| Route | Use when | Primary owner |
|---|---|---|
| Invite users directly | An Org Admin, Team Admin, or Project Admin will add the initial users at the appropriate level. This is suitable for a small pilot or a manually managed rollout. | Org Admin, Team Admin, or Project Admin |
| Use SSO | An identity provider should authenticate users and, when configured, map groups to Teams. | Identity administrator and Org Admin |
| Invite from | Use when | Confirm |
|---|---|---|
| Organization | Administrators are creating the enterprise member pool and assigning users to one or more Teams. | Organization role, Team assignments, Team roles, and resulting Project access. |
| Team | Internal users need access to several Projects within one Team. | Team role and the role for each relevant Project. |
| Project | A user should access one Project, such as an external or cross-functional collaborator. | Current Project role, resulting Team role, and access to other Projects. |
| Capability | What it does | Important boundary |
|---|---|---|
| SAML SSO | Authenticates users and can add them to the Organization. | Users are not assigned to Teams by default unless SAML Group Mapping is configured. |
| SAML Group Mapping | Maps identity-provider groups to Apidog Teams and grants initial Project permissions. | The initial Project role depends on the mapped Team role. Group Mapping does not provide a separate role setting for each Project. |
| SCIM | Automates supported user provisioning and removal. | SCIM does not manage groups. Use SAML Group Mapping for identity-provider group-to-Team mapping. |
| Representative user | Expected access | Validation |
|---|---|---|
| Admin user | Project Admin | Can manage the pilot Project and its members. |
| Editor user | Project Editor | Can create and modify the intended Project content. |
| Read-only user | Project Read-only | Can view and run permitted content but cannot edit it. |
| Restricted user | Project Forbidden or no Project membership | Cannot open the pilot Project. |