View Privilege Holders for Group or Folder
-
Navigate to a group or folder
-
Click on the grey Privileges tab
-
Privilege holders are listed one per row under Entity name in the lower grey portion of the screen
-
A black checkmark in a column means the entity holds that privilege directly
-
A grey checkmark means the entity holds that privilege indirectly
-
-
To see an entity's Privileges in more detail, click on the button and select Edit Membership and Privileges
Direct vs Indirect Privileges
In the example above, Another Test Group and Summer Scanlan have direct Admin privileges over the Sample Admin Group and therefore have black checkmarks in the Admin column and grey checkmarks in the Read, Update, OptIn, etc columns. As a member of Another Test Group, Karl Grose has indirect privileges over the Sample Admin Group, and has grey checkmarks in all columns.
Create Admin Privilege Group
Any group may be assigned admin privileges over another group. CalNet recommends that you create admin groups specifically for that purpose.
- First, create a group following the instructions at How to Create a Group
- Be sure to be clear when naming your group -- CalNet recommends including the word Admin in any groups that you intend to use to administer other groups
- Add users who you want to have admin privileges over other groups
- Next, follow the steps below to allow your group to manage another group
Assign Admin Privilege Group to Manage other Group
You can use any group to administer another group, but CalNet recommends that you create groups specifically for that purpose. Follow instructions above to Create Admin Privilege Group before following the steps below.
- Navigate to the group what you want to be managed
- Click on the grey Privileges tab
- Click the button
- In the search field, enter the name of the Admin Privilege group created above
- Select the group name when it appears below
- Check the appropriate boxes for the privileges you want the Admin Privilege group to have
- CalNet recommends selecting Admin
- Do not select Member unless you want the Admins to be members of the group - admins do not need to be members of groups they manage
- See below for Privilege Definitions
- Click the button
Add Privilege Holder to Group
- Navigate to the group what you want to be managed
- Click on the Privileges tab
- Click the button
- In the search field, enter the name of person you want to manage this group and select it when it appears below
- Check the appropriate boxes for the privileges you want to assign
- CalNet recommends selecting Admin
- Do not select Member unless you want the Admins to be members of the group - admins do not need to be members of groups they manage
- See below for Privilege Definitions
- Click the button
View or Edit Privilege Holder Settings
To view or edit a privilege holder's membership and privileges to a group:
- Navigate to the group
- Click the Privileges tab
- Click the button to on the right side of the row for the privilege holder
- Select Edit Membership and Privileges
- Add or remove membership to the group by checking the boxes under the Description section
- Add or remove privileges to the group by checking the boxes under the Direct Group Privileges section
- Press the button, or Cancel
Assign Global Privileges
Assigning a group Global Privileges will result in any CalGroups user being able to see the group and the group membership.
- Navigate to the group
- Click the button
- Select Edit Group
- Click the show advanced properties link
- Check the desired privilege boxes in the Assign privileges to everyone section
- Read will allow any CalGroups user to see the group membership
- See Privilege Definitions for more information
- Press the button
App/Org Owner Group Privileges
Inside your folder will be a App/Org Owner group that has admin privileges to the folder. You will automatically be a member of the App/Org Owner group, to which you can add other members. Members of the App/Org Owner group have the following privileges:
-
Add other owners
-
Create, update or delete folders
-
Create, update or delete groups
-
Add and delete group members
-
Manage group member privileges
Privilege Definitions
Privileges can be assigned to a person or a group.
ADMIN – you have full access to the group including being able to see the audit log and delete the group
READ – you can see the members of the group
UPDATE – you can update the members of the group
OPTIN – you can add yourself as a member of the group
OPTOUT – you can remove yourself from the membership list of the group
ATTRIBUTE READ – you can see attributes assigned to the group (for the attributes where you have ATTR_READ on the attribute definitions)
ATTRIBUTE UPDATE – you can update attributes of the group (for the attributes where you have ATTR_UPDATE on the attribute definitions)
VIEW – you can see that the group exists
Support
Request access via a folder space via a Service Request in ServiceNow.
If you have questions about CalGroups, including API questions, contact: calnet-admin@berkeley.edu.