Create users and assign per-module access. You can only grant modules your workspace is entitled to.
Single sign-on
Let your users sign in with your own identity provider (Google, Microsoft, or any OIDC). Federation only answers "who is this user" — roles and module access stay managed here.
Add an identity provider