Organization roles are inherited only within their assigned project, environment, or resource scope. Explicit denies always win.
Discovery, issuer binding, state, nonce, PKCE, signed ID tokens, and verified email-domain policy are enforced. Provider access and refresh tokens are discarded.
cloud auth:oidc:disable <slug> --confirm <slug> from the host.{{ oidcCallbackPattern() }}{{ issued()?.acceptUrl }}Copy this link now. Only its SHA-256 hash is stored, and resending replaces it.| Person | Role | Effective scope | Last activity | |
|---|---|---|---|---|
| {{ actorName(member) }}{{ member.actor?.externalId?.replace('dashboard:', '') }} | {{ member.roleTemplate }}{{ roleSummary[member.roleTemplate] }} | {{ scopeLabel(member.scope) }}{{ member.source === 'legacy' ? 'Migrated direct access' : 'Inherited from membership' }} | {{ member.lastActiveAt ? new Date(member.lastActiveAt).toLocaleString() : 'Never' }} |
{{ opOutput() }}| Role | Scope | State | ||
|---|---|---|---|---|
| {{ invitation.email }} | {{ invitation.roleTemplate }} | {{ scopeLabel(invitation.scope) }} | {{ invitationState(invitation) }} |