Groups
A group holds a set of permissions and grants them to every member. Both users and service accounts can be added to a group.
Groups can be managed here.
Built-in groups
Every organization starts with two built-in groups:
- admin grants full access to organization settings, billing, and permissions.
- user grants the baseline permissions for every member of the organization. This does include some write permissions.
A built-in group stays in step with the RWX defaults, so it picks up permissions that RWX adds later. You cannot rename or delete a built-in group.
Custom groups
Create a group for each distinct set of permissions you want to assign to people in your organization, then add the members who need them.
You can only grant a permission you hold yourself. Anything you don't hold isn't offered when you choose the group's permissions.
Adding or removing a permission to a group grants/revokes it immediately to everyone in the group.
Members
Add users and service accounts on the group's Members tab. Every member holds each permission the group grants.
You can also specify the group(s) for each member when inviting them to your organization.
Members hold the permissions of their groups in addition to any permissions you assign them directly.
Nesting groups
Nest one group under another to hand the parent's permissions down. Members of the child group hold everything the parent grants, in addition to what the child grants.
Manage nesting from the parent group's Nesting tab.
Managing a group
A group's manager can edit its permissions, members, and nesting, and can delete it. A manager can also add themselves to the group, therefore obtaining all the permissions the group grants.
For that reason the group:manage permission can only be granted from one member to another if the granting member holds all of the group's permissions. Additionally, whenever a permission is added to a group (or new layers of nesting are added), the confirmation message will list both the members of the group(s) who will receive new permissions and any group managers who would also gain the permission if they were to join the group they manage.
Deleting a group
Deleting a group removes its memberships and its nesting. Its members lose the permissions it granted, unless another group grants the same permissions. You cannot delete a built-in group.