MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support - #9105
Conversation
…ABAC pages for team support
|
Newest code from mattermost has been published to preview environment for Git SHA 75b10e9 |
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Newest code from mattermost has been published to preview environment for Git SHA 20fe15f |
📝 WalkthroughWalkthroughThe administration guide documents team membership ABAC, separates it from channel membership policies, and updates system-wide policy assignment, enforcement, administration workflows, synchronization, troubleshooting, and policy deletion guidance. ChangesABAC administration guidance
Estimated code review effort: 3 (Moderate) | ~20 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@source/administration-guide/manage/admin/abac-system-wide-policies.rst`:
- Around line 118-125: Update the team-assignment procedure around the
Membership Policy section to state that administrators must first enable “Manage
membership with attribute based membership policies” for the team, and that
group-synced teams cannot use this control. Describe the required setting
sequence before instructing them to link an existing policy, or link directly to
the complete procedure in the team membership access policies documentation.
In `@source/administration-guide/manage/admin/abac-team-membership.rst`:
- Around line 124-129: Update the “Join gate (private teams)” and “Browse Teams
filter” cells in the ABAC-disabled row to describe standard private-team
behavior: joining remains invite-only, and visibility remains restricted to
members. Do not imply that disabling ABAC makes private teams open or visible to
everyone.
- Around line 25-27: The documentation’s universal claims about the Access tab
omit the exception for LDAP/AD group-synced teams. Update the important notice
and the related statements around the Public Team and Private Team cards to
limit them to non-group-synced teams or explicitly state that group-synced teams
display the static message described near the group-sync guidance.
- Line 434: Update the synchronization timing references in the admin guide,
including the team and channel membership scheduler descriptions, to use
AccessControlSettings.SyncJobIntervalSeconds and state a maximum wait of 60
minutes. Replace the outdated 30-minute references while preserving the
documented 3600-second default and shared scheduling behavior.
In `@source/administration-guide/manage/admin/attribute-based-access-control.rst`:
- Line 19: Update the authorization claim in the paragraph to accurately reflect
strict enforcement: replace the statement that only authorized users can access
Mattermost channels and teams with wording that strict policies can manage
access, or explicitly scope the claim to private channels and teams. Preserve
the surrounding explanation about security, compliance, and manual role
adjustments.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 44109363-c136-4816-9d51-52f4af12ccc4
📒 Files selected for processing (4)
source/administration-guide/manage/admin/abac-system-wide-policies.rstsource/administration-guide/manage/admin/abac-team-channel-policies.rstsource/administration-guide/manage/admin/abac-team-membership.rstsource/administration-guide/manage/admin/attribute-based-access-control.rst
|
Newest code from mattermost has been published to preview environment for Git SHA 9b20a4e |
Thank you! |
|
Thanks for the thorough updates, @pvev! One small consistency point: the Channel Membership page says scheduled sync runs every 30 minutes, while the Team Membership page says the default is 60 minutes. Could we align those values? Otherwise, this looks good to approve to me from an Editor perspective. Is there a dev you can tag for the dev review on this as well? |
|
Newest code from mattermost has been published to preview environment for Git SHA b64cbaa |
Good catch, thanks @Combs7th . Both schedulers are built from the same interval, so they've never actually differed. It used to be a hardcoded hour and is now configurable via AccessControlSettings.SyncJobIntervalSeconds (default 3600s). The "30 minutes" figure didn't match the old behaviour either, so I updated abac-channel-access-rules.rst and abac-team-channel-policies.rst to say 60 minutes and name the setting. All four ABAC pages are consistent now. |
davidkrauser
left a comment
There was a problem hiding this comment.
Looks good to me - thanks for keeping these up to date.
| - **Permission policies** (managed by System Admins): Attribute-based restrictions on user actions such as file upload and file download. See :ref:`Permission policies <administration-guide/manage/admin/abac-system-wide-policies:permission policies>`. | ||
| - **Team-scoped membership policies** (managed by Team Admins): Channel membership policies that Team Admins can create, edit, and delete directly from Team Settings for channels in their team. See :ref:`Manage team-scoped membership policies in Team Settings <administration-guide/manage/admin/abac-channel-access-rules:manage team-scoped membership policies in team settings>`. | ||
| - **Team membership policies** (managed by System Admins and Team Admins): Attribute-based rules that control who can join a team. On private teams, rules gate directory visibility, join evaluation, and removal at sync (strict mode). On public teams, rules drive a "Recommended" tag and optional auto-add without restricting access (advisory mode). See :doc:`Team membership access policies </administration-guide/manage/admin/abac-team-membership>`. | ||
| - **Team-scoped channel membership policies** (managed by Team Admins): Channel membership policies that Team Admins can create, edit, and delete directly from the Channel Membership tab in Team Settings for channels in their team. See :doc:`Team-level channel membership policies </administration-guide/manage/admin/abac-team-channel-policies>`. |
There was a problem hiding this comment.
