Governance Updates for Teams and Enterprise Workspaces
RunDiffusion is expanding governance capabilities with new controls for managing tool access and user provisioning across teams.
This update introduces role-based tool blocking and SCIM-based user provisioning, improving how organizations manage access and scale team operations.

Role-Based Tool Blocking
You can now configure each team role to control access to tools at a granular level.

- Block individual tools or entire model families
- Hidden tools are removed from the tool gallery
- Hidden tools do not appear in search results
- Hidden tools are removed from recent history
- Access can be tailored by role
Blocked tools are fully hidden from users assigned to that role.
Enterprise SSO with SCIM Provisioning
SCIM provisioning is now available for Enterprise plans, enabling automated user lifecycle management through your identity provider.

- Automatically create, update, and deactivate users
- Sync roles and team membership from identity provider groups
- Eliminate manual onboarding
- Ensure access aligns with your organization’s directory
- Immediate deprovisioning when users are removed
Documentation Updates
Enterprise SSO and User Provisioning on RunDiffusion | RunDiffusion
Learn how Enterprise SSO user provisioning on RunDiffusion uses SCIM 2.0 to sync users, teams, and roles from your identity provider.

Team Roles in RunDiffusion: Guide to Permissions and Controls | RunDiffusion
Learn what each Team Role option does in RunDiffusion, including token cooldown, generation permissions, and Open-Source App access.

Company Roles in RunDiffusion: Guide to Company Administrator Permissions | RunDiffusion
Learn how Company Roles work in RunDiffusion, including Account Owner, Report Analyst, and company-level admin permissions.
