Hi mbelarde. I'd appreciate you not pulling Cody or Valentijn into this. They work incredibly hard for this community, and I'm the one who made the decision. The full details are in DefectDojo v3 - A New Chapter for the OWASP Edition.pdf.
We held office hours discussing different avenues before settling on this route, I've done my best to be clear and transparent about the why, and the move has drastically helped the economics. I empathize with your frustration, but no one offered up a reasonable alternative, and I believe that's because one doesn't exist: if the conversion metrics aren't sustainable, there aren't other viable options.
We did weigh the other paths. If we stopped supporting the Jira integration instead, that would hit small teams hardest. If we stopped supporting deduplication or auto-triage via reimport, both would impact far more of the community. Everything else we looked at had the same problem. Choosing not to support RBAC and SSO in v3 was the option that affected the fewest users while also making the platform easier to maintain: supporting integrations with identity systems we don't control or have access to is resource intensive.
We offer a free tier of Pro to non-enterprise teams that qualify. It gives the community cross-tool deduplication, root cause analysis with correlation, threat intel, reachability, auto-remediation, a new UI, astronomical performance gains, the list goes on.
I made these changes so that Dojo is still here years from now. A sustainable company is what funds the platform, the OSS edition included.
You're welcome to stay on v2. It's still available and accessible, and everything you're running today keeps working as it always has. The reasons SSO didn't carry into v3 are laid out in the letter.