Guides

Digital business cards for 500–1,000 employees: how an enterprise runs them with SSO, SCIM and a central brand

Updated on September 23, 2026

In short

For a company with 500–1,000 employees, digital business cards work when the directory is the single source: Microsoft Entra ID or Google Workspace holds the record, bizCARD turns it into a card, a signature and a print PDF in the organisation's template. SSO removes passwords, SCIM creates and deactivates cards, a locked theme keeps the brand consistent.

What breaks at 500 people?

Picture a Swiss company with 800 employees on four sites. Marketing owns the brand, IT owns identities, HR owns joiners and leavers. Business cards sit between the three, and nobody owns them. Marketing keeps an Excel file of contacts and gets a ticket for every new card. The email signature exists in three versions. Every role change means a reprint. When someone leaves, the paper goes in the bin, but the old signature and a card once created in a free app stay online. Ask which cards are live today and nobody can answer. The same contact record lives in five places and none is authoritative: at 50 people an office manager holds it together, at 500 the effort grows faster than the headcount.

What does the target picture look like?

One rule: the directory is the single source. Microsoft Entra ID or Google Workspace already holds name, role, department, phone, email and often the photo of every employee. bizCARD turns each record into a digital card, an email signature, a print-ready paper card and, if wanted, an NFC card, all in the organisation's template. Joiners get a card automatically, role changes propagate, leavers are deactivated the same day.

ProcessTodayWith directory and bizCARD
New employeeTicket to Marketing, Excel row, print orderCard created from the directory record
Role or number changesReprint, new signature, three people to informOne change in the directory, every card follows
LeaverCards stay online somewhereCard deactivated with the account
Brand updateNew template by email, applied by someTheme applied to all cards in one click
Who is live?Nobody knowsTeam view with every card

SSO or SCIM, and in which order?

SSO and SCIM are two different things, adopted in two steps. SSO means people sign in with company credentials through OpenID Connect or SAML 2.0, with no extra password; any OIDC or SAML provider works. It removes the password tickets, but it does not create cards. SCIM 2.0 is provisioning: members and cards are created, updated and deactivated from directory attributes, with the profile photo where the directory has one. bizCARD's SCIM is designed for Microsoft Entra ID and any provider with a standard SCIM client. Google Workspace does not expose SCIM to third-party apps, so with Google you combine SSO with invitations or import.

The attribute mapping is defined with your IT. Provisioned people get the editor role by default, and the SCIM token is dedicated to your organisation, rotatable and revocable. The order that works: SSO first, then SCIM on a test tenant with a small pilot group and the template already loaded, then rollout.

How is the brand set once for everyone?

Marketing defines the presentation once. A theme holds the colours for background, text, accents and links and the styling of header, content, footer and buttons; the card uses the Classic or Modern template with your logo. Saved themes are reusable, and one click applies one to every card in the team. In the Enterprise plan the presentation can be locked: people correct their number but cannot pick their own colours. Cards live on your domain, for example cards.yourcompany.com, and the bizCARD watermark can be hidden.

Dynamic contacts: what changes where?

Every person has one contact record. Change the role, the number or the logo once and the card updates everywhere it was ever shared: in the emailed link, in the QR scanned last year, in the signature. The QR on printed cards points to the card URL, which never changes, so paper printed before a promotion stays valid afterwards.

How do print and NFC work at scale?

Paper does not disappear at a trade fair, so bizCARD generates it from the same record. Marketing uploads the design for front and back, places placeholders for name, role, phone, email and other fields, and chooses a font per placeholder. bizCARD generates a variant for every member and provides print-ready PDFs, singly or as a batch, in nine formats from the NFC card to the folded card; the PDF regenerates when contact data change. NFC cards are printed with the company template in one order for the whole team, with proofs before payment, order tracking and CHF prices that decrease with quantity.

Email signatures for everyone, honestly

bizCARD generates an email signature from the card data for every member, in one consistent style, and keeps it current in the app. Each person copies it, formatted or as HTML, into Gmail, Outlook, Apple Mail or Thunderbird, with step-by-step instructions per client. What bizCARD does not do is inject the signature server-side into every mailbox: if you need central deployment into hundreds of mailboxes, that is a different class of tool. What you get here is one source for the signature, so three versions become one.

Joiners, movers, leavers

Joiners appear in the directory and, with SCIM, get a card with the template, the mapped fields and the editor role. Movers change title or department in the directory, and card, signature and print PDF follow. Leavers are marked inactive; bizCARD deactivates the card, revokes sessions and removes access the same day, without deleting data. Roles keep responsibilities clear: the owner has everything including billing, admins manage the team, all cards and the aggregate analytics, editors handle only their own card. One subscription covers the team, billed centrally.

Rollout in three phases

  • Connect the identity provider: register bizCARD in Entra ID or Google Workspace, enable SSO, sign in with a test account on a test tenant.
  • Map attributes and pilot: agree the mapping with IT, load template and theme, provision a small group from several sites, check cards, signatures and print PDFs.
  • Rollout: assign the remaining directory groups, switch on the custom domain, hide the watermark, order NFC cards for the people who meet customers.

RFP checklist

These questions separate an enterprise setup from a collection of individual accounts. Ask for the answers in writing.

  • SSO via OpenID Connect or SAML 2.0; SCIM 2.0 provisioning with an attribute mapping we define.
  • Deactivation of card, sessions and access when the directory disables the account; data kept until we decide.
  • Roles that separate billing, team administration and individual editing.
  • Templates and themes with a lock on the presentation, custom domain, watermark removal.
  • Print-ready PDFs for every member in batch; NFC cards ordered centrally.
  • Signatures generated from card data, and a plain statement of whether deployment is central or per person.
  • Aggregated team analytics; individual statistics visible only to the person concerned.
  • Data location, applicable law and a data processing agreement on request. bizCARD: dambox Sagl, Swiss law, jurisdiction Lugano, Vercel and Neon in European data centres, Stripe for payments; revFADP and GDPR where applicable. A dedicated guide on data protection covers the details.
  • Sustainability: fewer printed cards and no reprints, with measurable numbers (active cards, views, saved contacts) to estimate paper saved. bizCARD is not an ESG reporting tool.

Frequently asked questions

We use Google Workspace, not Microsoft. Does this still work?

Google Workspace does not expose SCIM to third-party apps. With Google you use SSO for sign-in and create members by invitation or import; changes and leavers are handled by your admins in the team view.

What does IT actually have to do?

Register bizCARD in the identity provider (OpenID Connect or SAML 2.0), agree the attribute mapping, generate the SCIM token and assign the pilot group. The token is dedicated to your organisation, rotatable and revocable.

Can individual employees still change their card?

Provisioned people get the editor role: they see and edit only their own card. If the template is locked, they correct their data but not the presentation. Directory fields are overwritten at the next sync.

What happens to the data of people who leave?

The card is deactivated and no longer reachable, sessions are revoked, access is removed. Nothing is deleted automatically: final deletion is a separate decision your company takes.

Who sees the analytics?

Owners and admins see the aggregated team dashboard and every card's statistics. Editors see only their own. Nobody sees who scanned.

How long does a rollout take?

Start with a pilot on a small group, on a test tenant with the template already loaded. After that, rollout means assigning groups in the directory; the timing depends on your IT's calendar.