GLAM
Externals
External organizations (customers and partners) under openxchange/external: their accounts and the projects shared with them.
How external access works
- Create the group here. GLAM creates openxchange/external/<slug> with a SAML group link external-<slug> at the role you choose - the maximum permission everyone entering through the LDAP group gets. The slug is the group URL and the LDAP contract; the display name is free-form and can differ.
- File the IT ticket. Ask internal IT at oox.io/help to create the LDAP group external-<slug> and add the external's accounts to it. The LDAP group name always follows the URL slug, never the display name.
- Accounts appear on first sign-in. The SAML link maps the LDAP group into GitLab membership when each person first logs in; until then the group looks empty here. Send the external's users the sign-in instructions below so they know how.
- Share projects or groups from the external's page. GLAM handles the share_with_group_lock unlock on locked ancestors and records every unlock in the audit log. Unshare from the same place to offboard.
Sign-in instructions for external users
Send this to the external's users once their LDAP group exists. Their accounts are created on first sign-in through the group SSO link:
https://gitlab.com/groups/openxchange/-/saml/sso?token=P1nBqh-3
- Open the link and click the sign-in button; you'll land on the Open-Xchange login page.
- Sign in with the Open-Xchange SSO credentials provided by your Open-Xchange contact.
- GitLab creates a GitLab.com account linked to your SSO identity - follow the prompts (confirm your email, accept a username).
- You now see the projects shared with your organization. Bookmark the link: it also refreshes an expired SSO session.
Users who already have a GitLab.com account with the same email should sign in to it first, then open the link to connect it to the SSO instead of creating a new account.