The user's application role is based on membership in the organizational groups and specific attributes in the SAML response. The organizational groups are managed in the organization’s Identity Provider. This is also where the users are added/created - on the Idp's end, rather than on Kaltura side.