Group Permissions
Two separate questions: what you can do to a group, and what the group gets you.
Owners and members
Section titled “Owners and members”| Owner | Member | |
|---|---|---|
| See the group and its membership | ✓ | ✓ |
| Use what the group has access to | ✓ | ✓ |
| Add and remove members | ✓ | |
| Answer requests to join | ✓ | |
| Manage the group’s Deployables | ✓ | |
| Change or delete the group | ✓ |
A group can have several owners, and should. Adding someone to a group grants them everything the group can reach, so ownership is an access-granting privilege.
Group owners manage any Deployable the group owns, exactly as an individual owner manages their own. See Permissions.
What a group grants
Section titled “What a group grants”Nothing by itself. Access arrives when a Deployable is shared with the group, or when the group owns it.
Either way the grant is live: it follows membership rather than being copied at the moment of sharing, so adding and removing people takes effect everywhere the group is used.
This is the usual reason someone still has access after being removed from a Deployable’s list. Check their group memberships before assuming something is broken.
Reviewing access
Section titled “Reviewing access”To answer “who can open this?”, read the Deployable’s sharing scope, then expand any group on its list. Access built out of a few named groups is reviewable; access built out of individual grants is not.
