Fullstory
Fullstory is in beta in Ploy. Ploy connects to Fullstory's SCIM provisioning endpoint to scan your teammates, their roles and, optionally, your groups. The integration is built from Fullstory's published provisioning behaviour and has not yet been run against a live Fullstory account, so we ask for your consent before connecting (step 1 below).
What Ploy reads
Every teammate on the Fullstory account, with their email address and whether they are enabled or disabled.
Each teammate's Fullstory role: Admin, Architect, Standard, Explorer or Guest.
Who currently has access to Fullstory. Disabled teammates are shown as blocked and lose their access in Ploy.
Optionally, your Fullstory groups and who belongs to each. Groups decide who can view or edit Spaces, but which Spaces a group can reach is set inside Fullstory and is not read.
What Ploy can change
Add a teammate, optionally with a role.
Disable a teammate and enable them again. A disabled teammate cannot sign in and stops using a seat, and the dashboards, segments and metrics they created stay in place.
Change a teammate's role between Admin, Architect, Standard, Explorer and Guest. Umbrella Manager can only be given inside Fullstory.
Fullstory never deletes a teammate through provisioning, so disabling them is how Ploy removes access. Ploy does not change group membership.
If your identity provider (for example Okta) also provisions Fullstory, it may undo a change Ploy makes the next time it pushes that person. Make lasting changes in one place.
Before you start
Your Fullstory account must be on the Enterprise plan.
You must be a Fullstory Admin.
SAML single sign-on must already be set up in Fullstory. The SCIM option only appears once it is.
To scan groups, Fine-Grained Access Controls must be turned on for the account.
Step 1: Agree to the beta terms
The first page of the Fullstory setup in Ploy has a required consent checkbox. Because the integration is in beta, ticking it lets Ploy record redacted error data when a Fullstory request fails: the error status and message with any personal data, tokens and secrets removed. We use it only to fix the integration quickly. You cannot continue without ticking it.
Step 2: Find the SCIM details in Fullstory
In Fullstory, go to Settings, then Account Management, then SSO.
Under Account Provisioning, choose SCIM Provisioning.
Copy the SCIM connector base URL. It looks like
https://app.fullstory.com/scim/v2.Click Generate Authorization Token and copy the token. Fullstory shows it only once, so keep it somewhere safe until you have pasted it into Ploy.
If your identity provider already uses a SCIM token for Fullstory, check with your Fullstory admin before generating a new one, in case it replaces the token your identity provider relies on.
If your company uses a Fullstory Umbrella with several organisations, each organisation has its own base URL and token. Add one Ploy connection per organisation.
Step 3: Enter the details in Ploy
In Ploy, open Integrations, find Fullstory and start the setup.
Tick the beta consent checkbox.
Paste the SCIM connector base URL and the Authorization Token.
Choose whether to scan Fullstory groups. Choose Yes only if Fine-Grained Access Controls are turned on.
Continue. Ploy tests the connection by reading one teammate.
If the test fails:
"Fullstory rejected that Authorization Token": generate a new token in Fullstory and paste it again.
"Fullstory could not find SCIM at that base URL": copy the SCIM connector base URL again from the SSO settings screen.
"Enter the SCIM connector base URL exactly as Fullstory shows it": Ploy only accepts an https address on fullstory.com.
"That token cannot read users": check SCIM Provisioning is still turned on in Fullstory.
What to expect
The first scan runs shortly after setup and then every hour. Teammates appear in Ploy with their Fullstory role, and disabled teammates are shown as blocked. If you turned on group scanning, your groups appear as resources with their members.
Not included yet: last sign-in times, second-factor status, Space permissions, and changing group membership from Ploy.