Workspace groups & permissions
Bundle workspace members into groups and grant them workspace-tier permissions in one place.
Workspace groups let you hand out workspace-level access to a set of people at once instead of adjusting each person individually. A group holds a list of members and a list of permissions; everyone in the group gets those permissions.
A member's effective access is the union of every group they belong to plus whatever their workspace role already grants. Groups only ever add access — they never take away what a role already gives, so putting someone in a group with few permissions does not restrict them.
Prerequisites
- You must be a workspace admin or owner, or belong to a group with the Manage groups permission. Without it the page is read-only: you can see groups, their permissions and their members, but every control is disabled.
- The people you want to add must already be members of the workspace. Invite them from Admin → Members first — pending invitees cannot be added to a group until they accept.
Open the groups page
Go to Admin → Permissions → Groups. The page is a two-pane layout: every group in the workspace on the left, the selected group's details on the right.

Each row in the list shows the group name, a badge naming the preset its permissions match (or Custom), the member count, and how many of the 12 workspace-tier permissions it grants. Use the search box above the list to filter by name when the list gets long.
Create a group
-
Click New group, give the group a name, and confirm with Create group. Names are just labels — pick something that describes the job the group does, like "Support Leads".

-
The new group opens in the detail pane with 0 of 12 permissions enabled and no members. Nothing has been granted yet — a group only takes effect once you turn permissions on and add people.

Grant permissions
Permissions are organised into four scopes, each collapsible and each showing how many of its permissions are on:
- Workspace — admin-level controls: manage the workspace, invite and remove members, manage groups, read the audit log, read usage and top questions.
- Projects — create projects at the workspace level.
- Integrations & AI — manage connectors, knowledge sources, and AI providers.
- Insights — read conversations and read feedback across the workspace.
-
To fill in a whole set at once, open the preset menu next to PERMISSIONS and pick one. Full access turns on every workspace-tier permission, Manager covers inviting people, managing groups and creating projects, and Viewer covers the read-only permissions: audit, usage, conversations and feedback.

-
Adjust individual permissions by clicking the pills — filled means granted, outlined means not. Allow all and None on a scope header toggle that whole scope. As soon as the draft differs from what is saved, an Unsaved changes marker appears with Cancel and Save changes; the badge next to PERMISSIONS switches to Custom once the selection no longer matches a preset.

-
Click Save changes. The indicator clears and the group's row in the list updates to the new permission count. Nothing is applied until you save — the page warns you if you try to navigate away with unsaved edits, and Cancel throws the draft away.

Add and remove members
-
Scroll to the MEMBERS section at the bottom of the detail pane and click Add members. The picker lists every workspace member who is not already in the group; search by name or email and tick everyone you want to add. The button counts your selection, so you can add several people in one go.

-
Confirm, and the members appear in the list with the group's permissions now in effect for them. Remove someone with the ✕ on their row — that takes effect immediately and revokes only the access this group granted.

Rename a group
Click the group's name in the detail header, type the new name, and press Enter to save or Escape to cancel. Renaming is a label change only — permissions and membership are untouched.

Delete a group
Click Delete in the detail header. If the group has members, the dialog lists who is affected and asks you to confirm you understand their permissions will be revoked; you have to tick that box before the Delete group button becomes available.

Deleting a group removes only the access that group granted. Members keep everything they get from their workspace role and from any other group they belong to.
Notes
- Groups grant workspace-tier permissions. Access inside an individual project is managed separately in that project's own settings.
- Because access is a union, a person in several groups gets every permission any one of those groups grants. To take access away you have to remove it everywhere it is granted, including their workspace role.
- Permission edits are batched: toggling pills only changes a local draft, and nothing reaches other members until you click Save changes. Member additions and removals, by contrast, apply immediately.