Account-Level Group Isolation
Account-Level Group Isolation is the most restrictive group control available in CERTInext. It is a single account-wide switch that, when enabled, forces every non-Administrator user to see and interact only with resources that belong to their designated group - regardless of what their role's scope or group configuration would otherwise allow.
What Group Isolation Does
When isolation is enabled, any user whose role ordinarily carries All or Group scope has their effective access ceiling reduced to their own group boundary. A Manager who could normally see every certificate across the account will suddenly only see certificates belonging to users in their own group. A Standard User whose view_all permissions previously gave them account-wide read visibility will only see records owned by members of their group.
The Administrator role is explicitly excluded from this restriction at all times. An Administrator always retains full All scope visibility and management capability across every group and every entity in the account, even when isolation is active.
When to Enable Group Isolation
Group isolation is most appropriate for multi-team or multi-department accounts where each team manages its own certificate estate and must not see another team's records, for reseller or partner accounts where multiple end-customers operate within a single CERTInext account and must be kept strictly separate, and for any account subject to regulatory data segmentation requirements.
Group isolation is an account-wide blunt instrument. If you need more targeted, user-by-user group restrictions, use the "Limit this user to specific groups" checkbox on the Add/Edit User form instead. Both approaches can be used together.
Enabling Group Isolation
Log in as an Administrator and navigate to Settings > Account Configuration. Locate the Account-Level Group Isolation setting.
📷 Screenshot: Account Configuration - Group Isolation toggle (disabled state)
Show the Account-Level Group Isolation toggle in its off/disabled state. Annotate the toggle control and any descriptive text visible alongside it.
Toggle the setting to Enabled. A confirmation prompt appears, explaining that all non-Administrator users will immediately have their visible resources restricted to their own group. Confirm the action. The setting takes effect immediately - no user logout or session refresh is required.
📷 Screenshot: Group Isolation - confirmation dialog
Show the confirmation dialog that appears when enabling Account-Level Group Isolation, including the warning message and the Confirm / Cancel buttons.
📷 Screenshot: Account Configuration - Group Isolation toggle (enabled state)
Show the toggle in its on/enabled state with any visual confirmation indicator (colour change, active label) confirming the setting is active.
Effect on Each Role When Isolation Is Active
Administrator: Unaffected. Retains full All scope across every module and every group.
Manager: Previously account-wide visibility narrows to the user's designated group. All management capabilities remain - only the reach of the data changes.
Standard User: The view_all permissions that previously gave account-wide read visibility now resolve at the group boundary only.
Discovery User: Access to discovered certificates and bots is limited to their own group. Full operational control over those resources is retained.
Finance Manager: Visibility over certificates and orders is reduced to the user's group. Billing and financial capabilities are unchanged since billing records are not group-scoped.
Basic User / Sub-Account User: No practical change - their permissions already operate at Own scope in all modules where group membership would otherwise matter.
Disabling Group Isolation
To disable isolation, navigate to Settings > Account Configuration, toggle the Account-Level Group Isolation setting to Disabled, and confirm the action. All non-Administrator users immediately regain access to the full scope their role and group configuration allow. No user session restart is required.
📷 Screenshot: Account Configuration - disabling Group Isolation
Show the Account Configuration page with the Group Isolation toggle being switched off and the confirmation dialog that appears.
Last updated
