Turn on a feature for one of a client's user groups

Every capability starts switched off for a group. Turning one on is done per mapped group on the client, and permissions add up across groups.

Every capability starts switched off for a client’s user groups. Nothing a group can do arrives by default, which is why a newly mapped group appears to do nothing at all.

Turning something on is done per group, on that client, under User Access Control.

Where somebody belongs to two mapped groups, what they can do is everything either group allows rather than the narrower of the two.

Before you begin

Confirm the group is already mapped. Importing a group is not the same as mapping it, and mapping is what makes permissions available to set.

Agree with the client what that group should be able to do. This is their access, and it is worth them saying so.

Turn it on

  1. Open the client and go to User Access Control.
  2. Find the mapping for the group you want.
  3. Open Edit user permissions on that mapping and switch on what the group should be able to do.
  4. Save.

The permissions apply to everybody in that group from then on.

Good to know

Permissions add up. Somebody in two mapped groups gets the union, so a permissive group quietly widens what its members can do elsewhere.

Sensitive capabilities are deliberately harder to reach and stay off unless somebody makes a decision about them. Treat any of those as a conversation with the client rather than a switch.

Verify it worked

Ask somebody in that group to try the thing. That is the only verification that counts.

Confirm somebody outside the group is still refused.

If something doesn’t look right

If nothing changed for the group, confirm you used Edit user permissions rather than the admin editor on the same mapping, and that it saved.

If somebody can do more than you granted, check whether they are in a second mapped group.

If a capability is not available to switch on at all, it may be off at your own organisation level first.

To report a problem, open a support conversation from the Help drawer with the client, the group and the capability.

FAQ

Q: Why can a group do nothing after being mapped?

A: Mapping grants nothing on its own. The permissions have to be set.

Q: What happens if somebody is in two groups?

A: They get everything either group allows.

Q: Can the client change these themselves?

A: The mapping and its permissions are set here, by you.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy