Admin › Users › Groups
Why Groups?
| Per-user | Per-group |
|---|---|
| Set permissions per user individually | Set once on the group, applies to everyone |
| Edit one by one when changing | Edit only the group setting |
| Becomes complex as users grow | Scales systematically |
Creating a Group
Group Permission Settings
Configure detailed permissions per group. All permissions are split into 4 levels.
Permission Levels
| Level | Description |
|---|---|
| None | Cannot access the feature |
| Access | View list (no detail access) |
| Read | View list + view details |
| Write | View + create/edit/delete |
Workspace permissions detail
Workspace permissions detail
| Permission | None | Access | Read | Write |
|---|---|---|---|---|
| Agents | No access | List only | View detail | Create/edit |
| Knowledge Base | No access | List only | View detail | Create/edit |
| Prompts | No access | List only | View detail | Create/edit |
| Tools | No access | List only | View detail | Create/edit |
| Database | No access | List only | View detail | Create/edit |
| Glossary | No access | List only | View detail | Create/edit |
| Guardrails | No access | List only | View detail | Create/edit |
| Flow access | No access | List only | View detail | Create/edit |
Admin permissions detail
Admin permissions detail
You can delegate parts of admin features to regular users.
| Permission | None | Access | Read | Write |
|---|---|---|---|---|
| User management | No access | View user list | View detail | Create/edit/delete |
| Settings access | No access | View settings list | View setting values | Change settings |
| Evaluations | No access | View evaluation list | View detail | Change settings |
| Monitoring | No access | View monitoring | View detail | — |
Sharing/Chat/Feature permissions detail
Sharing/Chat/Feature permissions detail
Default Permissions
Set default permissions applied to users not in any group. Click Default Permissions at the top of the Groups tab.Group ↔ Organizational Unit Mapping
In the Organizations tab of the group edit modal, you can map this group to one or more organizational units (OUs). All members of mapped OUs automatically inherit the group’s permissions, so when IdP sync adds a new employee to an OU, permissions apply without any manual action.| Field | Description |
|---|---|
| Tab location | Group edit modal → General / Permissions / Organizations / Users |
| Selection | Multi-select checkboxes. Search box filters OUs by name, display name, or description |
| Mutual exclusivity | Each OU can be assigned to only one group. OUs already claimed by another group are automatically excluded from the list |
| Displayed info | OU display name + internal name, member count, Assigned badge for OUs already attached to the current group |
| Save behavior | On group save, persisted to group.meta.org_unit_ids |
OUs themselves are imported via IdP sync (Entra/Google Workspace OIDC) or created manually under Admin > Organizations. See Organization Management for OU creation and sync.
Related Pages
User Management
User list, roles, add/edit, usage limits
Organizations
Organization/OU hierarchy, Entra ID sync, organization-based access control
Inquiries
Receive and handle user inquiries
