Maps a raw IdP group to an ANKASecure role at the platform (ROOT) scope — the deny-by-default admission input. Unlike the tenant plane, the deployment plane uses the single admin.platform.idp.manage scope (no separate mapping scope). The mapped role is checked at declaration time so the mapping cannot be created in a state the federated login path is unable to consume: an unknown role, or a custom role owned by another tenant, is refused 404 (both causes are collapsed into one oracle-safe body); a service-to-service-only role is refused 400; and a role that is not assignable inside a tenant of this type is refused 422 federated-role-not-assignable. Cross-surface divergence, deliberate: the SAME (role, tenant type) matrix answers 400 invalid-input on assignUserRoles and 422 here. The user-assignment surface rejects a malformed assignment request, whereas this surface accepts a well-formed declaration whose semantics cannot be satisfied — which is what 422 means. Required scope: admin.platform.idp.manage.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||