If user identity is important to your application, you need a way to manage it. Usually this means user accounts, and you create them when someone signs up.
But allowing employees to sign up for whatever SaaS app strikes their fancy is a management nightmare. So organizations like ways to control which users exist (or do not exist) in your app.
For that you need roles, or groups, which, like the users, come from the organization's identity provider - Entra, Google, Okta, etc. Groups form the basis of Firezone's access model. They determine who can access what.
The process of getting users and groups into your app is called directory sync, and it's surprisingly tricky to do well. In this post we'll cover what directory sync is exactly, the leading standard for implementing it, and why we opted to forgo it entirely to build our own engine from scratch.






