Hi! I’m work with Uri, just dropping my thoughts and our needs:
SSO - either with SAML or OIDC - we use Okta so it covered by both. The main goal is to offload the identity management to our external instance.
Provisioning - really optional but nice to have, in order to have users created/removed by the identity provider.
Alternatively, if SSO and full external auth is not available, just having a way to limit user domains per workspace would be a great start - so we can use Login with Google and then scope it to our domain. In addition, having API to manage users would be great, so we can do our own thing for provisioning to sync user access.