Access Groups
access groups enables administrators to organize users and service ids into groups, simplifying access management and allowing permissions to be assigned and managed at scale across services by assigning access policies to groups rather than individual users, administrators can simplify identity and access management, improve governance and maintain consistent permissions across teams and workflows access groups can be used to grant role based access to different types of users, manage service id permissions for automation and integrations and create temporary groups for project specific access requirements this centralized approach helps streamline access administration while supporting security and compliance objectives prerequisites the following prerequisites must be met to create and manage access groups you must have the administrator role assigned to your account users and service ids docid\ i2wxfqp2tstqi7gfvof18 must exist in the account before being added to groups only administrators can create, modify or delete groups or assign policies access groups page the access groups page provides a centralized view of all access groups in your account from this page, administrators can monitor and manage group based access by reviewing the total number of groups and their classification as bridge groups or service groups summary cards provide a quick overview of group distribution across the account, helping administrators manage permissions and access assignments more effectively by default, bridge groups are predefined and cannot be customized accessing the access groups page from the main menu , go to administration → → access groups managing access groups the access groups page allows administrators to view, create and manage access groups within a account from this page, you can review existing groups, add or remove users and service ids, assign access policies and manage permissions for groups based on business and operational needs for more information about bridge access groups, see the table in inviting new users docid 7caos2ibikfbh9x bz51x creating an access group to create an access group, complete the following steps on the access groups page, click add access group in the side drawer, enter a name for the group (must start with a letter; letters, numbers, underscores, spaces and hyphens allowed) add a description (max 100 characters) click add access group once the group is created, it will appear in the list of service access groups adding service ids to an access group to add a service id to a group, complete the following steps from the access groups page, locate the access group that you want to manage and select it to open its details navigate to the service ids tab within the group click + add service id select one or more service ids and click add service id to learn more, see service ids docid\ i2wxfqp2tstqi7gfvof18 once all available service ids have been added, the button is disabled assigning access policies to an access group to assign an access policy to an access group, complete the following steps from the access groups page, locate the access group that you want to manage and select it to open its details navigate to the access policies tab click + assign access policy select the service you want to assign, followed by scope and role and click assign to learn more, see access policies docid\ nb3bzm bsa3w7aefpbdzs custom groups require manual policy assignment default groups come with pre assigned policies but can be extended with manual policy assignment with different scope policies associated with platform and with administrator role, cannot be removed policies associated with all identity and access enabled services with any role, cannot be removed adding or removing users from an access group you can add or remove users from an access group to ensure that access permissions remain aligned with users' roles and responsibilities click the overflow menu next to the access group that you want to manage select view details the following two actions are available to add users, select add member , choose one or more users, and then select add to remove a user, locate the user in the members list and select the delete icon next to their name confirm the action when prompted deleting a service access group administrators can delete service access groups that are no longer needed to help maintain an organized and manageable access structure follow these steps to delete a service access group from the system on the access groups page, scroll to the service access groups section and locate the access group that you want to delete to quickly find a specific group, use the search field to filter the list in the actions column, click the ellipsis ( ) , and select delete group from the menu default bridge groups cannot be removed; only custom service access groups can be deleted editing membership you can update a user's access group membership after they have been added to the account to learn more, see editing user membership under users docid 7caos2ibikfbh9x bz51x