Skip to main content

Manage global org-role assignments

Only relevant when global SSO is enabled and the install wants IdP groups to drive org membership + roles across multiple orgs. Configured at Admin → Settings → Global SSO → Organization role assignments.

This is the Phase 3 SSO feature: the global IdP becomes the identity AND the membership authority. An IdP group like acme-engineers can grant "editor in Acme" automatically, with no manual invite step.

If you don't need cross-org IdP-driven membership, leave the grid empty and use per-org SSO instead.

How the grid maps​

Each row is a tuple: (IdP group, org, role).

group org role
───────────────── ───────── ──────
acme-admins Acme admin
acme-engineers Acme editor
acme-readonly Acme viewer
bortech-admins BorTech admin
bortech-viewers BorTech viewer

One IdP group can produce multiple rows — engineering can grant editor in Acme AND editor in BorTech in the same map. One org can receive multiple groups — acme-admins and acme-leads can both feed admin in Acme so leaving a sub-group still keeps the other.

What happens on every SSO login​

For each row whose group the user is in:

  1. The user is added to the org (org_members row created if missing).
  2. The role is granted via the org's Casbin grouping.

For each row whose group the user is no longer in:

  1. The role is revoked only if it was granted by the grid (manual role assignments stay safe).
  2. If the user has no remaining roles in that org from the grid, the org membership row is removed too (manual memberships in the same org keep the membership alive).

Super-admin flag is never touched. A super-admin who drops out of every IdP group keeps the platform-wide flag and break-glass access.

Safety nets​

WhatBehaviour
Validation at SaveEach row's org must exist; role must exist in that org. Errors come back with GLOBAL_SSO_ASSIGNMENT_UNKNOWN_ORG / UNKNOWN_ROLE and the offending row.
Org delete refusedIf any row references the org, deleting it returns ORG_IN_USE_BY_GLOBAL_SSO. Clear the row first.
Role delete refusedIf any row references the role, deleting it returns ROLE_IN_USE_BY_SSO.
Absent groups claimThe reconcile is skipped entirely (HasGroupsClaim=false). A broken IdP Action that stops shipping groups will NOT silently revoke every grid-managed role — it just leaves Casbin alone.

Steps​

  1. Admin → Settings → Global SSO. Scroll to Organization role assignments.
  2. Click Add row. Fill:
    • Group — exact IdP group name (case-sensitive).
    • Organization — dropdown of every org in the install.
    • Role — dropdown filtered to the picked org's roles.
  3. Repeat for every group → org/role triple you want.
  4. Save.

Editing​

Rows can be edited inline. Deleting a row removes its reconciliation effect — the next SSO login from a user in that group will revoke the role (because the row no longer says "should have"). Members who got their role from that row before the deletion keep it until their next login.

Worked example — single-tenant company​

You're a one-customer install with 3 orgs (engineering, finance, sales) and want IdP groups to fully drive membership. In Auth0:

Roles: engineer, finance-admin, finance-viewer, sales

In the dtedge global SSO grid:

engineer → engineering → admin
finance-admin → finance → admin
finance-viewer → finance → viewer
sales → sales → viewer

User in Auth0 roles engineer, finance-viewer:

  • Logs in via SSO → reconcile
  • Added: engineering/admin, finance/viewer
  • Not added to: sales
  • HR moves the user out of finance → next login → finance/viewer is revoked, finance membership removed (if no other rows matched and no manual roles)

Troubleshooting​

SymptomLikely cause
Save fails GLOBAL_SSO_ASSIGNMENT_UNKNOWN_ORGThe org was deleted, or the org UUID was hand-edited
Save fails GLOBAL_SSO_ASSIGNMENT_UNKNOWN_ROLEThe role doesn't exist in that org's role catalog. Create it under Roles tab first.
Org delete fails ORG_IN_USE_BY_GLOBAL_SSOThe org is referenced in the grid. Remove its rows first.
Role delete fails ROLE_IN_USE_BY_SSOThe role is referenced in the grid (or in per-org group_role_map, or set as default_role).
Member loses role on every loginGrid row says "should have" but IdP isn't sending the group. Confirm has_groups=true in backend log.
Per-org SSO conflictIf an org also has its own per-org SSO enabled, that org's logins use per-org reconcile, not the global grid. Don't mix unless you intend to.

See also​