Skip to content

MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support#9105

Open
pvev wants to merge 1 commit into
v11.10-documentationfrom
MM-69100-team-abac-membership-docs
Open

MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support#9105
pvev wants to merge 1 commit into
v11.10-documentationfrom
MM-69100-team-abac-membership-docs

Conversation

@pvev

@pvev pvev commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Summary

Documents the Team Membership ABAC feature (PR #37054 / MM-69100) and updates the existing ABAC docs to reflect that policies can now be assigned to teams, not just channels.

What's included

New pageabac-team-membership.rst:

  • Advisory (public) vs strict (private) enforcement model, keyed on allow_open_invite
  • Prerequisites + feature-flag behavior matrix (what changes when
    EnableAttributeBasedAccessControl / TeamMembershipAccessControl are off)
  • System Admin config: policy assignment, custom rules, both auto-add checkboxes, sync
    footer, Membership sync jobs Teams tab
  • Team Admin config: Team Membership tab, system-policy banner, custom rules, auto-add,
    test matching users, save confirmation, self-exclusion block, sync footer
  • End-user surfaces: Browse Teams (hidden / Recommended chip), Invite modal, Add Members
    admin flow, Team Members modal, removal/auto-add DMs
  • Policy inheritance, sync execution order, mass-removal guardrail, group-sync mutual
    exclusivity
  • Troubleshooting FAQ

Access tab UI change (all deployments): Prominently documents that the "Allow any
user to join" checkbox is permanently replaced by Public/Private selection cards on
every team, regardless of ABAC or license. The cards control the single
allow_open_invite field (same field the checkbox did); type is intentionally left
untouched.

Updated pages:

  • attribute-based-access-control.rst — toctree entry, team policy type, deduped roles
    lists
  • abac-system-wide-policies.rst — "Assign policies to teams" section; delete now
    requires 0 channels and 0 teams
  • abac-team-channel-policies.rst — "Membership Policies" tab renamed to "Channel
    Membership"; disambiguation note vs. the new Team Membership tab

Ticket Link

https://mattermost.atlassian.net/browse/MM-69100

@github-actions

Copy link
Copy Markdown
Contributor

Newest code from mattermost has been published to preview environment for Git SHA 75b10e9

@amyblais amyblais added this to the v11.10.0 milestone Jul 17, 2026
@esethna
esethna requested a review from Combs7th July 21, 2026 13:32
@amyblais amyblais added the 2: Editor Review Requires review by an editor label Jul 22, 2026 — with Claude
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

2: Editor Review Requires review by an editor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants