Enterprise SSO
For orgs that live in an identity provider: members sign in through it, and joining/leaving the company can drive access automatically.
🚧 Not written yet
This page is scaffolded — the outline below is what it will cover. Progress is tracked in gearflow#959.
What this page will cover
- Who can do this: org owner / admins
- Connecting SAML 2.0 or OIDC
- Provisioning modes and group-to-role mapping
- Enforcing SSO (and the break-glass considerations)