Skip to content

Cloud: Add clarifying note to IDP and groups#2576

Open
tmjd wants to merge 1 commit intomainfrom
ets-org-idp-info
Open

Cloud: Add clarifying note to IDP and groups#2576
tmjd wants to merge 1 commit intomainfrom
ets-org-idp-info

Conversation

@tmjd
Copy link
Member

@tmjd tmjd commented Mar 9, 2026

Product Version(s):
Calico Cloud

Issue:
User thought a user given Admin through IDP groups should have Team Management permissions. This PR clarifies that is not the case.

Link to docs preview:

SME review:

  • An SME has approved this change.

DOCS review:

  • A member of the docs team has approved this change.

Additional information:

Merge checklist:

  • Deploy preview inspected wherever changes were made
  • Build completed successfully
  • Test have passed

@tmjd tmjd requested a review from a team as a code owner March 9, 2026 19:38
@netlify
Copy link

netlify bot commented Mar 9, 2026

Deploy Preview for calico-docs-preview-next ready!

Name Link
🔨 Latest commit 41c8f6b
🔍 Latest deploy log https://app.netlify.com/projects/calico-docs-preview-next/deploys/69af21cbe5dbb100081a3e3f
😎 Deploy Preview https://deploy-preview-2576--calico-docs-preview-next.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify
Copy link

netlify bot commented Mar 9, 2026

Deploy Preview succeeded!

Name Link
🔨 Latest commit 41c8f6b
🔍 Latest deploy log https://app.netlify.com/projects/tigera/deploys/69af21cb5643ec0008ac7094
😎 Deploy Preview https://deploy-preview-2576--tigera.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 68 (🟢 up 1 from production)
Accessibility: 98 (no change from production)
Best Practices: 92 (no change from production)
SEO: 100 (no change from production)
PWA: -
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

Comment on lines +34 to +36
:::note
Organization-level permissions, such as user and role management, are not included when roles are assigned through IdP groups.
:::
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should be specific about the permissions that can't be assigned this way. Do you have a complete list?

If I can't assign them with IdP groups, what's the workaround?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The user and role management are the only two permissions that I'm aware of.
The expectation is that any user needing to have Organization Admin needs to be explicitly assigned the Admin role.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I missed that this include access to the Usage page. So roles assigned through IDP groups will not give access to the Manage Team or Usage pages.

@ctauchen
Copy link
Collaborator

ctauchen commented Mar 12, 2026

@tmjd Let's move this note out of the procedure and into a dedicated Limitations section before Prerequisites. Here's the suggested wording:

## Limitations

The following organization-level permissions cannot be assigned through IdP groups:

- Manage Team
- Usage Metrics

To grant these permissions, assign them directly to individual users in the Calico Cloud web console.

---

Also, please remember to put this through to vNext.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants