Overview
Groups allow you to organize users into logical collections and manage their access collectively. When you assign roles to a group, all members automatically inherit those permissions. This makes it easy to onboard new team members and ensure consistent access across your organization.Team Organization
Inherited Permissions
Why Use Groups?
- Simplified Onboarding
- Consistent Access
- Easy Offboarding
- Create user account
- Identify all needed roles
- Assign each role individually
- Hope you didn’t miss anything
- Create user account
- Add to appropriate group(s)
- Done — they inherit all necessary permissions
Viewing Groups
The Groups page shows all groups in your organization:Quick Actions
From the three-dot menu (⋮) on any group:- Manage Members — Add or remove users
- Edit — Update group details and roles
- Delete — Remove the group
Creating Groups
Open Create Dialog
Define Group Identity
- Group Key — Unique identifier (lowercase, e.g.,
engineering) - Group Name — Display name (e.g., “Engineering Team”)
- Description — Explain the group’s purpose
Assign Roles
- Use the search bar to filter roles
- Check the boxes next to desired roles
- Both system and custom roles are available
Save the Group
Managing Group Members
Viewing Members
To see who’s in a group:- Find the group in the list
- Click the three-dot menu (⋮)
- Select Manage Members
- Left panel — Current members with option to remove
- Right panel — Available users to add
Adding Members
Open Manage Members
Search for Users
Add Users
Verify Addition
Removing Members
Open Manage Members
Find the Member
Remove User
Confirm Removal
Editing Groups
To modify an existing group:Find the Group
Open Edit Dialog
Make Changes
- Group Name — Change the display name
- Description — Update the purpose description
- Assigned Roles — Add or remove roles
Save Changes
Deleting Groups
Consider the Impact
Open Delete Dialog
Confirm Deletion
How Group Permissions Work
Permission Inheritance
When a user is added to a group, they automatically inherit all roles assigned to that group.Multiple Group Membership
Users can belong to multiple groups. Their effective permissions are the union of:- Directly assigned roles
- All roles from all groups they belong to
Example: Multiple Groups
Example: Multiple Groups
- None
- Engineering Team → Incident Editor
- On-Call Responders → Incident Admin, Schedule Editor
- All Incident Editor permissions ✓
- All Incident Admin permissions ✓
- All Schedule Editor permissions ✓
Permission Resolution
Permissions are additive — you can only gain more access through groups, never less.Common Use Cases
Team-Based Access
Team-Based Access
- Engineering — Incident Editor, Integration Viewer
- Support — Incident Viewer, User Viewer
- Management — Full Viewer access
- DevOps — Incident Admin, Schedule Admin
On-Call Rotation
On-Call Rotation
- Add whoever is currently on-call
- Remove them when their rotation ends
- Permissions automatically adjust
Project Teams
Project Teams
- Project Alpha Team — Specific permissions for the project
- Add cross-functional team members
- Delete the group when the project ends
External Contractors
External Contractors
- Contractors — Read-only access to specific areas
- Easy to audit who has external access
- Quickly revoke all contractor access if needed
Best Practices
Name Groups by Function
Name Groups by Function
Document Group Purpose
Document Group Purpose
- What the group is for
- What permissions members get
- Who should be added
Prefer Groups Over Direct Roles
Prefer Groups Over Direct Roles
Keep Groups Focused
Keep Groups Focused
Review Membership Regularly
Review Membership Regularly
- Remove people who’ve left or changed roles
- Verify new team members are in the right groups
- Check for users in groups they shouldn’t be in
Use Meaningful Group Keys
Use Meaningful Group Keys
- Use lowercase letters and underscores
- Make it descriptive but concise
- Examples:
engineering,support_tier_1,on_call
Groups vs. Direct Role Assignment
Troubleshooting
User doesn't have expected permissions
User doesn't have expected permissions
- Verify the user is in the correct group(s)
- Check that the group has the expected roles assigned
- Confirm the roles include the needed permissions
- Ensure the user’s account is active
Can't add a user to a group
Can't add a user to a group
- Verify the user exists in your organization
- Check if they’re already in the group (they won’t appear in search)
- Ensure you have permission to manage groups
Removed user still has access
Removed user still has access
- Check if they have the same role assigned directly
- Check if they’re in another group with the same role
- Ask them to log out and back in to refresh their session
Group role changes not taking effect
Group role changes not taking effect

