Assign Users To Groups
Last updated
Group membership is configured at the user level, not at the group level. When creating or editing a user, the Administrator specifies which group or groups that user belongs to.
Navigate to Settings > Users & Roles, click + Create User, and fill in the user details. In the Group Access section of the form, check the "Limit this user to access specific groups" checkbox. A group-selection control appears - select one or more groups from the list. Click Save.

Navigate to Settings > Users & Roles, locate the user in the list, and click View in their Action column. Click the Edit (pencil) icon on their profile page. In the Group Access section, add or remove groups as needed. Click Save. The change takes effect immediately - the user's visible resources update without requiring them to log out.

When a user is assigned to more than one group, their access is the union of the scopes applicable to each group. For permissions at Group scope, CERTInext aggregates records from all groups the user belongs to. A Manager assigned to both Group A and Group B can see all certificates belonging to users in Group A and all certificates belonging to users in Group B.
This additive behaviour means that assigning a user to multiple groups progressively widens their reach. Administrators should review multi-group assignments carefully and ensure that cross-group visibility is intentional. For cases where a user genuinely needs visibility across multiple teams, multi-group assignment is the correct mechanism. For cases where strict separation between teams is required, each user should belong to a single group, and cross-group access should be configured explicitly at the group level rather than via multi-group user membership.
Last updated
