Set up directory sync
- In workspace administration, open People & Security, then Domain and Members.
- Under User provisioning, choose Setup Directory sync.
- Select the identity provider offered by the setup flow and follow the generated instructions in both systems.
- Start with a test user and group. Verify that a user creation, an attribute update, a group membership change, and a deactivation are reflected as intended before provisioning the broader directory.
Map groups to workspace roles
An administrator can map a workspace group to an Admin or Manager role from Settings & Governance > Roles. The group can be provisioned from the IdP or managed manually in the workspace.- A member inherits the role mapped to each group they belong to.
- Each group can grant at most one role.
- A member who receives roles from several groups keeps the highest role.