Maps a federated email address or normalized domain to an ANKASecure role at the platform (ROOT) scope — the email/domain half of the deny-by-default admission input. A DOMAIN rule may not grant a platform-scope / wildcard role (422); an EMAIL rule is uncapped by that privilege ceiling. Independently of that ceiling, and on BOTH rule types, the admitted role is checked at declaration time so the rule cannot be created in a state the federated login path is unable to consume: an unknown role, or a custom role owned by another tenant, is refused 404 (both causes are collapsed into one oracle-safe body); a service-to-service-only role is refused 400; and a role that is not assignable inside a tenant of this type is refused 422 federated-role-not-assignable. Cross-surface divergence, deliberate: the SAME (role, tenant type) matrix answers 400 invalid-input on assignUserRoles and 422 here. The user-assignment surface rejects a malformed assignment request, whereas this surface accepts a well-formed declaration whose semantics cannot be satisfied — which is what 422 means. Required scope: admin.platform.idp.manage.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||