Group access
Scope which customers a team member or role can see and act on.
A role decides what someone can do. Group access decides which customers they can do it to. A Helpdesk role says someone can work tickets through AI Chat. Their group membership says whose tickets.
Non-admins start with no access
This isn't opt-in the way it might be in other tools: a non-admin user can't access any company or end-user until they've been given group-based access. Someone with no group assigned is logged in, but they can't work anything. It's not a broad default that groups then narrow down, it's zero until you grant some.
When you need it
Every tenant with non-admin team members needs at least one group. There's no "skip groups, everyone sees everything" option below Admin, so this isn't an advanced feature you grow into, it's part of onboarding day one. Beyond that baseline, groups also let you shape access for specific situations:
- Separate branches, Scranton and Utica, say, that each only handle their own book of customers.
- A tier system where senior technicians see everything but a Tier 1 queue is scoped to a subset of lower-complexity accounts.
- A set of sensitive or VIP customers visible only to a smaller group of technicians.
How it applies
A group is a set of customers plus the team members who can access them. Team members can belong to more than one group, and their access is the union of every group they're in.
Owners and Admins see every customer regardless of group membership. Groups are what give a Manager, Engineer, Helpdesk, or custom-role user any customer access at all, not a restriction layered on top of access they'd otherwise have.
Group access can only be assigned once someone has accepted their invite. See Invite a team member for that limitation.
Creating a group
Open Team & Roles
Go to Team & Roles > Groups and select New group.
Name it and add customers
Name the group for what it represents, a branch, a tier, a segment, and add the customers it should cover.
Add team members
Add the technicians or roles that should have access to this group's customers. You can add someone here or from their profile in Invite a team member.
Keeping groups accurate
A group only protects access as long as it reflects reality. When you take on a new customer, retire one, or move a technician between branches, update group membership too. An out-of-date group either blocks someone from a customer they now own, or leaves access open to one they no longer should see, and neither failure mode announces itself. You find out when someone complains they can't see a ticket, or when you notice someone could see one they shouldn't have.