releases.shpreview

SSO role-based access control ships

July 20, 2026ChangelogView original ↗
1 featureThis release1 featureNew capabilitiesAI-tallied from the release notes
From the original release noteView original ↗

SSO now supports role-based access control

You can now gate content by role when authenticating with SSO. Fern reads each user's roles from the token your identity provider issues, then applies the roles and viewers rules in your docs.yml. Previously, role-based access control was limited to JWT and OAuth.

To use it, assign roles through your WorkOS organization, either directly or by mapping your SSO/directory groups to roles.

Fetched July 20, 2026