When Single Sign-On (SSO) is enabled in Observe, users may not appear in their assigned “groups” within Workspace Settings, even though group mappings are configured correctly in the Identity Provider (IdP) and SAML assertions.
This behavior occurs because Observe relies on SAML authentication to populate group memberships. Users are not automatically assigned to their respective groups in Workspace Settings until they successfully log in via SAML.
If a user previously had a local account, they must log out and log back in through SAML to be assigned to the correct SAML group. Group assignments are dynamically synced during the SSO login process, based on the groups attribute sent in the SAML response from the IdP.