Skip to main content
Cimento’s employee list drives everything else: phishing audiences, training assignments and reporting. Import it from the directory your organization already uses. Cimento supports three: Okta and Microsoft Entra ID, which send employees to Cimento over SCIM, and Google Workspace, which Cimento reads with read-only access.

Choose your directory

Your organization connects one directory. Once it’s configured, the choice is locked; contact support to change it.

Before you start

  • Where to start. Go to Admin → Integrations → Employee data in Cimento and choose your provider under Directory provider. If you don’t see Employee data, ask your Cimento contact to enable it.
  • Your email domains. Cimento records your organization’s email domains when it creates your account. Single sign-on covers only those domains, and Google Workspace sync imports only people in them. Ask your Cimento contact to add any that are missing.
  • Manual employee management turns off. As soon as you click Begin Setup, employees come from your directory. You can no longer add or upload employees in Cimento, or edit their names, email addresses, status or departments. You can still change their roles.

What Okta and Microsoft Entra ID send

Employee attributes

Groups

Pushed groups become Cimento groups with the same members. A group can only include people your directory has already provisioned to Cimento. Group names must be unique in Cimento regardless of capitalization, so rename any existing Cimento group that has the same name as one you push.

When someone leaves

When you deactivate or unassign someone in Okta or Entra, Cimento deactivates them. They can no longer sign in, and they drop out of campaign audiences. If your directory deletes the account, Cimento also removes them from their groups. Cimento never deletes the employee record, so their history stays in your reports.
The API token (Okta) or secret token (Entra) lets your directory create, update and deactivate employees in Cimento. Store it like a password. To stop provisioning, turn it off in Okta or Entra.

What Cimento imports from Google Workspace

  • Users in your email domains: primary email, name, and the department and job title from their employee information. Suspended and archived users aren’t imported.
  • Groups in your email domains, with their names and descriptions.
  • Group members who are users in your directory. Members of nested groups and addresses outside your directory are skipped.
Cimento doesn’t import phone numbers, managers, aliases or locations from Google. Its scopes give it no access to mail, files or anything else outside the directory.

When someone leaves

At the next daily sync, anyone suspended, archived or deleted in Google, or moved out of your email domains, is deactivated in Cimento and signed out of Cimento. Cimento never deletes the employee record, so their history stays in your reports. Restoring the user in Google reactivates them at the following sync.

Keep accounts out of Cimento

If your organization has Admin → Integrations → Sync exclusions, use it to keep service accounts, shared mailboxes or whole Google groups out of Cimento. Excluded people and groups are hidden everywhere and aren’t imported again. Re-including one brings it back with an immediate re-import.