Instance/Workspace/Users/Roles/Group Management Best Practices

Hey everyone! I’m new to Tulip and have been reading up on Instances, Workspaces, and Users/Roles/Groups and integration with SAML. I came across several posts looking to add features (below).

https://community.tulip.co/t/adding-users-to-multiple-workspaces/11476

https://community.tulip.co/t/allow-a-user-to-be-mapped-to-multiple-workspaces-through-attribute-mapping/14124

When I sat down and looked at the best option when using SAML, it was recommended in the documentation to use group names that have site/role in the name. I think this is fine and makes a lot of sense, but since the introduction of Workspaces, this becomes way more complicated, and right now, we have no way to have users in multiple workspaces.

Currently, we are using a single instance with workspaces setup for DEV and PROD between the different companies/sites, as well as we are setup to use Tulip Control Mode, with a default Role and Workspace assignment. I would like to be fully IdP Control Mode so moving users between groups will change their permissions in the tool so I/specified users do not need to adjust permissions in the app.

I’m curious, given the current capabilities with Tulip, what best practices have you established for multi-company, multi-site, enterprise wide deployment? I’m curious about your use of instances, workspaces, and the SAML capabilities.

Thanks for taking the time to help me (and others that follow)!