Skip to content

MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support#9105

Open
pvev wants to merge 1 commit into
v11.10-documentationfrom
MM-69100-team-abac-membership-docs
Open

MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support#9105
pvev wants to merge 1 commit into
v11.10-documentationfrom
MM-69100-team-abac-membership-docs

Conversation

@pvev

@pvev pvev commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Summary

Documents the Team Membership ABAC feature (PR #37054 / MM-69100) and updates the existing ABAC docs to reflect that policies can now be assigned to teams, not just channels.

What's included

New pageabac-team-membership.rst:

  • Advisory (public) vs strict (private) enforcement model, keyed on allow_open_invite
  • Prerequisites + feature-flag behavior matrix (what changes when
    EnableAttributeBasedAccessControl / TeamMembershipAccessControl are off)
  • System Admin config: policy assignment, custom rules, both auto-add checkboxes, sync
    footer, Membership sync jobs Teams tab
  • Team Admin config: Team Membership tab, system-policy banner, custom rules, auto-add,
    test matching users, save confirmation, self-exclusion block, sync footer
  • End-user surfaces: Browse Teams (hidden / Recommended chip), Invite modal, Add Members
    admin flow, Team Members modal, removal/auto-add DMs
  • Policy inheritance, sync execution order, mass-removal guardrail, group-sync mutual
    exclusivity
  • Troubleshooting FAQ

Access tab UI change (all deployments): Prominently documents that the "Allow any
user to join" checkbox is permanently replaced by Public/Private selection cards on
every team, regardless of ABAC or license. The cards control the single
allow_open_invite field (same field the checkbox did); type is intentionally left
untouched.

Updated pages:

  • attribute-based-access-control.rst — toctree entry, team policy type, deduped roles
    lists
  • abac-system-wide-policies.rst — "Assign policies to teams" section; delete now
    requires 0 channels and 0 teams
  • abac-team-channel-policies.rst — "Membership Policies" tab renamed to "Channel
    Membership"; disambiguation note vs. the new Team Membership tab

Ticket Link

https://mattermost.atlassian.net/browse/MM-69100

@github-actions

Copy link
Copy Markdown
Contributor

Newest code from mattermost has been published to preview environment for Git SHA 75b10e9

@amyblais amyblais added this to the v11.10.0 milestone Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants