Groups, synced from your IdP
Grant access to a group instead of person by person — membership flows in over SCIM.
WhereConsoleCLITerraform
Introduced Jun 5, 2026
Your IdP→SCIM→platform group→grants
| Identity | Can be granted |
|---|---|
| user | agent roles · private resources · groups |
| agent | egress rules · private resources · other agents |
| app | conversations · private resources |
| runner | which environments may place work on it |
ownermaintainerparticipantinternal / private
How it works
Grant to a group.
Access lands on the team, not person by person — and follows the team as it changes.
Membership flows in over SCIM.
Groups carry an external identifier and a source, so the team you maintain in your identity provider is the team that holds access here.
Your access review already covers this.
The review your security team runs against the IdP now covers agents too — no second process.
See it on your own cluster.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.