Org Admin is an assignable role that you can grant to a (SCIM-linked or not) team [Public Beta]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
Today, organization administrator is a special "membership type", that isn't assignable using the standard roles and permissions system. The biggest implication of this is that teams cannot be assigned the "organization administrator" role, and requires users to manually be given the role.
When the organization administrator role is supported, administrators will be able to:
1. Assign the role to a team, which has the side effect of making it possible to @mention all the admins (if you like).
2. Link that team to an IDP group
3. Use your IDP to then manage who an administrator of that organization is.
JIT permission management systems, such as PIM, can also use this to elevate users to the "admin group" on demand, to let them take actions that aren't supported by the custom role platform yet, and then automatically drop back to standard permissions.
### Expected Outcome
Organization administrator will be a role that can be assigned to a team, like any other role at the organization level. Users in that team (or a child team) will be full administrators of the organization it's assigned in.
In the future, organization administrator will also be available from the enterprise level, so that users and enterprise teams can be assigned that role against multiple organizations at once.
贡献指南
调研方向
此路线图 issue 未指明任何 repository 文件、测试或实现入口。首先定位组织角色和团队权限系统,然后验证组织管理员角色可以分配给团队、由子团队成员继承,并可与链接到 IDP 的组一起使用。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github
- 领域
- authorization
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100