Subscription admins can rank all of their account's roles, standard and custom, in one drag-and-drop list. SSO uses that ranking to decide which role a user gets when their identity provider groups map them to the same workspace with different roles: they get the highest-ranked one.
Standard roles start in a default order, and custom roles sit in the same list, so the full hierarchy is visible in one place. Each user still holds a single role per workspace.
It lives under "Amend role priority" at the bottom of the "Set group access" section on Settings > Single sign-on.
This is a small setting that only matters for accounts that use custom roles and have overlapping group mappings in "Set group access", but for those accounts it closes a real gap: until now there was no rule for which role won.
Any user in the Subscription Admin role can configure both these features.
👥 Who it's for:
These were built based on requests from Target, but apply to any enterprise account on SSO, especially those running many workspaces, and to the IT and identity admins who manage their access.