Skip to main content
Organization Admin permissions are required to manage user groups.
User groups let you manage permissions for multiple users at once instead of configuring each user individually.
Groups page showing a list of user groups with their name, label, member count, and group ID

Settings > Groups page in Omni, listing all user groups

Creating user groups

User groups can also be created through some SCIM integrations.
  1. Navigate to Settings > Groups.
  2. Click New Group.
  3. Enter a Name for the group. You can also add a description.
  4. Click Save to create the group.
After the group is created, you’ll be redirected to the group’s Members tab where you can add users.

Managing group members

Users can be added to and removed from groups manually, through the API or some SCIM integrations.
You can add external users to groups and remove them only in the Omni UI, not through the API or SCIM. API group responses do not include external users.

Adding users to groups

A user’s group membership is also available as the omni_user_groups user attribute, which can be used for data-level permissioning.
You can add users to groups from the group’s Members tab or directly from a user’s Groups tab.From a group’s Members tab:
  1. Navigate to Settings > Groups.
  2. Click the group you want to work with.
  3. In the group’s Members tab, click Add Members.
  4. Search for and select users in the modal, then click Add.

Removing users from groups

When a user is removed from a group, they lose any permissions that were granted through that group. Users can be re-added as group members if needed.
You can remove users from groups from the group’s Members tab or directly from a user’s Groups tab.From a group’s Members tab:
  1. Navigate to Settings > Groups.
  2. Click the group you want to work with.
  3. In the group’s Members tab, locate the user you want to remove.
  4. Click Remove from group.

Managing a user’s groups from their settings

In addition to managing user memberships from the group’s Members tab, you can view and modify an individual user’s group memberships from their user settings. This is particularly useful when managing a user who is not yet a member of any groups, or when you need to modify multiple group memberships for a single user.

Assigning permissions to groups

Access to connections, models, and content can be granted to an entire user group at once.

Assigning connection/model access

Model roles control what actions user group members can perform on connections and the individual models associated with those connections.
Group roles are combined with any roles a user has directly or through the connection’s base access, and Omni grants the most permissive one. Adding a user to a group can raise their access but can’t lower it. User groups grant connection and model roles only; the Organization Admin role is assigned per user. Refer to Connection permission basics for more information.
  1. Navigate to Settings > Connections and open the connection you want to work with.
  2. Click the Permissions tab and scroll to Connection Roles.
  3. In the Groups view, locate the group you want to grant permissions to.
  4. Use the Access dropdown to change the group’s role. If custom roles are defined, they will display as options in the dropdown.
Connection Roles section showing groups listed with their model, access level dropdown, and member count

Connection Roles section showing the Groups view with access dropdowns for each group

Assigning content access

To grant access to documents and folders, share the content with the group. See Content sharing for details.

Allowing groups to switch user attribute values

The Allowed user attribute values section of a group’s Settings tab lists the user attribute values that group members can switch to in documents and the model IDE, if they have access. See User-selected attribute values to learn more about provisioning values.

Deleting user groups

Deleting a user group is not reversible. Group members will lose any connection roles and content access that were granted through the group.
  1. Navigate to Settings > Groups.
  2. Click the icon in the user group’s row.
  3. When prompted, click Yes, Delete to confirm.
You can also delete a group by opening its Settings tab and clicking the Delete button.

Next steps