Get started
Quick start
Configure Camper so people flow in from your identity provider, a target app is connected, and at least one resource is linked — then run the first reconcile.
Prerequisites
- A Camper workspace (create one if you do not have one yet)
- Access as owner or admin
- An identity provider that can push SCIM (Okta, Entra ID, or a SCIM bridge)
- Admin access to at least one target app (Google Workspace, Slack, Atlassian, GitHub, or Microsoft 365)
Summary of steps
- Connect your identity provider — SSO (optional at first) and SCIM so people appear in Camper
- Shape the org — confirm axes and import the units you want to manage
- Connect a target app — one connection is enough for a first pass
- Link a resource and dry-run — attach or create a group/channel/team, review the plan
- Run first reconcile — worker applies approved membership ops
Nothing is written to a connected app until you approve a dry run. Steps 1–3 are safe before you decide what to manage.
1. Connect your identity provider
- Sign in at app.getcamper.io.
- Open Settings → Identity Providers.
- Generate a SCIM bearer token and copy the Base URL.
- In your IdP, create a SCIM client pointed at that URL with Bearer auth, assign users (and optionally groups), and enable create / update / deactivate.
Vendor walkthroughs:
- Okta
- Entra ID
- Google Workspace as source (via IdP or SCIM bridge)
Optional but recommended: register SSO on the same page so operators and workers sign in through your IdP. See Enterprise SSO.
Check: People lists assigned users. Settings → Identity Providers shows a recent push.
2. Shape the org
New workspaces get two default axes:
- Department — from the
departmentprofile attribute (nested when values contain>) - Teams — from SCIM Group push (multi-membership)
- Open Catalog in the sidebar.
- Review Suggested units from the first SCIM push.
- Import the units you want to manage (only imported units can hold resource links).
- Optionally create more axes under New axis or Settings → Mappings.
Details: Org axes & units, Org catalog.
3. Connect a target app
- Open Connections.
- Choose a provider → Set up.
- Complete the guided dialog (Check access → Grant access → Done).
| Provider | Typical installer |
|---|---|
| Google Workspace | Workspace admin |
| Slack | Workspace or Grid admin |
| Atlassian | Org admin + classic API token |
| GitHub | Org owner/admin for App install |
| Microsoft 365 (beta) | Entra Global / Privileged Role Admin |
4. Link a resource and dry-run
- Open Resources → Link resources (or Link resources on an imported catalog unit).
- Choose Create new or Link existing, then the app and what to link.
- Set Access rules (who gets in, movers, leavers, outsiders).
- On Review, read the membership plan. Confirm only when the blast radius looks right.
Full guide: Link resources.
5. Run first reconcile
On Overview, the Next Steps card for first reconcile unlocks once an IdP and a target are connected. Enqueue the tenant-wide reconcile so the worker evaluates linked resources.
Watch Activity for failed tasks and drift: Activity & drift.
Next Steps cards
New tenants see a Next Steps block on Overview until the basics are in place. Each card deep-links to the surface where the work happens. Cards disappear as steps complete; the block can be dismissed.
Elevate other operators
Map SCIM roles = Admin for people who should run Camper. Everyone else stays on My Access. See Roles.