Plerion has several kinds of groups. User groups collect people. Integration groups collect cloud integrations for scoping a role. Asset groups collect assets. This page is about user groups only.
Who can manage user groups
Only Organization admins can create, edit, or delete user groups and change what they grant. Organization read-only users can view them.Create a user group
1
Go to Admin > Directory > User groups
The list shows every user group in the organization, who manages it, and how many members it has.
2
Click Create user group
Enter a name and, if you want, a description. Names are unique within the organization.
3
Add members
Open the group and add users from the directory. A user can belong to any number of user groups.
4
Grant roles
In the
Roles section of the group, add one or more roles. Built-in roles and custom roles can both be granted; a tenant role is granted for one tenant or for all tenants. Every member holds these roles through the group from the moment they are added.User groups managed by your identity provider
When SCIM provisioning is enabled and your identity provider pushes groups, each pushed group appears here as a user group marked Managed by your identity provider.- Name and membership belong to the identity provider. You cannot rename such a group or change its members in Plerion. Make those changes in your identity provider and they sync across.
- Roles are still granted in Plerion. SCIM carries no roles. Open the group and grant the roles its members should hold, exactly as for a group you created yourself.
- You can delete it in Plerion. Deleting an identity-provider group here removes what it granted. Your identity provider may recreate it on its next push if the group is still assigned to the Plerion application.
- A SCIM-managed user’s roles come from their groups only. They cannot be granted a role directly on their user page, and you cannot add them to a user group you created by hand, because their memberships belong to the identity provider. To change their access, change the roles on one of their groups, or move them between groups in your identity provider.