Document organization-managed users and fix adjacent identity gaps - #21110
Document organization-managed users and fix adjacent identity gaps#21110jkodroff wants to merge 1 commit into
Conversation
Adds content/docs/administration/concepts/org-managed-users.md covering how SAML JIT provisioning, SCIM, and the Migrate to Org-Managed Account control create an organization-managed account, how that differs from SAML org membership, the three restrictions that apply, and the destructive migration. Also closes the adjacent gaps found in the same investigation: corrects the Pulumi Cloud FAQ answer that conflated linking an OAuth identity with signing in through it, documents when identity linking is unavailable, states the Bitbucket workspace admin requirement, separates backing membership from Pulumi membership, warns that switching away from SAML discards the SCIM token, adds the multi-org prerequisite for SAML conversion via a new saml-conversion-prereq shortcode, and reconciles Atlassian/Bitbucket naming. Fixes #21103 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015tSLanRMgU47HztDkoxHbG
There was a problem hiding this comment.
✅ No issues found
About Unblocked
Unblocked has been set up to automatically review your team's pull requests to identify genuine bugs and issues.
📖 Documentation — Learn more in our docs.
💬 Ask questions — Mention @unblocked to request a review or summary, or ask follow-up questions.
👍 Give feedback — React to comments with 👍 or 👎 to help us improve.
⚙️ Customize — Adjust settings in your preferences.
Pre-merge Review — Last updated 2026-08-25T00:55:54ZTip Summary: This PR adds a new concept page, Review confidence:
Investigation log
🔍 Verification trail97 claims extracted · 61 verified · 11 unverifiable · 0 contradicted
Important Please don't hide, resolve, or delete this comment! It breaks things! 📖 How pre-merge review works — the full lifecycle, short-circuits, and escape hatches. |
continued from previous comment
🚨 Outstanding in this PRThese must be resolved or refuted before merging.
|
Lighthouse Performance ReportCommit: be285bb | Metric definitions
|
Adds a concepts page for organization-managed Pulumi Cloud accounts — accounts an organization creates and controls through SAML JIT provisioning or SCIM — and closes the seven adjacent documentation gaps found in the same investigation.
Changes
New page —
concepts/org-managed-users.md: how an account becomes org-managed, why an administrator wants it, how it differs from SAML organization membership, the three restrictions, and the destructive Migrate to Org-Managed Account migration. Cross-linked from Accounts, SAML, SCIM, and SAML admin.Adjacent fixes
saml-conversion-prereqshortcode, used in all six SAML guidesConcepts nav weights shifted to seat the new page after Accounts.
Fixes #21103