Search resources and navigation

Start typing to search this project.

Saved views

acme-production-app/production
Production scope
Dashboard/ Organization / People & access

People & access

Organization roles are inherited only within their assigned project, environment, or resource scope. Explicit denies always win.

{{ message() }}

Single sign-on

OpenID Connect providers

Discovery, issuer binding, state, nonce, PKCE, signed ID tokens, and verified email-domain policy are enforced. Provider access and refresh tokens are discarded.

Keep the recovery path proven.Organization owners can always use local sign-in. Before enforcement, verify the owner email, save MFA recovery codes, and test cloud auth:oidc:disable <slug> --confirm <slug> from the host.
Callback URI{{ oidcCallbackPattern() }}
No SSO providersLocal authentication remains available until an OIDC provider is explicitly configured.

{{ oidcEditing() ? 'Configure SSO provider' : 'Add SSO provider' }}

HTTPS discovery issuer must match this value exactly.
{{ oidcEditing() ? 'Leave empty to preserve the encrypted secret.' : 'Encrypted at rest with the authentication key.' }}
Exact domains only; wildcards are rejected.
Required when MFA is enabled.

Invite a member

{{ roleSummary[roleTemplate()] }}
Required when adding another owner.
One-time acceptance link{{ issued()?.acceptUrl }}Copy this link now. Only its SHA-256 hash is stored, and resending replaces it.

Members

PersonRoleEffective scopeLast activity
No membersCreate an invitation to add someone.

Edit access

Required when adding, removing, or changing an owner.
After previewing, type the membership ID.
Gained{{ accessDiff()?.gained?.join(', ') || 'None' }}
Lost{{ accessDiff()?.lost?.join(', ') || 'None' }}

Remove membership

Type {{ confirmTok() }} to {{ confirmVerb() }}:
{{ opOutput() }}

Pending & previous invitations

EmailRoleScopeState
No invitationsNew and previous invitation states appear here.