SAML2 authentication - Just in Time Provisioning not working

I tried blowing away everything and re-creating the containers; the issue still persists.

I’ve also tried inviting myself using my email address. I receive the email; clicking the link takes me to a page telling me that I “may create an account by authenticating with the organizations [sic] SSO provider”. Clicking the Join with SAML2 button takes my to our IdP login; after logging in, I’m logged into Sentry as the super-user.