Prompt Details
Model
Chat - (gpt-5.6)
Token size
367
Example input
[FEATURE_IDEA]: Allow workspace admins to require SSO login for all members, with a grace period before password login is disabled
[USER_OR_PERSONA]: Workspace admin at a B2B SaaS company
[CONSTRAINTS]: Must support SAML first; grace period configurable 7–30 days; do not build SCIM in this release; must not lock out the last admin; web app only for v1
Example output
1. Epic Summary
Workspace admins need to require SSO so company security policy is enforced without accidental lockouts. Success: admin can enable SAML SSO requirement with a 7–30 day grace period; after the period, non-SSO password login is disabled for members while the last admin remains recoverable.
Non-goals (v1): SCIM provisioning, mobile-native enforcement flows, non-SAML IdPs.
2. User Stories
1. As a workspace admin, I want to connect a SAML SSO provider, so that members can sign in through our IdP.
2. As a workspace admin, I want to require SSO with a configurable grace period (7–30 days), so that the org can transition without an abrupt cutoff.
3. As a workspace admin, I want to see who has not yet completed SSO login during the grace period, so that I can nudge stragglers.
4. As a member, I want clear prompts to complete SSO before password login is disabled, so that I am not surprised by lockout.
5. As a workspace admin, I want protection so the last admin cannot be fully locked out, so that the workspace remains recoverable.
6. As a workspace admin, I want to disable SSO requirement if needed during the grace period, so that we can roll back a bad setup.
3. Acceptance Criteria
Story 2 — Require SSO + grace period
- Admin can set grace period between 7 and 30 days
- During grace period, password login still works with warning
- After grace period, password login is rejected for non-exempt users
- Attempting values outside 7–30 shows validation error
Story 5 — Last-admin protection
- System prevents actions that would leave zero recoverable admin access
- If policy would lock out last admin, admin sees a blocking error with explanation
4. Out of Scope
- SCIM
- Mobile app enforcement (web only v1)
- Non-SAML protocols
- Automatic user provisioning/deprovisioning beyond login method
5. Edge Cases & Risks
- IdP misconfiguration during grace period
- Users with multiple workspaces and mixed auth
- Clock/timezone boundary at grace period end
- Admin demotion while SSO enforcement is active
6. Open Questions
- Exact behavior for API tokens / service accounts during enforcement?
- Who is exempt besides “last admin” (break-glass accounts)?
- Email/notification copy and frequency for member nudges?
Get this prompt + 9 more with Select$14 first month, then $19/mo · Cancel anytime$14 first month · then $19/mo
View SelectBy purchasing this prompt, you agree to our terms of service
GPT-5.6
Turn a rough feature idea into backlog-ready user stories with testable acceptance criteria, out-of-scope boundaries, risks, and open questions—without inventing business rules you never stated.
Who it’s for:
Product managers, eng managers, founders, and delivery teams who need clarity before build.
How to use:
Fill three variables in ChatGPT, Claude, Gemini, or similar:
• [FEATURE_IDEA] — what you want to build
• [USER_OR_PERSONA] — who it’s for
• [CONSTRAINTS] — must/must-not etc
...more
Added 2 weeks ago
