This is really cool. As someone who's moved a very large SaaS product to a Customer IAM SaaS vendor the missing piece is typically user authorization. Currently the identity of who the user is is owned by the SaaS where's the RBAC and groups are maintained application side.
This type of thing could be really useful but I wonder how hard it will be to generalize the problem.