Back to all releases

v1.31.2

Platform

// September 27, 2026

Directory groups grant roles on their own, and Slack accounts resolve to the people behind them

Roles stop being a manual list. An organization admin can map a directory group, or a directory attribute value such as department_name=Sales, to a role, and every member who matches picks that role up on top of whatever was assigned to them directly. Groups can be pulled in and mapped before any directory event delivers them, and role member counts include people who hold a role only through a mapping. Slack arrives as a work identity in the same release: connect one or more workspaces under Identity, sync and browse the directories, and map Slack members to the people already in your organization, so an account posting in Slack and a person in the platform are one record rather than two.

Features

  • Map directory groups and attributes to roles #6821 - Organization admins map a directory group, or a directory attribute value in key=value form, to a role, and matching members receive it alongside their direct assignments. syncDirectoryGroups pulls groups from the organization's linked directories so they can be mapped before an event delivers them, with webhook events remaining the source of truth: the listing never restores a group an event deleted and never overwrites a newer row. Setting and removing a mapping are audited under the directory_role_mapping subject, and role member counts include members who hold the role only through a mapping. (Author: @adaam2)
  • Connect Slack workspaces under Identity #6715 - Organization admins connect workspaces through Slack OAuth from a Slack workspaces tab and disconnect them from the list. Connecting a listed workspace again reauthorizes it in place, so there is no separate reconnect step. Credentials stay encrypted, workspace changes are audited, and the tab requires an organization admin browser session: API keys and support sessions are refused. (Author: @ThomasRooney)
  • Sync and browse Slack directories #6719 - Directories sync after a connection or on an admin's request, with workspace sync history, member counts, and a searchable read-only directory across workspaces. Complete snapshots preserve identity mappings and retained membership. (Author: @ThomasRooney)
  • Map Slack members to people #6726 - An inline picker lets organization admins map Slack memberships to existing personnel, reassign or remove mappings, and review directory changes without granting new permissions. A sync maps members whose email matches exactly one person. (Author: @ThomasRooney)
  • Work identities on a person's Accounts and devices page #6732 - Mapped Slack workspace accounts appear under Work identities. Employees can read their own mappings and contact an administrator for corrections, while organization admins review an active person's exact membership. (Author: @ThomasRooney)
  • Identity setup is one task with three steps #6793 - The setup board carries a single "Set up identity provider" task covering domain verification, single sign-on, and directory sync, replacing the separate "Verify your domain" task and the legacy connect and directory-sync tasks. (Author: @adaam2)
Sagar Batchu
Sagar Batchu
View on GitHub