Skip to main content

When to use a group instead of a user

Decide when to grant access directly to a person and when to organize the grant by group.

When to use this​

  • Use it before creating a data rule or assigning a role.
  • Use it when more than one person needs the same access.
  • Use it in governance reviews.

Before you start​

  • Determine whether the need is individual or belongs to a team.
  • Confirm whether the responsibility will continue to exist even as people change.
  • Decide who will review the group's members.

Step by step​

  1. Use a group when the access represents a function, a team, or a project.
  2. Use an individual user when the need is one-off and personal.
  3. Avoid creating many groups for a single person's exceptions.
  4. Prefer a group when the access will be reused across several rules.
  5. Review the members before attaching sensitive data.

What happens next​

  • Grants by group become easier to maintain.
  • People joining and leaving only requires reviewing membership.
  • Auditors can understand the responsibility the group represents.

Common errors​

  • Creating an individual rule for every new person on a team.
  • Using a broad group for sensitive data with no membership review.
  • Leaving a group with no clear owner.

Good practice​

  • Use groups for stable responsibilities.
  • Document the group's purpose in your organization's process.
  • Review groups before widening data access.

Next steps​