> For the complete documentation index, see [llms.txt](https://docs.snyk.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.snyk.io/platform-administration/user-management.md).

# User management

- [User roles](https://docs.snyk.io/platform-administration/user-management/user-roles.md): Snyk user roles and how they differ by plan, from administrator-only on Free to multiple roles on Enterprise
- [User role management](https://docs.snyk.io/platform-administration/user-management/user-role-management.md): How to manage Snyk pre-defined and custom user roles, available on Enterprise plans
- [Pre-defined roles](https://docs.snyk.io/platform-administration/user-management/pre-defined-roles.md): Snyk standard pre-defined user roles, which cannot be customized, and how to assign them
- [Custom role templates](https://docs.snyk.io/platform-administration/user-management/custom-role-templates.md): Templates for Snyk custom roles, with titles and permissions mapped to responsibilities across the development lifecycle
- [Team Lead role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/team-lead-role-template.md): Custom role template for a Team Lead, an Organization Admin who can also customize permissions for other users
- [Developer role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/developer-role-template.md): Custom role template for a Developer, an Organization-level role to review scan results, fix vulnerabilities, and run tests
- [Auditor role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/auditor-role-template.md): Custom role template for an Auditor, a Group-level read-only role for viewing scan results and reports
- [Remediator role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/remediator-role-template.md): Custom role template for a Remediator, an Organization-level role that helps developers assess and fix vulnerabilities
- [Integration Editor/Implementor role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/integration-editor-implementor-role-template.md): Custom role template for an Integration Editor or Implementor, a Group-level role for managing third-party tool integrations
- [Incident Responder role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/incident-responder-role-template.md): Custom role template for an Incident Responder, an Organization-level role for quickly finding and addressing vulnerabilities
- [Application Security Engineer role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/application-security-engineer-role-template.md): Custom role template for an Application Security Engineer, an Organization-level role to manage Projects, ignores, and PR checks
- [Kubernetes Uploader role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/kubernetes-uploader-role-template.md): Custom role template for a Kubernetes Uploader, an Organization-level role that publishes Kubernetes Monitor and Insights data to Snyk
- [Legal Advisor role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/legal-advisor-role-template.md): Custom role template for a Legal Advisor, an Organization-level role to manage security and license policies and export reports
- [CLI Tester role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/cli-tester-role-template.md): Custom role template for a CLI Tester, an Organization-level role that lets CI/CD service accounts run Snyk CLI tests
- [Read-only CLI Tester role template](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/read-only-cli-tester-role-template.md): Custom role template for a Read-only CLI Tester, an Organization-level role that runs snyk test but blocks snyk monitor
- [Snyk Learn - Learning Admin](https://docs.snyk.io/platform-administration/user-management/custom-role-templates/snyk-learn-learning-admin.md): Custom role template for a Snyk Learn Learning Admin, which requires the Learning Management add-on
- [User management with the API](https://docs.snyk.io/platform-administration/user-management/user-management-with-the-api.md): How to manage Snyk users through the Snyk API, available on Enterprise plans
- [Provision users to Organizations using the API](https://docs.snyk.io/platform-administration/user-management/user-management-with-the-api/provision-users-to-organizations-using-the-api.md): How to provision SSO users to Snyk Organizations and grant permissions before they log in, using the API
- [Update member roles using the API](https://docs.snyk.io/platform-administration/user-management/user-management-with-the-api/update-member-roles-using-the-api.md): How to migrate Snyk members to new roles using the API, with recommended bounded concurrency
- [Remove members from Groups and Orgs using the API](https://docs.snyk.io/platform-administration/user-management/user-management-with-the-api/remove-members-from-groups-and-orgs-using-the-api.md): How to remove members from Snyk Groups and Organizations programmatically using the API
- [Retrieve audit logs of user-initiated activity by API for an Org or Group](https://docs.snyk.io/platform-administration/user-management/user-management-with-the-api/retrieve-audit-logs-of-user-initiated-activity-by-api-for-an-org-or-group.md): How to retrieve audit logs of user activity for a Snyk Organization or Group through the API, available on Enterprise plans
- [Single Sign-On (SSO) for authentication to Snyk](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk.md): How Snyk supports Single Sign-On (SSO) authentication through your company identity provider, available on Enterprise plans
- [Choose a provisioning option](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/choose-a-provisioning-option.md): How to choose a Snyk SSO provisioning option that controls how new users in your company gain access
- [Set up Snyk Single Sign-On (SSO)](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/set-up-snyk-single-sign-on-sso.md): How to set up Snyk SSO with your existing identity provider, including the information needed to establish trust
- [Configure Self-Serve Single Sign-On (SSO)](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/configure-self-serve-single-sign-on-sso.md): How Group Admins on Enterprise plans configure Self-Serve SSO with SAML for Snyk
- [Okta SAML application setup](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/configure-self-serve-single-sign-on-sso/okta-saml-application-setup.md): How to set up an Okta SAML application and connect it to Snyk for SSO
- [Entra ID Enterprise application setup](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/configure-self-serve-single-sign-on-sso/azure-ad-enterprise-application-setup.md): How to set up an Entra ID (formerly Azure AD) Enterprise Application and connect it to Snyk for SSO
- [Ping Identity setup](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/configure-self-serve-single-sign-on-sso/ping-identity-setup.md): How to set up a Ping Identity application and connect it to Snyk for SSO
- [Google Workspace setup](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/configure-self-serve-single-sign-on-sso/google-workspace-setup.md): How to set up a Google Workspace SAML application and connect it to Snyk for SSO
- [OneLogin SAML Application setup](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/configure-self-serve-single-sign-on-sso/onelogin-saml-application-setup.md): How to set up a OneLogin SAML application and connect it to Snyk for SSO
- [Custom mapping](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping.md): How Snyk custom mapping dynamically assigns users to Groups and Organizations based on identity provider data
- [Legacy custom mapping](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/legacy-custom-mapping.md): How to configure Snyk legacy custom mapping using role patterns in SAML attributes or OIDC claims
- [Examples: setting up custom mapping for IdPs](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps.md): Examples of setting up Snyk custom mapping for identity providers such as Okta, Entra ID, and Google Workspace
- [Example: setting up custom mapping for Okta](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-okta.md): Example of setting up Snyk custom mapping for Okta roles using legacy custom mapping
- [Example: setting up custom mapping for Entra ID](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-entra-id.md): Example of configuring Snyk custom mapping of roles for Entra ID (formerly Azure AD)
- [Example: setting up custom mapping for Ping Identity](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-ping-identity.md): Example of configuring Snyk custom mapping of roles for Ping Identity using legacy custom mapping
- [Example: setting up custom mapping for Google Workspace](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-google-workspace.md): Example of mapping Snyk roles for a Google Workspace custom SAML connection
- [Example: setting up custom mapping for an Okta OIDC app](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-an-okta-oidc-app.md): Example of setting up a Snyk custom mapping integration for an Okta OIDC application
- [Example: setting up custom mapping for OneLogin](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-onelogin.md): Example of configuring Snyk user roles after setting up OneLogin SSO
- [Identity Provider (IdP) migration](https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/identity-provider-idp-migration.md): How to migrate Snyk SSO from a legacy identity provider to a new one by submitting new IdP metadata


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.snyk.io/platform-administration/user-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
