When to use a group instead of a user
Decide when to grant access directly to a person and when to organize the grant by group.
When to use this
- Use it before creating a data rule or assigning a role.
- Use it when more than one person needs the same access.
- Use it in governance reviews.
Before you start
- Determine whether the need is individual or belongs to a team.
- Confirm whether the responsibility will continue to exist even as people change.
- Decide who will review the group's members.
Step by step
- Use a group when the access represents a function, a team, or a project.
- Use an individual user when the need is one-off and personal.
- Avoid creating many groups for a single person's exceptions.
- Prefer a group when the access will be reused across several rules.
- Review the members before attaching sensitive data.
What happens next
- Grants by group become easier to maintain.
- People joining and leaving only requires reviewing membership.
- Auditors can understand the responsibility the group represents.
Common errors
- Creating an individual rule for every new person on a team.
- Using a broad group for sensitive data with no membership review.
- Leaving a group with no clear owner.
Good practice
- Use groups for stable responsibilities.
- Document the group's purpose in your organization's process.
- Review groups before widening data access.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.