Conversation
✅ Deploy Preview for calico-docs-preview-next ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview succeeded!
To edit notification comments on pull requests, go to your Netlify project configuration. |
| :::note | ||
| Organization-level permissions, such as user and role management, are not included when roles are assigned through IdP groups. | ||
| ::: |
There was a problem hiding this comment.
We should be specific about the permissions that can't be assigned this way. Do you have a complete list?
If I can't assign them with IdP groups, what's the workaround?
There was a problem hiding this comment.
The user and role management are the only two permissions that I'm aware of.
The expectation is that any user needing to have Organization Admin needs to be explicitly assigned the Admin role.
There was a problem hiding this comment.
I missed that this include access to the Usage page. So roles assigned through IDP groups will not give access to the Manage Team or Usage pages.
|
@tmjd Let's move this note out of the procedure and into a dedicated Limitations section before Prerequisites. Here's the suggested wording: Also, please remember to put this through to vNext. |

Product Version(s):
Calico Cloud
Issue:
User thought a user given Admin through IDP groups should have Team Management permissions. This PR clarifies that is not the case.
Link to docs preview:
SME review:
DOCS review:
Additional information:
Merge checklist: