Manage roles with Okta
Automatically assign Pinecone organization and project roles from SAML attributes with Okta.
Instead of managing roles manually in Pinecone, you can have Pinecone automatically assign organization and project roles from your identity provider (IdP) on each login. This page continues Configure SSO with Okta and shows how to set up SAML role management with Okta. These instructions can be adapted for any provider with SAML 2.0 support.
How it works
Section titled “How it works”When SAML role management is enabled, Pinecone reconciles each user's roles on every SSO login:
- Pinecone reads the roles your IdP sends in the SAML
rolesattribute. - It replaces the user's organization and project roles with exactly the roles in that attribute. Roles for projects not included in the attribute are removed, and values that don't match a known role are ignored.
- Because roles come entirely from your IdP, while this mode is enabled you can no longer invite members or edit roles in the Pinecone console or through the Admin API, and the SSO Default role isn't applied.
- To revoke a member's access, remove their roles in your IdP. At their next sign-in, Pinecone clears all of their organization and project roles and blocks the login. Active members are re-authenticated at least every 24 hours, so the change applies within a day.
To avoid losing access, configure and verify the roles attribute in Okta before you enable SAML role management in Pinecone. The steps below are in that order.
Role attribute values
Section titled “Role attribute values”Pinecone reads roles from the roles attribute. Each value uses one of the following formats:
- Organization role:
pinecone:<OrgRole> - Project role:
pinecone:project:<projectID>:<ProjectRole>
<projectID> is the project's unique ID. To find it, go to the project list in the Pinecone console. For more information, see Project IDs.
A user can hold multiple roles by sending multiple values in the roles attribute.
Organization roles
Section titled “Organization roles”For details on what each organization role grants, see Understanding organizations.
| Organization role | Attribute value |
|---|---|
| Organization owner | pinecone:OrgOwner |
| Organization manager | pinecone:OrgManager |
| Organization member | pinecone:OrgMember |
| Billing admin | pinecone:OrgBillingAdmin |
Project roles
Section titled “Project roles”For details on what each project role grants, see Understanding projects.
| Project role | Attribute value |
|---|---|
| Project owner | pinecone:project:<projectID>:ProjectOwner |
| Project manager | pinecone:project:<projectID>:ProjectManager |
| Project member | pinecone:project:<projectID>:ProjectMember |
| Control plane editor | pinecone:project:<projectID>:ControlPlaneEditor |
| Control plane viewer | pinecone:project:<projectID>:ControlPlaneViewer |
| Data plane editor | pinecone:project:<projectID>:DataPlaneEditor |
| Data plane viewer | pinecone:project:<projectID>:DataPlaneViewer |
For example, to make a user an organization manager who is also a project owner on one project, send these two values in the roles attribute:
pinecone:OrgManager
pinecone:project:a2f7dddb-1597-4eff-9f71-535fde243f58:ProjectOwner1. Send roles from Okta
Section titled “1. Send roles from Okta”Configure Okta to send each user's roles in a SAML attribute named roles, where each value is one of the role attribute values above. You can populate that attribute in a few ways; choose whichever fits how you already manage users in Okta.
Option A: From a user profile attribute
Section titled “Option A: From a user profile attribute”Use this option to set roles directly on each user's Okta profile.
-
In Okta, go to Directory > Profile Editor and edit the Okta user profile.
-
Add an attribute named
pineconeRoleswith data type string array. -
For each user, set
pineconeRolesto theirpinecone:*values (directly, or through a profile mapping). -
In Applications > Pinecone > Sign On, add an Attribute Statement:
- Name:
roles - Name format:
Unspecified - Value:
user.pineconeRoles
- Name:
Option B: From group membership
Section titled “Option B: From group membership”Use this option to assign roles by adding users to Okta groups.
-
In Okta, create a group for each Pinecone role you want to assign, naming each group exactly as the role's attribute value (for example,
pinecone:OrgOwnerorpinecone:project:<projectID>:ProjectManager), and add the appropriate users to each group. -
In Applications > Pinecone > Sign On, send those group names in the
rolesattribute using either:- A Group Attribute Statement with Name
roles, Name formatUnspecified, and Filter Starts withpinecone:. - Or an Attribute Statement with Name
rolesand the expressionuser.getGroups({'group.profile.name': 'pinecone:', 'operator': 'STARTS_WITH'}).![profile.name].
- A Group Attribute Statement with Name
Any other approach works as well, as long as the roles attribute resolves to the role attribute values.
2. Verify the roles in the SAML assertion
Section titled “2. Verify the roles in the SAML assertion”Before you hand role management to Okta, confirm the roles attribute contains what you expect.
- In Applications > Pinecone > Sign On, click Preview the SAML Assertion.
- Select a user who should be an organization owner and generate the preview.
- Confirm the assertion includes a
rolesattribute containingpinecone:OrgOwner(and any project roles you assigned).
3. Enable SAML role management in Pinecone
Section titled “3. Enable SAML role management in Pinecone”- In the Pinecone console, go to Settings > Access > Identity provider.
- Confirm that single sign-on shows the Enforced status. If it doesn't, edit your SSO configuration to enforce SSO before continuing.
- In the User management section, select Manage roles with SAML attributes.
- In the Enable SAML role management dialog, review the Before you enable prerequisites, then click Enable SAML role management.
Role assignment now comes entirely from your IdP. Roles update at the member's next SSO login. Since SAML sessions re-authenticate at least every 24 hours, an active user's role changes apply within 24 hours. Default role assignments configured during SSO setup no longer apply.
To stop syncing roles from your IdP, return to Settings > Access > Identity provider and select Manage roles in Pinecone. Existing roles are preserved, and you can edit them again in the console.