Manage global org-role assignments
Only relevant when global SSO is enabled and the install wants IdP groups to drive org membership + roles across multiple orgs. Configured at
Admin → Settings → Global SSO → Organization role assignments.
This is the Phase 3 SSO feature: the global IdP becomes the
identity AND the membership authority. An IdP group like
acme-engineers can grant "editor in Acme" automatically, with
no manual invite step.
If you don't need cross-org IdP-driven membership, leave the grid empty and use per-org SSO instead.
How the grid maps
Each row is a tuple: (IdP group, org, role).
group org role
───────────────── ───────── ──────
acme-admins Acme admin
acme-engineers Acme editor
acme-readonly Acme viewer
bortech-admins BorTech admin
bortech-viewers BorTech viewer
One IdP group can produce multiple rows — engineering can grant
editor in Acme AND editor in BorTech in the same map. One org
can receive multiple groups — acme-admins and acme-leads can
both feed admin in Acme so leaving a sub-group still keeps the
other.
What happens on every SSO login
For each row whose group the user is in:
- The user is added to the org (
org_membersrow created if missing). - The role is granted via the org's Casbin grouping.
For each row whose group the user is no longer in:
- The role is revoked only if it was granted by the grid (manual role assignments stay safe).
- If the user has no remaining roles in that org from the grid, the org membership row is removed too (manual memberships in the same org keep the membership alive).
Super-admin flag is never touched. A super-admin who drops out of every IdP group keeps the platform-wide flag and break-glass access.
Safety nets
| What | Behaviour |
|---|---|
| Validation at Save | Each row's org must exist; role must exist in that org. Errors come back with GLOBAL_SSO_ASSIGNMENT_UNKNOWN_ORG / UNKNOWN_ROLE and the offending row. |
| Org delete refused | If any row references the org, deleting it returns ORG_IN_USE_BY_GLOBAL_SSO. Clear the row first. |
| Role delete refused | If any row references the role, deleting it returns ROLE_IN_USE_BY_SSO. |
| Absent groups claim | The reconcile is skipped entirely (HasGroupsClaim=false). A broken IdP Action that stops shipping groups will NOT silently revoke every grid-managed role — it just leaves Casbin alone. |
Steps
Admin → Settings → Global SSO. Scroll to Organization role assignments.- Click Add row. Fill:
- Group — exact IdP group name (case-sensitive).
- Organization — dropdown of every org in the install.
- Role — dropdown filtered to the picked org's roles.
- Repeat for every group → org/role triple you want.
- Save.
Editing
Rows can be edited inline. Deleting a row removes its reconciliation effect — the next SSO login from a user in that group will revoke the role (because the row no longer says "should have"). Members who got their role from that row before the deletion keep it until their next login.
Worked example — single-tenant company
You're a one-customer install with 3 orgs (engineering, finance,
sales) and want IdP groups to fully drive membership. In Auth0:
Roles: engineer, finance-admin, finance-viewer, sales
In the dtedge global SSO grid:
engineer → engineering → admin
finance-admin → finance → admin
finance-viewer → finance → viewer
sales → sales → viewer
User in Auth0 roles engineer, finance-viewer:
- Logs in via SSO → reconcile
- Added:
engineering/admin,finance/viewer - Not added to:
sales - HR moves the user out of finance → next login →
finance/vieweris revoked,financemembership removed (if no other rows matched and no manual roles)
Troubleshooting
| Symptom | Likely cause |
|---|---|
Save fails GLOBAL_SSO_ASSIGNMENT_UNKNOWN_ORG | The org was deleted, or the org UUID was hand-edited |
Save fails GLOBAL_SSO_ASSIGNMENT_UNKNOWN_ROLE | The role doesn't exist in that org's role catalog. Create it under Roles tab first. |
Org delete fails ORG_IN_USE_BY_GLOBAL_SSO | The org is referenced in the grid. Remove its rows first. |
Role delete fails ROLE_IN_USE_BY_SSO | The role is referenced in the grid (or in per-org group_role_map, or set as default_role). |
| Member loses role on every login | Grid row says "should have" but IdP isn't sending the group. Confirm has_groups=true in backend log. |
| Per-org SSO conflict | If an org also has its own per-org SSO enabled, that org's logins use per-org reconcile, not the global grid. Don't mix unless you intend to. |
See also
- Configure global SSO — the parent form
- Configure per-org SSO — alternative pattern
- Identity and SSO