The SAML use case is a special one - it’s the only one where a user’s roles cannot be dynamically updated. This is because the user’s roles are sent in the initial authentication handshake between Gate and the SAML Identity Provider (IdP). IdP Setup To enable SAML roles, configure your IdP to include group membership in the assertion (not covered - some providers may not offer this option).