linear-enterprise-rbac
Manage Linear security permissions, SSO, and SCIM provisioning for enterprise compliance.
Install
mkdir -p .claude/skills/linear-enterprise-rbac && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4693" && unzip -o skill.zip -d .claude/skills/linear-enterprise-rbac && rm skill.zipInstalls to .claude/skills/linear-enterprise-rbac
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Implement enterprise role-based access control with Linear.Key capabilities
- →Implement role-based access control for integrations
- →Map application roles to Linear OAuth scopes
- →Configure SAML SSO for enterprise access
- →Provision users via SCIM
- →Audit user permission levels and actions
How it works
The skill provides patterns for mapping application-level roles to Linear OAuth scopes and configuring enterprise security features like SAML and SCIM.
Inputs & outputs
When to use linear-enterprise-rbac
- →Configure team-based access control
- →Map user roles to OAuth scopes
- →Implement SAML SSO settings
- →Audit user permission levels
About this skill
Linear Enterprise Access Governance
Overview
Model access from the workspace's actual plan, roles, teams, OAuth actor, and identity-provider ownership instead of inventing application-side Linear roles.
Prerequisites
- The target repository, Linear workspace, environment, and accountable owner
- Current security, privacy, compliance, capacity, and change-control requirements
- An approved Linear credential only when a bounded live verification is necessary
Tool Discipline
Use Read, Glob, and Grep to inspect code, configuration, and evidence. Use WebFetch only for current first-party Linear documentation and package metadata. Use Write or Edit only for requested implementation with known target files. Never write credentials, customer content, unrestricted environment output, or unredacted GraphQL variables.
Current Contract
- Workspace Owner exists only on Enterprise; Team Owner exists on Business and Enterprise; Free-plan users are admins.
- SCIM 2.0 is an Enterprise capability. Linear supplies the base connector URL and bearer token in security settings; do not hard-code a guessed endpoint.
- SCIM group push can map groups one-to-one to teams, and special
linear-owners,linear-admins, andlinear-guestsgroups control roles. - Enterprise audit logs retain 90 days of events and are accessible only to workspace owners.
Authentication
Use a personal API key only for owner-controlled scripts, OAuth with PKCE for user-delegated applications, or an enabled client-credentials grant for approved automation. Personal keys use Authorization: <API_KEY>; OAuth tokens use Authorization: Bearer <ACCESS_TOKEN>. Store credentials server-side in an approved secret manager.
Treat app approval, team access, scope changes, credential creation, rotation, revocation, and production access as owner-approved actions.
Instructions
- Confirm plan, workspace owners, admins, team owners, members, guests, private teams, and existing SCIM ownership.
- Map each application action to the narrowest OAuth scopes and team access; do not derive authorization from UI role labels alone.
- Review identity-provider group mappings, default public teams, guest exceptions, suspension, and break-glass ownership.
- Test create, update, suspend, unsuspend, group removal, and disconnect behavior in a non-production identity set.
- Configure audit queries or streaming with redaction, retention, and SIEM ownership appropriate to the signed policy.
- Produce a least-privilege matrix and a separately approved rollout/rollback plan.
Approval Boundaries
Do not create, reveal, rotate, or revoke credentials; authorize an OAuth app; change scopes or team access; create, mutate, archive, or delete workspace data; configure or re-enable webhooks; import or export data; change roles, SCIM, or audit streaming; transmit diagnostics; change paid entitlements; or perform another production mutation without explicit approval from the accountable owner. Keep diagnosis read-only unless implementation was requested.
Output
Return the workspace and team scope, auth mode without credential value, files and contracts inspected, exact operation names, evidence collected, validation result, sensitive fields redacted, remaining risk, accountable owner, approval state, and rollback or next action.
Error Handling
| Condition | Response |
|---|---|
| Plan capability unavailable | Do not emulate SCIM or audit-log guarantees; escalate the entitlement decision. |
| Conflicting SCIM groups | Resolve push order and role ownership before changing memberships. |
| Guest data exposure risk | Review connected integrations and team visibility before enabling access. |
| Break-glass path absent | Do not make the IdP authoritative until recovery ownership is tested. |
Examples
Use a compact handoff that makes scope, mutation authority, and verification evidence reviewable.
Input:
plan=enterprise; idp=okta; groups=owners,admins,guests,teams; audit=siem
Expected handoff:
role-map=reviewed; scim-url=workspace-supplied; rollout=approval-pending
Resources
When not to use it
- →When using a plan below Business or Enterprise for SSO/SCIM
- →When user lacks admin access for configuration
Prerequisites
Limitations
- →Guest role is read-only
- →Requires Business or Enterprise plan for SSO/SCIM
How it compares
It enables programmatic enforcement of enterprise-grade access control and auditing rather than relying solely on manual UI settings.
Compared to similar skills
linear-enterprise-rbac side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| linear-enterprise-rbac (this skill) | 1 | 2mo | Review | Advanced |
| 1password | 27 | 4mo | Review | Intermediate |
| security-compliance | 19 | 9mo | Review | Advanced |
| information-security-manager-iso27001 | 11 | 9mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
security-compliance
davila7
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.
information-security-manager-iso27001
davila7
Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS implementation, cybersecurity risk assessment, security controls management, and compliance oversight. Use for ISMS design, security risk assessments, control implementation, and ISO 27001 certification activities.
cursor-sso-integration
jeremylongshore
Configure SSO and enterprise authentication in Cursor. Triggers on "cursor sso", "cursor saml", "cursor oauth", "enterprise cursor auth", "cursor okta". Use when working with cursor sso integration functionality. Trigger with phrases like "cursor sso integration", "cursor integration", "cursor".
springboot-security
affaan-m
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
django-security
affaan-m
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.