Group Role Mapping

Settings → SCIM: give each group your identity provider pushes a Guard role, with the highest role winning.

Group Role Mapping is the third section on Settings → SCIM. It maps groups your identity provider pushes through SCIM to Guard roles. When a user belongs to multiple groups, the highest role wins.

Map a group to a role

  1. Go to Settings → SCIM and find Group Role Mapping. Each group pushed from your identity provider appears as a row with its group name.
  2. In the group's role list, choose Unmapped, Read Only, Analyst, or Admin.
  3. Guard saves the change immediately and shows Role mapping updated for {group}.

Users whose groups are all Unmapped get the Default SCIM Role from Provisioning Settings. Mappings match on the group name, so renaming a group in your identity provider requires mapping it again.

If the section shows No groups have been pushed from your identity provider yet. Configure push groups in your IdP to see them here., set up group push in your identity provider first.