Multi-tenant (each of my customers gets a fully separate directory, with access to all tenants for our admins)
SAML and OAuth (customers can set up SAML themselves via the SaaS interface, or we set the SP up for them)
Rule based group assignment based on SAML attribute evaluation (e.g. assign users to this group if the attribute X = Y)
APIs to manage users, groups, organisations (tenants)
We've built something using Okta, but all our customer users are in one Directory/Tenant.
Auth0 nearly gets there with Organisations but can't help with the sub-groups and rule based management.
For context, we have an education product and customers are districts or schools, and the sub-groups are typically schools and/or classes or groups of users (e.g. seniors or juniors).
We also need to support SAML Federations like InCommon, OpenAthens, UK Access Management Federation which makes the challenge harder (these federations want a single SP to which many IDPs authenticate) for Universities. None of the modern platforms support this.
If anyone has found an out of the box solution for this, I'd love to hear about it.