Per-organization SSO group filtering
K
Krzysztof Czajkowski
SSO group allow/block regex filters currently apply at the company level, so they can't be scoped to an individual organization. Because teams are organization-scoped while group filters are not, any IdP group assigned to a user triggers team creation in every organization that user can access, regardless of whether the group is relevant there. Customers running multiple organizations under one account have no way to prevent this cross-org team sprawl without one shared regex affecting all organizations identically. Supporting per-organization group filters would let admins keep each organization's team list limited to the groups that actually belong there.