Multiple SSO connections per Organization; multi-directory provisioning
An Organization can now have more than one SAML or OIDC enterprise connection, removing the organization_already_has_sso_connection error, and each connection can have its own directory. Clerk tracks each directory's view of a user separately: a user stays active while at least one enabled directory reports them active, and memberships are only deleted when no directory grants them anymore.