Role Inheritance by Security Group in SSO

Hi All, apologies if this is in the wrong place - feel free to move it.


I am planning new access control features and would like to assign roles within a SaaS application using dynamic security groups. I would like to know which role will take priority if a user is in more that one group.


For example in my application I have two roles, Admin user and Normal User, both assigned to the groups SaaS_Admin and SaaS_NormalUser. Bob is in the admin group and Sarah is in both. I know what role Bob will receive but what will Sarah get?

