Manage Group Access
The Roles tab lets you view and manage the permissions that are available to the members of a group. Group members inherit permissions based on the roles that are assigned to the group in one or more projects.
View Access Permissions of a Group
The access permissions for a group are displayed on the Roles tab of the group profile. Here, you can view which roles are assigned to the group.
There are two views available on this tab. The default view shows the list of roles that are assigned to the group, listed by User or group.
You also have the option to view the list by Role.
The following actions are available in both views:
Use the search box to filter the list. You can use a range of filter criteria including user, group, role, and permission. Enter your search criteria in the format
field: value.Click the Details button to show or hide the sidebar. The sidebar displays the set of permissions that are assigned to the role. The permissions are grouped by service.
To view the access rights for a group:
From the main navigation menu, select Groups.
Select a group from the list.
Open the Roles tab of the group profile.
Use the search box to filter the list by a role or a particular permission to find out if the group has the required access to a resource or operation.
Grant a Role to a Group
You can grant a role to a group directly. Members of the group are granted all access permissions that are assigned to this role.
To assign an individual role to a group:
From the main navigation menu, select Groups.
Select a group from the list.
Select the Roles tab.
Click the Grant role button.
In the Grant Role dialog, choose the role that you want to assign to the group.
Click the Grant button.
The selected role is granted to the user group.
All the permissions that are assigned to the role are granted to the users who are members of the group.
Revoke a Role from a Group
If a group of users no longer requires access that is granted by a role, you can revoke the role assignment. This procedure only applies to roles that are assigned directly to a group. If a role is granted to a group as a subgroup of another group, you have two options:
Revoke the role from the parent group.
Remove the subgroup from the parent group by nesting it under the All Users group.
To revoke a role from a group:
From the main navigation menu, select Groups.
Use the search box to find the desired group.
Select a group from the list.
Select the Roles tab.
Select the role assignment that you want to remove from the selected group. Use the search box to locate a role by name or permission.
Click the Revoke role button.
Confirm the action in the confirmation dialog.
The role is revoked from the group.
Members of the group lose the permissions that are assigned to the role.