Logical Groups
A logical group limits what somebody sees, as distinct from what they may do. Permissions are verbs; logical groups are nouns.
Settings ▸ Administration ▸ Logical Groups manages them.

The distinction that matters
| Permission group | Logical group | |
|---|---|---|
| Controls | What actions are allowed | Which records are visible |
| Example | "May delete a subject" | "Only the north building's cameras" |
| Answers | Can they? | To what? |
Both apply. A user with full permissions and a narrow logical group has broad rights over a small slice of data — which is very often exactly the arrangement you want.
Someone can hold every permission and still see nothing, because their logical group covers nothing. That is the single most common cause of "why can this person not see anything?"
What they are for
- Multi-site organisations. Staff at one property see that property.
- Departments. Front-of-house sees front-of-house cameras.
- Contractors and third parties. Narrow access to only what they are engaged for.
- Training. New staff see a subset while they learn.
How they work
A logical group names a set of things — cameras, locations, entities, module records — and the users it applies to. A user in the group sees that set; a user in no group typically sees everything their permissions allow.
Filtering is applied consistently, so a logical group narrows queries, dashboards, alerts, reports and Ace alike. There is no route around it.
In this section
- Creating a Logical Group
- Filtering Modules and Entities — choosing the records it covers
- Group Members — who it applies to
A word of warning
An empty logical group applied to a user is a group covering nothing, which means that user sees nothing. When someone reports a sudden loss of data, check their logical group membership before anything else — this is by far the most likely explanation.
What is recorded
Creating, changing and deleting logical groups, and adding or removing their members, is audited under the user-group administration type. See Reading the Audit Trail.
The Security and Access report can include logical groups, so a review covers both what people may do and what they may see.