Use groups such as Helpdesk, Tier 3, HR or C Suite to manage access for a team. Choose which organizations members can access, explicitly exclude organizations, and use the same groups when granting access to records or folders.
Create a group
As an Admin, open Platform → Groups and select New group. The group editor opens in a drawer.
Enter a Group name, such as “Service desk”, and an optional Description.
Under Users, select the people who belong to the group.
Under Organizations → Allow, select the organizations the group should be able to access, or choose Grant access to all organizations.
Use Deny to exclude organizations. For “all organizations except these,” grant access to all organizations, then add the exceptions under Deny.
Under Blocked asset types, select types members must not access.
Review the summary and select Create.
Add all current users to this group adds the users who exist when you save. It does not automatically enroll future users. Review membership when new people join.
Understand how group access combines
A group does not replace a user's role. Roles control which actions a person can perform; organization scopes, blocked asset types and record or tag grants also affect access.
For account-wide roles, allowed organizations from the user's own scope and group memberships combine. An explicit organization denial takes precedence over an allow. Asset types blocked by a group remain blocked even if another group does not block them. Users with a single-organization role remain limited to their assigned organization scope.
Leaving an organization out of one group's Allow list is not the same as denying it: the user may have access through their own scope or another group. Use Deny when you intend an explicit exclusion.
A group can also be selected when granting access to a record or restricted tag. Membership can therefore affect access through those grants as well as organization scope. It does not automatically expose every private record. See Understand record, folder and tag access for those rules.
Organization tags are not access rules. Adding a tag to an organization does not restrict that organization or automatically restrict its records. Use the group’s organization settings for organization access, and restricted record tags/folders for access to particular records.
Find and edit a group
Use Search groups to find a group, then open it from the list. Update its name, description, users, allowed or denied organizations, and blocked asset types. Select Save to apply the changes.
Cancel leaves without saving; if prompted, choose Discard changes to abandon the draft. If saving fails, keep the drawer open and review the error. Check the saved membership and scopes before retrying, especially when several settings changed together.
Review warnings when your changes restrict your own user. An unavailable asset type can still be an existing exclusion; it stays blocked unless you deliberately remove that exclusion.
Delete a group
Open the group, select Delete group, and confirm. Deleting the group cannot be undone. It does not delete its users or their records.
Review both grants and restrictions before deleting: members may lose access supplied by the group, while restrictions supplied only by that group are also removed. Removing the last grantee does not make an explicitly restricted tag public. Arrange another valid access path before removing a group used for sensitive records.
Check unexpected access
Check the user's role and organization scope, every group they belong to, explicit organization denials, blocked asset types, and the record's access settings. Test using the affected user's access; being an Admin is not proof that another user can see the same records.
