RyzeDeskRyzeDesk

Stripe

4105 articles

Set up group-based role assignment with SCIM synchronised groups


Set up group-based role assignment with the related setting synchronised groups

Before you begin

To assign account or organisation roles to users dynamically and offline with the related setting, you must:

  • Set up single sign-on
  • Set up the related setting
  • Configure your IdP to synchronise users and groups to Stripe

Configure group-based role assignment in Stripe

You can view the groups that you sync through the related setting:

  1. From the Team and security settings page, go to Groups .
  2. When you enable group sync through the related setting in your IdP configuration, groups display in a table in this view.
  3. If group sync through the related setting isn’t enabled, a prompt appears to Enable the related setting in Stripe to trigger a group sync the related setting update.
  4. If you enabled the related setting on your IdP and in Stripe, check your IdP logs to confirm whether the related setting group sync events were pushed to Stripe.

Assign roles to users in groups:

  1. Select a group by clicking the overflow menu ( ) next to it.
  2. Alternatively, you can select a group to view members of the selected group first.
  3. Then, to assign roles to the group (inherited by the members in the group), select Assign roles .
  4. You can apply more than one Dashboard role to a group. In this case, the set of permissions mapped to each group applies.
  5. If you sync groups to an organisation, you see a prompt to choose the accounts you want to assign group-based roles to, similar to the normal role assignment flow in organisations.

Group-based role assignment and Stripe organisations

We support group-based role assignments for Stripe organisations. When assigning roles at the organisation level, the role assignment applies to the organisation, meaning the roles also automatically propagate to each account within the organisation.

Troubleshoot group-based role assignment

Avoid some common role assignment issues by considering the following guidelines.

You don’t see the option to assign roles to a group

  • To assign roles to groups or users in the Dashboard with SSO, you must configure role assignment to be Dashboard-based (instead of SAML).
  • Go to Settings > Team and security and click the Single sign-on (SSO) tab.
  • Click Configure role assignment > Stripe Dashboard > Save .

You can now assign roles to groups that sync through the related setting.

You don’t see any users or groups synchronized into Stripe

  • Groups synchronise to Stripe according to IdP synchronisation cycle times. For example, Microsoft Entra ID (formerly Azure AD) might take as long as 40 minutes to synchronise groups.
  • Stripe only synchronises users that match the domains configured in Stripe.
  • If neither users nor groups synchronise to Stripe after a long time, check your IdP the related setting provisioning logs for errors. These errors might be due to key mismatches or endpoint URL misconfiguration.
Last verified 2026-09-27

Is this helpful?