TL;DR: Groups let you control which organizations and asset types your team members can access. Access grants go one level deeper - letting you restrict or grant access on a per-asset basis.
Access Grants
Access grants control which users or groups can access a specific asset, on top of the broader org and asset-type scopes set by groups.
How Grants Work
Every asset has its own set of access grants. By default, any user with org scope for the organization that owns the asset can see it. When grants are enabled on an asset, only the users and groups explicitly granted access can see it.
Roles and permissions for grants:
Viewer (can see whether grants are on or off, but cannot see which users or groups are granted access)
Support & Admin (can list and view access grants on an asset)
Admin (can create, edit, and delete access grants)
Asset Ownership
Every asset has an Owner. The Owner always has an access grant to their asset and cannot be removed.
If a user manually creates an asset, they are the Owner - shown as a pill in the grants area.
If the asset came from a data source (such as an IT Glue migration or PSA integration), the Owner is system and does not appear as a pill.
Adding a Grant
To grant access to a specific user or group, enable the second radio button on the asset's grants panel, then select the user or group to add. Changes take effect immediately.
⚠️ Warning: Because changes take effect immediately, it's possible to orphan an asset. If an Admin (who is not the Owner) adds a grant and then removes all grants, every user except the Owner loses access instantly - including the Admin themselves. If the Owner is the system user, all users will immediately lose access to that asset.
Scope Deny Overrides Grants
Even if a user is explicitly granted access to an asset, they will still be unable to see it if they are in a group that has a deny scope for that asset's asset type. Deny scopes always take precedence.
📝 Note: Bulk management of asset grants is coming before general availability.
For information on Group Management click here.