Building reliable (and fast!) directory sync

“Who’s your User?”

— Master Control Program, TRON (1982)

If user identity is important to your application, you need a way to manage it. Usually this means user accounts, and you create them when someone signs up.

But allowing employees to sign up for whatever SaaS app strikes their fancy is a management nightmare. So organizations like ways to control which users exist (or do not exist) in your app.

That controls who can sign in, but how about what they can do?

For that you need roles, or groups, which, like the users, come from the organization's identity provider - Entra, Google, Okta, etc. Groups form the basis of Firezone's access model. They determine who can access what.