TL;DR: B2B onboarding remains a governance problem, not just a UX problem, because tenant creation, SSO setup, SCIM provisioning, OAuth consent, and admin delegation all carry identity and access decisions, according to Descope. The operational risk is that customer self-service can scale faster than the controls that preserve tenant isolation, consent, and auditability.
NHIMG editorial — based on content published by Descope: Making B2B Customer Onboarding Easy With Descope Auth Thoughts
Questions worth separating out
Q: How should security teams govern self-service B2B onboarding?
A: Treat self-service onboarding as delegated identity administration, not a convenience feature.
Q: Why do tenant-level SSO and SCIM controls need privileged access oversight?
A: Because they change authentication and provisioning behaviour for an entire customer environment, not just one user.
Q: What breaks when OAuth consent is not centrally governed?
A: When consent is not centrally governed, employees can grant third-party apps persistent access to enterprise data without security review.
Practitioner guidance
- Separate tenant creation from tenant authority Require distinct approval paths for creating a tenant, assigning tenant admin rights, and enabling integrations.
- Treat SSO and SCIM as privileged configuration changes Log and review every setup action that binds a tenant to an external identity provider or provisioning source.
- Attach explicit owners to outbound OAuth scopes Record which business team owns each tenant-level integration, which scopes were granted, and how revocation will be handled when the relationship changes or the tenant is decommissioned.
What's in the full article
Descope's full post covers the operational detail this post intentionally leaves for the source:
- Step-by-step tenant creation and style configuration inside the Descope console and SDK
- The setup-suite flow used to guide customer admins through SSO and SCIM configuration
- Examples of outbound app consent and token handling for tenant-level integrations
- How additional tenant admins are invited and assigned roles during onboarding
👉 Read Descope's guide to self-service B2B onboarding with multi-tenancy and Flows →
B2B onboarding flows: what IAM teams need to govern now?
Explore further
Tenant onboarding is an identity lifecycle process, not a product workflow. The moment a customer admin can create users, configure federation, and attach integrations, the platform is exercising governed identity change at tenant scope. That means onboarding belongs in lifecycle thinking alongside joiner-mover-leaver controls, access reviews, and privileged administration. The practical conclusion is that onboarding success should be measured by control integrity, not just completion speed.
A few things that frame the scale:
- 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What is the difference between tenant self-service and tenant self-governance?
A: Self-service means customers can complete setup without a support ticket. Self-governance means the platform also enforces policy, evidence, role separation, and lifecycle control around those actions. A secure onboarding model needs both, or automation simply shifts risk from operations to identity control.
👉 Read our full editorial: B2B customer onboarding still depends on tenant-level identity governance