Team-scoped channel membership policies - lol, that's a mouthful.
|
Newest code from mattermost has been published to preview environment for Git SHA b64cbaa |
|
@pvev - I think this one's good to merge now? |
@pvev was this included in this PR? It seems this is focused on the ABAC pages but we should include that update in the team settings docs here https://docs.mattermost.com/end-user-guide/collaborate/team-settings.html#access-settings |
* conf * v11.10.0 Changelog (#9100) * docs: add changelog for v11.0.0 * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Add link * Update mattermost-v11-changelog.md --------- Co-authored-by: Changelog Bot <changelog-bot@mattermost.com> Co-authored-by: Amy Blais <29708087+amyblais@users.noreply.github.com> * v11.10 upgrade notes (#9102) * Update docs for v11.10 feature release Add the v11.10 (2026-08-14) feature release across server releases, deployment guides, desktop compatibility, release policy timeline, and open source components. Co-authored-by: Amy Blais <29708087+amyblais@users.noreply.github.com> Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Update important-upgrade-notes.rst * Add v11.10 User Interface entries to UI & ADA changelog * Update ui-ada-changelog.rst * Update important-upgrade-notes.rst * Update open-source-components.rst * Update mattermost-desktop-releases.md * Update software-hardware-requirements.rst * Update release-policy.md * Update source/product-overview/ui-ada-changelog.rst Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update software-hardware-requirements.rst * Update software-hardware-requirements.rst * Update ui-ada-changelog.rst * Update ESR support snippet to reflect v10.11 ESR has reached end of life * Update ESR support snippet to reflect v10.11 ESR has reached end of life * Update ESR support snippet to reflect v10.11 ESR has reached end of life * Update ESR support note to reflect v10.11 ESR has reached end of life * Update ESR lifecycle content to reflect v10.11 ESR has reached end of life * Fix corrupted null-escape sequences in troubleshooting section * Update release-policy.md * Move v10 changelog into unsupported legacy releases v10 has reached end of support, so its changelog content is merged into unsupported-legacy-releases.md alongside v9/v8/v7, following the existing pattern for retired major versions. Updates all cross-references (version archive, release policy, redirects, kubernetes HA upgrade doc, changelog filter script, and the changelog-automation file list) to point at the new location, and removes the standalone v10 changelog page and its toctree/index entries. * Revert "Move v10 changelog into unsupported legacy releases" This reverts commit 5049eb4. * Update release-policy.md * Update release-policy.md * Update ui-ada-changelog.rst * Update software-hardware-requirements.rst * Update mattermost-server-releases.md * Update release-policy.md * Update release-policy.md * Update prepare-to-upgrade-mattermost.rst * Update common-esr-support-rst.rst * Update common-esr-support-upgrade.md * Update common-esr-support.md * Update mattermost-desktop-releases.md * Revert ESR end-of-life wording change on 4 pages Reverts the v10.11 support-status note back to "coming to the end of its life cycle... is recommended" across common-esr-support-rst.rst, common-esr-support-upgrade.md, common-esr-support.md, and the "Upgrade to Mattermost v6.0" note in prepare-to-upgrade-mattermost.rst. * Update mattermost-desktop-releases.md * Update mattermost-server-releases.md * Revert mattermost-desktop-releases.md changes Removes the v11.10 compatibility entry added to the v6.2 desktop app row. * Update release-policy.md * Update release-policy.md * Update release-policy.md * Revert unrelated backtick/escape fix in prepare-to-upgrade-mattermost.rst This change was out of scope for the v11.10 upgrade notes update; removing it to keep the PR focused. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update version-archive.rst (#9134) * Update software-hardware-requirements.rst * Update release-policy.md * MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support (#9105) * MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support * Correct team membership ABAC docs to match current behaviour * Address review feedback on team membership ABAC docs * Align channel ABAC sync interval with the configurable default --------- Co-authored-by: changelog-automation-docs[bot] <278388344+changelog-automation-docs[bot]@users.noreply.github.com> Co-authored-by: Changelog Bot <changelog-bot@mattermost.com> Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Pablo Vélez <pablovv2012@gmail.com>
