I think SAML is okay for large organisations with lots of integration with third parties, but you need a well architected AND documented environment. JFDI doesn't work well when it comes to infrastructure and security…

//