A group is a named set of people you can grant access to all at once. Instead of adding ten people to a space one by one, you add them to a group, then give the group access. Anyone you add to the group later inherits that access automatically, and anyone you remove loses it. Groups are the simplest way to keep access tidy as your team grows.
Note: A few permissions decide what you can do here:
To create a group, you need the "Create groups" permission, which comes with the Group creator role.
To manage a group (rename it, change its members, or delete it), you need to be a manager of that group. You become one automatically when you create it.
To give a group tenant-wide capabilities, you need the "Manage roles" permission. This is optional and covered near the end.
When you add someone to a group, you pick one of two roles:
Group member can see the group and who's in it.
Group manager can change the group's membership and rename or delete it.
Tip: Most people in a group are members. Give the manager role only to the few people who should maintain the group.
Create a group
To create a group, go to settings, then groups and select the plus button in the top right.
Give the group a name, for example "Designers" or "Security team."
Under Members, add the people who belong in the group and choose a role for each and click create.
Note: you're added as the group's manager by default, so you can manage its membership right away.
Give a group access to spaces, connectors, and skills
Grant resource access to a group, from the resource itself. For example, to give a group access to a space, open that space's settings, go to its access tab, and add the group there.
The group's own access tab shows a read-only list of everything the group can currently reach. To change any row, open that resource's settings and adjust the group's access from there.
This is why groups are so useful: grant the group access to a space once, and every current and future member gets it without any extra steps.
Add or remove members later
Open the group from the Groups list and go to the Access tab.
Under Members, add people, remove them, or change their role.
Removing someone from a group only takes away the access the group gave them. They keep every other role they hold directly or through other groups. If removing someone would cut off access they're actively relying on, Tines 3B asks you to confirm first.
Give a group tenant-wide capabilities
Beyond access to specific resources, you can give everyone in a group a tenant-wide capability, such as the ability to create spaces or connectors:
Open the group and go to the settings tab.
Under tenant roles, turn on the capabilities the group should have.
This section only appears if you have permission to manage roles.
Tip: Add tenant capabilities sparingly, since it applies to every member of the group.
Rename a group
Open the group, go to the settings tab, and edit the group name. Group names have to be unique across your tenant.
Delete a group
Open the group, go to the settings tab, select delete group and confirm.
Deleting a group permanently removes it and takes away the access it provided, but members keep all their other access.
Note: You can't delete a group while it still has access to any resource. Remove the group from those spaces, connectors, and skills first, then delete it.
If your identity provider manages groups
If your organization syncs groups from an identity provider, that provider can own the management of group membership.
When it does, Tines 3B locks the matching controls so a manual change here can't be overwritten later. Depending on how your sync is set up, you may find that adding or removing members, renaming a group, or creating and deleting groups is disabled, with a note explaining why. In that case, make those changes in your identity provider instead.

