Articles in this section

[Admin Guide] Using Dynamic Teams

Keep your Spekit teams in sync with your org automatically by defining rules that add and remove people based on their identity provider attributes. Instead of managing team membership by hand, you set rules once, and Spekit populates the team from your connected identity provider and keeps it current as people's details change. This guide covers how to add rules to a team, how rules combine, how membership stays in sync, and how to tell a dynamic team apart from a manual one.

 

ℹ️ Who this is for: Account Admins managing teams. Dynamic Teams uses attributes from your connected identity provider (IdP). To use custom attributes in your rules, they must be set up first, see Setting up Custom Attributes for Dynamic Teams.

 

1. What Dynamic Teams does

Dynamic Teams lets you define attribute-based rules that automatically add and remove users from a team, using the identity provider you already have connected. Once rules are set, you get more control over team membership without maintaining it manually, and membership updates on its own as your IdP data changes.

 

2. Add rules to a team

Rules are defined on the team itself.

  1. Open the create team or edit team screen in the Spekit Hub (Web App).
  2. Scroll to the section at the bottom for defining rules to automatically add users to the team.
  3. Choose an attribute from the dropdown. This list contains the attributes Spekit can pull from your identity provider, including default attributes and any custom attributes you have set up.
  4. Set the condition for that attribute, for example job title is or contains a specific word, or a particular management level.
  5. Save the team. The rules run and pull in any users from your identity provider who match.

 

3. How rules combine

You can build a single rule from a combination of conditions, and you can add multiple rules to widen who gets included.

  • Within a rule: conditions work together, for example job title contains "manager" and management level is a certain tier.
  • Across rules: multiple rules use OR logic. A user is added if they match any rule. For example, one rule for a specific job title, OR another rule for department name is "Marketing," so you can build a broader team like a full revenue team from several rules.

💡 Pro tip: Start with the narrowest rule that captures the core group, save, and check who came in before adding OR rules to widen it. It is easier to see the effect of each rule when you add them one at a time.

 

4. How membership stays in sync

Once rules are set, membership is not a one-time import. As information syncs from your identity provider on a regular basis through SCIM, changes in your system flow into Spekit and the team updates dynamically. When someone's attributes change so they no longer match, or newly match, the team membership reflects that automatically.

 

5. Reading the indicators

Spekit shows where a team's membership comes from, so you always know what you can and cannot manage by hand.

Indicator What it means
Lock icon on a team The team is managed through your IdP groups. You cannot manage its membership within Spekit.
Rules indicator on a team The team has dynamic rules configured. Hover to see the rules defined for it.
Indicator on a user On the users page, shows whether a person is on a team because someone added them manually, or because they matched a dynamic rule.

 

💡 Pro tip: When a user shows up on a team you did not expect, check the indicator on their user page before removing them. If a rule added them, removing them by hand will not stick, since the next sync will add them back. Adjust the rule instead.

 

Was this article helpful?
0 out of 0 found this helpful