scim

3 posts

gitlab

Keep your GitLab seats in check with restricted access (opens in new tab)

GitLab’s restricted access feature helps organizations prevent unexpected seat overages by blocking new billable users once all purchased seats are occupied. Recent improvements make it work more reliably with SAML, SCIM, LDAP, OIDC, and SSO provisioning, while providing clearer warnings and audit information. The feature is forward-looking: it prevents future growth but does not automatically resolve existing overages. ## How restricted access controls seats - Available on GitLab.com and Self-Managed. - When all licensed seats are used, new billable users cannot be added. - Users who only need authentication can receive the non-billable Minimal Access role. - Existing billable members are not downgraded or removed when restricted access is enabled. - Organizations must resolve current overages by removing users or purchasing more seats. ## Identity provider integration - Users provisioned through SAML, SCIM, or LDAP are assigned Minimal Access when no paid seats are available. - Automated synchronization can continue without immediately creating billable overages. - OIDC-only users can be assigned Minimal Access at the top-level group and authenticate without consuming seats. ## Dormant user reactivation - GitLab can deactivate inactive users to free seats. - Previously, SSO or OIDC sign-ins could silently reactivate dormant users as billable members. - With restricted access enabled and no seats available, reactivated users enter a pending approval state. - Their existing group and project memberships are preserved until an administrator approves them. ## Improved operational visibility - Configuration warnings now appear for LDAP, SAML group links, and SCIM. - GitLab distinguishes between approaching and reaching the seat limit. - Group owners and instance administrators can receive email notifications when users fall back to Minimal Access. - Audit logs show Minimal Access fallback events. ## Self-Managed settings cache Self-Managed installations cache application settings for 60 seconds by default. Changes between restricted access and user cap may therefore take up to a minute to appear consistently. Administrators can adjust the cache interval if necessary. ## Restricted access versus user cap - **Restricted access:** Controls additions based on available licensed seats. - **User cap:** Sends new users into an administrator approval workflow regardless of seat availability. - The two features cannot be enabled simultaneously; enabling restricted access automatically disables user cap. ## Enabling the feature - **GitLab.com:** Settings > General > Permissions and group features > Seat control > Restricted access. - **Self-Managed:** Admin > Settings > General > New user account restrictions > Seat control > Restricted access. - GitLab.com does not support restricted access when the top-level group is shared with an external group. Restricted access is recommended for organizations seeking predictable licensing costs while retaining automated identity provisioning and controlled user reactivation.

figma

Figma Expands Support for India with Local Data Hosting and New Governance Tools | Figma Blog (opens in new tab)

Figma is expanding its support for India with local hosting for Figma file data and stronger enterprise governance tools. Local data residency is planned for Q1 2026, helping regulated organizations meet security and compliance requirements while maintaining Figma’s performance. Governance+ is already available to Enterprise customers in India. ## Local Data Hosting for Indian Customers - Figma file data will be hosted within India, including content from FigJam, Make, Sites, Buzz, and Slides. - The option is intended for regulated sectors such as public services, healthcare, and finance. - Indian users created more than 35 million files between October 2024 and September 2025. - India is Figma’s second-largest active user base globally. - The offering builds on existing data residency options in Australia, Europe, and the United States. - Figma has expanded its local presence through a new Bengaluru hub and serves companies including Airtel, Flipkart, Swiggy, TCS, and Zomato. ## Governance+ for Enterprise Teams Governance+ gives organizations more control over how employees access and use Figma: - **Centralized control:** IP Allowlisting and Network Access Restrictions help ensure work occurs in approved Figma instances and networks. - **Account security:** Enforced two-factor authentication, extended idle session timeouts, and support for multiple identity providers reduce account-compromise risks. - **Data governance:** The Discovery Pipeline provides visibility into activity to support retention policies and legal discovery. - Governance+ complements existing tools such as activity logs, SSO, SCIM-based seat management, and restrictions on external collaborators. - The feature is available now to all Enterprise-plan customers. Figma’s India strategy combines regional data residency with tighter administrative controls, making the platform more suitable for organizations with strict privacy, security, and regulatory obligations. Enterprises interested in local hosting can register their interest ahead of its planned Q1 2026 launch.

figma

Design needs everyone: new plans for companies that design together | Figma Blog (opens in new tab)

Figma’s 2022 plan updates aim to make design a company-wide activity while reducing the organizational complexity that comes with more participants. FigJam is leaving beta with expanded collaboration features and new pricing, while Figma Enterprise adds structure, controls, security, and administrative support for larger organizations. The central goal is to help teams collaborate from brainstorming through implementation without overwhelming users or administrators. ## FigJam Becomes a Full Collaboration Product - FigJam was launched in beta to support brainstorming, diagramming, planning, meetings, and informal collaboration. - Teams adopted it for varied uses, including: - Dwell’s company-wide idea “swarms” - Square’s employee onboarding - Twitter’s cross-functional bug-bashing sessions - Figma expanded FigJam with plugins, widgets, and ready-to-use templates. - FigJam is free on the Starter plan, including: - Unlimited personal whiteboards - Three shared whiteboards - Unlimited collaborators - Unlimited shared whiteboards for an organization start at $3 per editor per month. ## Figma Enterprise for Larger Organizations - As more departments joined the design process, companies faced: - More files and projects to navigate - Less flexibility for individual teams - Greater administrative responsibility - The Enterprise plan is designed for organizations needing more structure, granular controls, advanced security, and support. - Pricing begins at: - $75 per editor per month for Figma - $5 per editor per month for FigJam - Features were being released immediately or planned for the following months. ## Workspaces Reflect Company Structure - Enterprise workspaces let organizations create dedicated areas for departments, product groups, or functions. - Workspaces help users focus on relevant content while preserving access to company-wide resources. - Administrators can define default teams and libraries for each workspace. - Users can limit searches to a particular workspace to find files, people, and components more quickly. ## Administration at Company Scale - Enterprise tools are intended to manage large numbers of files, users, and permissions more efficiently. - Workspace administration can be delegated to people familiar with each group’s users. - Delegated responsibilities include membership, roles, and true-ups. - Role-setting through SCIM is also introduced to automate administrative workflows. Figma’s broader recommendation is that companies should invite more people into design while using FigJam for inclusive collaboration and Enterprise workspaces and controls for organization-wide scale.