Groups

A group is a named set of people. Groups can be nested, and a person in a child group is automatically a member of its parents.

Groups versus organisation units

Organisation unit Group
Answers Where does this person report? What does this person do?
Membership One primary unit per person Any number of groups
Drives Roll-up and scope Who a grant applies to

Group purposes

Every group is tagged with one or more purposes. This is not decoration — it changes what the group can be used for.

Purpose Allows the group to
Access Be the subject of an access grant.
Assignment Be named as the owner or assignee of a record — including owning a register.
Notification Receive notifications as a group.
Review Be a reviewer in an access review.

A group without the access purpose cannot appear in a grant at all — the dialog will not offer it. Without purposes, a group list becomes a junk drawer within a year, and nobody can tell what any group is for. This is one field that prevents that.

A group can own a register

Give a group the assignment purpose and it can be named as an owner. This is how a register keeps an accountable owner after the person who owned it leaves the company — ownership transfers with the group, not with an individual’s account.

Rule-based groups

Instead of listing members, a group can define a rule — for example, everyone whose unit is Cards & Payments or below.

Membership is then computed from the organisation tree and stays correct after a reorganisation.

This is the right way to express “grant access to everyone in a unit”. The grant table still shows a group, with a name and an owner, which an access review can certify. Granting the unit directly would let an HR transfer change somebody’s access with nobody deciding and nothing in the log.

Independence groups

A group can be marked as an independence group. Members are capped at their read-only ceiling role everywhere — except inside a sealed workspace their own function owns. This is how internal audit reads everything while writing only its own workpapers.