focusing on SCIM extension mechanisms (such as workloads, interoperability profiles, and real-time extensions) rather than a complete rewrite of the core RFCs. --- ## Next Steps * **Reviews Needed:** * **SCIM Protocol Interoperability Profile:** Mike Kiser, Maxwell Gerber, and Pamela Dingle to post reviews to the mailing list before November. * **SCIM GroupMember Resource Extension:** Jeff Lombardo, Pamela Dingle, and Hans York to post reviews to the mailing list. * **SCIM AI Agent Resource:** Working group members are encouraged to read the draft and discuss alternative naming options (e.g., "workload", "autonomous entity") and alignment with WIMSE on the list.