When a team uses multiple SAML IdPs (one per ingress domain) in a multi-ingress
setup, users can now authenticate via any of the team's IdPs even if their
account was originally provisioned under a different one. Spar resolves the
correct account by email-based NameID lookup across all team IdPs and migrates
the user's SSO identity to the authenticating IdP transparently.

**Important:** Email addresses (`NameID`s) must be unique across configured
IdPs! Otherwise, users may be logged into wrong accounts!

Please refer to the documentation for further information.
