Application Management

Mapping Identity Provider Groups to Papertrail Access Levels

This article explains how SAML role mapping, also known as group mapping, can be used to expedite assigning organization or product access levels.

First published date

12/9/2020 12:51 AM

Last published date

1/31/2026 12:14 AM

Overview

For SAML users, role mapping allows you to define organization and product roles, as well as grant access to logs and billing plans, based on the account's identity provider's group membership. Members added to an identity provider group will automatically gain access to any organization or product roles mapped to that group. Once role mapping is turned on, most access control permissions can only be changed in SAML settings. 

Product section

Papertrail

Cause

If role mapping is enabled in the SAML configuration page but you use the Papertrail to modify access levels, changes made to user access levels will not be retained. Only the definition of the specific log group(s) that members can access should be modified in Papertrail Members settings. For all other access level definitions, only settings in the SAML configuration page are retained.

Resolution

Once SAML role mapping is enabled, the organization owner should only modify access to Papertrail features in the SAML configuration page. Only the definition of the specific log group(s) that members can access should be modified in Papertrail Members settings.
Description of what part of Member settings is managed by Role Mapping vs modifiable in Papertrail settings

The organization owner should:

  1. Go to the Security section under the Account page and click the Enable SAML button. 

  2. Click Role Mapping to review and modify the configured settings.

If the roles mapped to an IdP include "Specific logs" or "Specific logs/alerts", go to the Papertrail Members settings. For each member with "Specific groups" listed under Log Access Permissions:

  1. Click Edit.

  2. Select the checkbox next to the log group(s) the member should access.

  3. Click Save Changes.