Right now, I believe the user that gets created in the recovery Silo during rack setup gets the "fleet admin" role. That user should have the privilege to grant "fleet admin" to anybody else (including users/groups in other Silos), but they have no way of knowing the identity of a user or group in another Silo. (And it's not clear that they should. See #1340.)
However we do it, we want some way of having this user delegate "Fleet Admin" to users or groups in other Silos. That way operators don't need to use the recovery Silo (which bypasses their IdP) to manage the rack.
Right now, I believe the user that gets created in the recovery Silo during rack setup gets the "fleet admin" role. That user should have the privilege to grant "fleet admin" to anybody else (including users/groups in other Silos), but they have no way of knowing the identity of a user or group in another Silo. (And it's not clear that they should. See #1340.)
However we do it, we want some way of having this user delegate "Fleet Admin" to users or groups in other Silos. That way operators don't need to use the recovery Silo (which bypasses their IdP) to manage the rack.