Application Management
Mapping Identity Provider Groups to Papertrail Access Levels
This article explains how SAML role mapping, also known as group mapping, can be used to expedite assigning organization or product access levels.
First published date
Last published date
Overview
Product section
Cause
If role mapping is enabled in the SAML configuration page but you use the Papertrail to modify access levels, changes made to user access levels will not be retained. Only the definition of the specific log group(s) that members can access should be modified in Papertrail Members settings. For all other access level definitions, only settings in the SAML configuration page are retained.
Resolution
Once SAML role mapping is enabled, the organization owner should only modify access to Papertrail features in the SAML configuration page. Only the definition of the specific log group(s) that members can access should be modified in Papertrail Members settings.
The organization owner should:
-
Go to the Security section under the Account page and click the Enable SAML button.
-
Click Role Mapping to review and modify the configured settings.
If the roles mapped to an IdP include "Specific logs" or "Specific logs/alerts", go to the Papertrail Members settings. For each member with "Specific groups" listed under Log Access Permissions:
-
Click Edit.
-
Select the checkbox next to the log group(s) the member should access.
-
Click Save Changes.