Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,9 @@ By managing membership in that security group, you can manage role-based access
To set up an identity provider for Calico Cloud, open a [support ticket](https://support.tigera.io).
:::
2. Select one or more predefined user roles from the **Predefined Roles** list to assign to this group.
:::note
Organization-level permissions, such as user and role management, are not included when roles are assigned through IdP groups.
:::
Comment on lines +34 to +36
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should be specific about the permissions that can't be assigned this way. Do you have a complete list?

If I can't assign them with IdP groups, what's the workaround?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The user and role management are the only two permissions that I'm aware of.
The expectation is that any user needing to have Organization Admin needs to be explicitly assigned the Admin role.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I missed that this include access to the Usage page. So roles assigned through IDP groups will not give access to the Manage Team or Usage pages.

1. Click **Save**.

## Add custom permissions to an IdP group
Expand Down