Managing groups
A group is a named list of people, and nothing more: it carries no permissions, which always come from a role. Other modules offer your groups as a way to scope who sees what.
- The Access Control module visible in your left-hand navigation.
- Permission to read and manage groups, granted on the Identity & Users · Group row of a role's permission matrix. Everyone can open Access Control, so a gap only shows when a request fails.
If Access Control isn't in your navigation, your role doesn't have visibility for it — ask a workspace administrator, or see Permissions and module visibility.
Steps
Select Access Control in the left-hand navigation, then Groups. The header search matches group names only.
Select Add Group, in the header of every Access Control page. Enter a Group Name of 2–100 characters, an optional Description, then Create.
Open the group from its name, or from Manage in the MEMBERS column. Under Manage Members, select Add Members, then find people with Search by user name or email and tick them. Each tick saves itself — there is no Save step.
Select Remove on their row, or tick rows and select Delete; Deselect All empties the group. All three apply at once, with no confirmation and no undo.
Select Edit Basic Details, then Update. To remove the group, use the delete icon in the ACTIONS column and confirm with Yes, Delete.
What success looks like
- Group created successfully! appears and the group is listed under Groups.
- The MEMBERS count matches the people you added.
- The group is offered wherever another module asks for Groups.
Groups and departments
Departments work identically — a name, a description, a list of members, no permissions. The difference is only what you call it: departments for how your organisation is arranged, groups for the teams that cut across it. Someone can belong to any number of both.
If something goes wrong
| Symptom | Likely cause | What to do |
|---|---|---|
| Access Forbidden replaces the whole module. | Your role cannot read, or cannot delete, groups. | Select Go Back, then ask for those permissions — see Roles. |
| A colleague is missing from Add Members. | The picker loads the first 100 users and searches only those. | Add the group from their own record — see Managing users. |
| MEMBERS shows —. | That row's count could not be read. | Select Refresh List. |
| A module's visibility scope lost a group. | It was deleted; nothing warns you it is in use. | Create it again, then reselect it there. |
Next
- Departments — the same mechanics, a different label.
- Roles — where permissions come from.
- Managing users — set a person's groups from their record.