Skip to main content

Group Members

A logical group's Users panel is who it applies to. Adding somebody narrows what they see to the group's contents; removing them widens it again.

Adding and removing​

Add users from the group's own Users panel. This is the direction that suits most changes — you are thinking about a scope and who belongs in it.

A permission group can be a member too, which saves maintaining the same list twice: scope "everyone in the Surveillance group" to a property once, and the logical group follows the permission group as people join and leave it.

Removing somebody returns them to whatever their remaining group memberships allow. Where they belong to no logical group at all, they typically see everything their permissions permit — so removing a group can widen access rather than remove it.

That surprises people. Check what someone will see after removal, not just before.

Belonging to more than one​

A user can be in several logical groups, and sees the combined contents. Someone in North Building and South Building sees both.

That makes groups composable in the same way permission groups are: define groups per site or department, and give people the ones they need rather than building a bespoke group per person.

Users in no group​

A user in no logical group is unfiltered — they see everything their permissions allow.

For a small single-site organisation that is often correct, and logical groups need not be used at all. For anything larger it is worth deciding deliberately rather than by default, since "no group" is the broadest possible setting and looks the same as an oversight.

Reviewing membership​

Membership drifts. People change roles, cover for colleagues, and join projects, and the group they were added to for a fortnight stays for two years.

Two things make review practical:

  • The group's Users panel — who is in this scope now
  • The Security and Access Report with Include logical groups and Include group members — a document covering everybody at once

The report is the one to use for a scheduled review, because it captures both what people may do and what they may see in a single point-in-time record.

When somebody reports missing data​

The order to check, fastest first:

  1. Logical group membership. Were they added to a group, or was a group's contents narrowed?
  2. Permission groups. Do they still hold the right permission group?
  3. The data itself. Does it exist in the period they are looking at?

Logical groups are first because they are the most common cause and the least obvious to the person affected — nothing tells them their view has been narrowed.

What is recorded​

Adding and removing members is audited under the user-group administration type, so a change in somebody's visible data can be traced to who made it and when. See Reading the Audit Trail.