#9145) * conf * v11.10.0 Changelog (#9100) * docs: add changelog for v11.0.0 * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Update mattermost-v11-changelog.md * Add link * Update mattermost-v11-changelog.md --------- Co-authored-by: Changelog Bot <changelog-bot@mattermost.com> Co-authored-by: Amy Blais <29708087+amyblais@users.noreply.github.com> * v11.10 upgrade notes (#9102) * Update docs for v11.10 feature release Add the v11.10 (2026-08-14) feature release across server releases, deployment guides, desktop compatibility, release policy timeline, and open source components. Co-authored-by: Amy Blais <29708087+amyblais@users.noreply.github.com> Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Update important-upgrade-notes.rst * Add v11.10 User Interface entries to UI & ADA changelog * Update ui-ada-changelog.rst * Update important-upgrade-notes.rst * Update open-source-components.rst * Update mattermost-desktop-releases.md * Update software-hardware-requirements.rst * Update release-policy.md * Update source/product-overview/ui-ada-changelog.rst Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update software-hardware-requirements.rst * Update software-hardware-requirements.rst * Update ui-ada-changelog.rst * Update ESR support snippet to reflect v10.11 ESR has reached end of life * Update ESR support snippet to reflect v10.11 ESR has reached end of life * Update ESR support snippet to reflect v10.11 ESR has reached end of life * Update ESR support note to reflect v10.11 ESR has reached end of life * Update ESR lifecycle content to reflect v10.11 ESR has reached end of life * Fix corrupted null-escape sequences in troubleshooting section * Update release-policy.md * Move v10 changelog into unsupported legacy releases v10 has reached end of support, so its changelog content is merged into unsupported-legacy-releases.md alongside v9/v8/v7, following the existing pattern for retired major versions. Updates all cross-references (version archive, release policy, redirects, kubernetes HA upgrade doc, changelog filter script, and the changelog-automation file list) to point at the new location, and removes the standalone v10 changelog page and its toctree/index entries. * Revert "Move v10 changelog into unsupported legacy releases" This reverts commit 5049eb4. * Update release-policy.md * Update release-policy.md * Update ui-ada-changelog.rst * Update software-hardware-requirements.rst * Update mattermost-server-releases.md * Update release-policy.md * Update release-policy.md * Update prepare-to-upgrade-mattermost.rst * Update common-esr-support-rst.rst * Update common-esr-support-upgrade.md * Update common-esr-support.md * Update mattermost-desktop-releases.md * Revert ESR end-of-life wording change on 4 pages Reverts the v10.11 support-status note back to "coming to the end of its life cycle... is recommended" across common-esr-support-rst.rst, common-esr-support-upgrade.md, common-esr-support.md, and the "Upgrade to Mattermost v6.0" note in prepare-to-upgrade-mattermost.rst. * Update mattermost-desktop-releases.md * Update mattermost-server-releases.md * Revert mattermost-desktop-releases.md changes Removes the v11.10 compatibility entry added to the v6.2 desktop app row. * Update release-policy.md * Update release-policy.md * Update release-policy.md * Revert unrelated backtick/escape fix in prepare-to-upgrade-mattermost.rst This change was out of scope for the v11.10 upgrade notes update; removing it to keep the PR focused. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> * Update version-archive.rst (#9134) * Update software-hardware-requirements.rst * Update release-policy.md * MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support (#9105) * MM-69100 - Add team membership ABAC documentation and update channel ABAC pages for team support * Correct team membership ABAC docs to match current behaviour * Address review feedback on team membership ABAC docs * Align channel ABAC sync interval with the configurable default * Update team settings docs for Public/Private cards and membership tab rename * Clarify advisory vs enforced ABAC behavior and public team join restrictions * Note that team admins can manage team membership rules from Team Settings --------- Co-authored-by: Amy Blais <29708087+amyblais@users.noreply.github.com> Co-authored-by: changelog-automation-docs[bot] <278388344+changelog-automation-docs[bot]@users.noreply.github.com> Co-authored-by: Changelog Bot <changelog-bot@mattermost.com> Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
…
Summary
Documents the Team Membership ABAC feature (PR #37054 / MM-69100) and updates the existing ABAC docs to reflect that policies can now be assigned to teams, not just channels.
What's included
New page —
abac-team-membership.rst:allow_open_inviteEnableAttributeBasedAccessControl/TeamMembershipAccessControlare off)footer, Membership sync jobs Teams tab
test matching users, save confirmation, self-exclusion block, sync footer
admin flow, Team Members modal, removal/auto-add DMs
exclusivity
Access tab UI change (all deployments): Prominently documents that the "Allow any
user to join" checkbox is permanently replaced by Public/Private selection cards on
every team, regardless of ABAC or license. The cards control the single
allow_open_invitefield (same field the checkbox did);typeis intentionally leftuntouched.
Updated pages:
attribute-based-access-control.rst— toctree entry, team policy type, deduped roleslists
abac-system-wide-policies.rst— "Assign policies to teams" section; delete nowrequires 0 channels and 0 teams
abac-team-channel-policies.rst— "Membership Policies" tab renamed to "ChannelMembership"; disambiguation note vs. the new Team Membership tab
Ticket Link
https://mattermost.atlassian.net/browse/MM-69100