Product Security - Groups - Rafay Product Documentation

Groups

A group is a collection of users that have the same role or roles. Groups make it easier to manage users that are similar instead of managing users one at a time.


Default Groups

All Organizations come primed with two default groups.


Add/Remove Users

Admins can easily add/remove users from Groups.


Assign Groups to Projects

In the example below, we have a Project called "SolutionsTeam". We have created a Group called "DemoAdmin" who are meant to be the group of privileged users for this Project.

Instead of assigning users "one at a time", we will assign the "DemoAdmin" Project to the group called "SolutionsTeam".

An example of selecting "Workspace Admin" base role from the list is given below. Permissions show the privileges allowed for each role.

An example of selecting a custom role from the drop-down is given below. Namespace is mandatory if assigning a custom role.

Organization Admins can model similar structures using groups.

Important: Namespace selection is mandatory when assigning Namespace Admin or Namespace Read Only role to the groups. This requirement applies to both base roles and custom roles.

Admins can modify custom roles assigned to groups holding base roles of Namespace Admin and Namespace Read Only.


Review Group

Admins can also review the users and projects associated with a group.

In the example below, we plan to review the users and projects associated with the Group "DemoAdmin".

To view the IDP users of this group, select IDP Users option. The below example shows one IDP User in this group.

Visit this page for Group Management via CLI.