16.5 Access Approval for New OAuth Users

Orbnetes deployment and release orchestration documentation for operators and platform teams.

OAuth login can be integrated with controlled onboarding.

Recommended onboarding model:

  1. User signs in via GitHub/GitLab OAuth.
  2. Account is created in pending state.
  3. Admin reviews and approves access.
  4. Admin assigns project/global permissions.
  5. User gains operational access according to assigned scope.

Why this matters:

  • prevents automatic unrestricted access from external identity provider,
  • enforces explicit onboarding governance,
  • ensures each new user is permissioned intentionally.

Operational notes:

  • pending users should not execute sensitive actions,
  • approval process should include role/permission assignment before activation,
  • maintain clear admin workflow for reviewing pending users.