Skip to main content

Setting up Insights & Stats for organizational time analysis

How to provision your organization so that Team Insights and Stats covers everyone & allows filtering and insights on how time is spent cross your team, department, location or org.

This guide describes the configuration required for organizations to obtain complete, filterable analytics in Reclaim. It is intended for the IT administrator and the Reclaim owner responsible for the rollout, and should be completed in coordination with your Reclaim contact.

Overview

Two separate configuration components feed analytics, and both are required for total analytics coverage:

  1. SCIM provisions users in Reclaim and maintains their organizational attributes — department, manager, location, cost center, and similar fields. These attributes become the filters available in Team Stats & Insights.

  2. A service account (Google domain-wide delegation, or Microsoft tenant-wide admin consent) grants Reclaim access to calendar data across the organization. This is the data that analytics measures.

If SCIM is granted but service-account access is declined, users are still created with their organizational attributes intact, but without a connected calendar. Each user must connect a calendar manually at first sign-in, and contributes no data until they do. Analytics will therefore reflect only the subset of users who have signed into Reclaim.ai and connected a calendar.

For accurate and comparative analytics a service account is highly recommended. Without a service account, analytics coverage will only cover Reclaim users but not provide insights into the broader organization for comparative analysis.

Prerequisites

  • An Enterprise plan with SSO enabled on your Reclaim team.

  • SSO configured with your identity provider (SAML or OIDC — for example, Okta or Microsoft Entra).

  • A SCIM provisioning connector in your IdP, using an API token provided by your Reclaim contact.

  • A complete list of your email domains, including any secondary or contractor domains such as ext.yourcompany.com. Each domain must be registered separately; an incomplete domain list is a common cause of rollout delays.

  • Google Workspace super-admin access (for domain-wide delegation) or Microsoft tenant admin access (to complete the admin-consent flow).

  • A small set of test users for initial validation.

Step 1 — SSO, SCIM, and domain capture

Your Reclaim contact configures the SSO connection, the SCIM endpoint, and your API token, and registers each of your domains.

Domain capture should be confirmed explicitly. When enabled, any user who signs up with an email address on one of your verified domains is automatically added to your enterprise team rather than creating a separate individual account. Without it, users who registered independently may remain outside your team, and outside your analytics.

Provide your Reclaim contact with all domains in advance, including subdomains used for contractors or acquired entities.

Step 2 — Grant organization-wide calendar access

Google Workspace: grant the Reclaim service account domain-wide delegation with the calendar scopes listed in Using Google Workspace service accounts to roll out Reclaim to your enterprise. Once configured, Reclaim attaches each user's primary calendar automatically during provisioning, with no action required from the user.

Microsoft: complete the tenant-wide admin-consent flow with your Reclaim contact, this guide can be used for reference Enabling Service Principal and SCIM at Microsoft Entra ID to use Reclaim.ai. Calendars are then attached through Microsoft Graph in the same manner.

If the required scopes are missing or incomplete, provisioning will still succeed: users are created with their SCIM attributes intact, but without an attached calendar. Reclaim cannot distinguish between access that has not yet been granted and access that has been declined. Confirm with your Reclaim contact that calendars are being attached for your test users before provisioning the full organization.

Step 3 — Map your SCIM attributes

The attributes sent over SCIM become the dimensions available for filtering and grouping in Team Stats. Attributes that are not sent will not appear as filters.

Reclaim reads:

  • Standard fields — username, name, display name, title, user type, email, and active status.

  • The SCIM enterprise extension — employee number, cost center, organization, division, department, and manager. Manager is required for Reclaim to construct a reporting hierarchy, so map it if you intend to roll analytics up by organization.

  • Reclaim's extension — location, hire date, job category, org role, and work group.

  • Custom attributes — any additional field you wish to filter on. Each becomes a filter automatically.

Field-by-field mapping instructions are available in the Okta SCIM initial setup guide.

Validate with test users first

No dry-run mode is available, so validation with real users is the only way to confirm that your mapping is correct. This step is strongly recommended: IdP mappings that appear correct frequently omit manager or department entirely.

  1. Push a small group of test users from your IdP.

  2. Ask your Reclaim contact to confirm which fields were received. This identifies both missing fields and values that do not match the expected format, such as a date sent as free text.

  3. Confirm that the attributes appear as filters in Team Stats.

  4. Provision the remainder of your organization only after validation is complete.

Verify your setup

  • Users: your test users exist in Reclaim, and their department, manager, and other mapped attributes are present and correct.

  • Calendars: provisioned users have a primary calendar attached without having signed in. If they do not, service-account access is not functioning and should be resolved before the full push.

  • Analytics: Team Stats loads for your administrators, and the available filters match the SCIM attributes you mapped.

  • Domains: every email domain is registered, including contractor and secondary domains.

  • Licensing: provisioned users who have not signed in are not counting against your seat total.

Additional Information

Provisioned users do not consume licenses until first sign-in

You can provision your entire organization in advance of a phased rollout without incurring charges for all users on day one.

A seat is consumed when a user signs in & begins using Reclaim. Users who have been provisioned but have never signed in are authorized but not billed.

This allows you to provision all users over SCIM up front for analytics usage, but still control your license amount.

Large rollouts are provisioned gradually by design

Reclaim paces user creation for large imports rather than creating all users simultaneously. Users who have been provisioned but have not yet signed in are refreshed on a 24-hour cycle rather than monitored in real time. Their data continues to flow into analytics on this slower cadence until first sign-in, after which they move to standard real-time processing.

There are two practical implications:

  • Provisioning a large organization is not instantaneous. Users appear progressively over a period rather than all at once. This is expected behavior, not a failure.

Related articles

If you are planning an enterprise rollout and are unsure which of these steps apply to your organization, consult your Reclaim contact before you begin.

Did this answer your question?