On TrendMiner side the all SAML groups are bundled under the SSO name. So in my example “SAML-Azure” contains all groups from that provider. So in your case it would contain all 80 SAML groups. So if you add the complete top level group there is no need to add all 80 groups separately per data source, nor is it required to create a new group on you server.
SAML-CS-3 in my example is a second SSO connection which might be a bit less common and therefor maybe somewhat confusing here.
About your other questions:
- yes, demo tag permissions are hardcoded.
- system admins will always have permissions to all data sources by default (since they can access ConfigHub and assign permissions to themselves anyway). For all other users explicit permissions are required indeed.
The ‘public’ option is a nice idea. Feel free to share it with our product team:
But that being said, the ‘public’ share can quite easily be simulated by assigning the permission to the full local group and all top level SAML groups like I shared above.