Skip to main content

Access Needed to Manage Groups

EmpowerID controls access to group management operations through Management Roles. To work with groups, users must be assigned the appropriate roles based on the operations they need to perform and the scope of their responsibilities.

Management Role Prefixes

Management Roles in EmpowerID use prefixes that indicate their function:

  • UI – Grants access to specific user interface elements and workflows
  • VIS – Grants visibility to specific objects in EmpowerID
  • ACT – Grants the ability to manage specific objects

Group Management Scope

Group management roles are scoped in different ways to align with organizational delegation models:

  • MyLocations – Manage groups in the same locations as the user
  • MyOrg – Manage groups in the same organizations as the user
  • System-specific – Manage groups in specific systems (AD, Azure, AWS, etc.)
  • All – Manage groups across all systems and locations
note

If a user has UI and VIS roles but not ACT roles for a specific operation, the requested change will route for approval to someone with the necessary ACT role.

Roles for Managing Group Memberships in Your Locations

These roles allow users to add and remove members from groups in their locations without requiring approval.

Management RoleAccess GrantedRole Type
UI-Account-Membership-ManagementAccess to user interfaces and workflows for viewing accounts and managing account group membershipsFeature Set (UI)
VIS-Accounts-MyLocationsVisibility for all user accounts in the same locations as the userVisibility (VIS)
ACT-Account-Membership-Management-MyLocationsManage membership for user accounts in the same locations as the userActivity (ACT)
tip

Accounts can only be added to groups that belong to the same domain.

Management RoleAccess GrantedRole Type
UI-Group-Membership-ManagementAccess to user interfaces and workflows for viewing groups and managing group membershipsFeature Set (UI)
Distribution Groups
VIS-Groups-Distribution-MyLocationVisibility for all distribution groups in the same locations as the userVisibility (VIS)
ACT-Group-Membership-Management-Distribution-MyLocationsManage membership for distribution groups in the same locations as the userActivity (ACT)
Generic Groups
VIS-Groups-Generic-MyLocationVisibility for all generic groups in the same locations as the userVisibility (VIS)
ACT-Group-Membership-Management-Generic-MyLocationsManage membership for generic groups in the same locations as the userActivity (ACT)
Security Groups
VIS-Groups-Security-MyLocationsVisibility for all security groups in the same locations as the userVisibility (VIS)
ACT-Group-Membership-Management-Security-MyLocationsManage membership for security groups in the same locations as the userActivity (ACT)

Roles for Managing Group Memberships in Your Organization

These roles allow users to add and remove members from groups in their organizations without requiring approval.

Management RoleAccess GrantedRole Type
UI-Account-Membership-ManagementAccess to user interfaces and workflows for managing account group membershipsFeature Set (UI)
VIS-Accounts-MyOrgVisibility for all user accounts in the same organizations as the userVisibility (VIS)
ACT-Account-Membership-Management-MyOrgManage membership for user accounts in the same organizations as the userActivity (ACT)
UI-Group-Membership-ManagementAccess to user interfaces and workflows for managing group membershipsFeature Set (UI)
Distribution Groups
VIS-Groups-Distribution-MyOrgVisibility for distribution groups in the same organizations as the userVisibility (VIS)
ACT-Group-Membership-Management-Distribution-MyOrgManage membership for distribution groups in the same organizations as the userActivity (ACT)
Generic Groups
VIS-Groups-Generic-MyOrgVisibility for generic groups in the same organizations as the userVisibility (VIS)
ACT-Group-Membership-Management-Generic-MyOrgManage membership for generic groups in the same organizations as the userActivity (ACT)
Security Groups
VIS-Groups-Security-MyOrgVisibility for security groups in the same organizations as the userVisibility (VIS)
ACT-Group-Membership-Management-Security-MyOrgManage membership for security groups in the same organizations as the userActivity (ACT)

Roles for Creating, Updating, and Deleting Groups in Your Organization

These roles allow users to create, modify, and delete groups in their organizations.

Management RoleAccess GrantedRole Type
UI-Group-Object-AdministrationAccess to user interfaces and workflows for creating, updating, and deleting groupsFeature Set (UI)
VIS-Groups-Distribution-MyOrgVisibility for distribution groups in the same organizations as the userVisibility (VIS)
VIS-Groups-Generic-MyOrgVisibility for generic groups in the same organizations as the userVisibility (VIS)
VIS-Groups-Security-MyOrgVisibility for security groups in the same organizations as the userVisibility (VIS)
ACT-Group-Object-Administration-MyOrgCreate, edit, and delete groups in the same organizations as the userActivity (ACT)

Roles for Managing Groups in Specific Systems

In addition to the UI-Group-Object-Administration role, users need system-specific visibility and activity roles:

Active Directory Groups

Management RoleAccess GrantedRole Type
VIS-Groups-All-ADVisibility for all Active Directory groupsVisibility (VIS)
ACT-Group-Object-Administration-ADCreate, edit, and delete all Active Directory groupsActivity (ACT)

Azure Groups

Management RoleAccess GrantedRole Type
VIS-Groups-All-AzureVisibility for all Azure groupsVisibility (VIS)
ACT-Group-Object-Administration-AllCreate, edit, and delete all groups, including groups in AzureActivity (ACT)

AWS Groups

Management RoleAccess GrantedRole Type
VIS-Groups-All-AWSVisibility for all AWS groupsVisibility (VIS)
ACT-Group-Object-Administration-AWSCreate, edit, and delete all AWS groupsActivity (ACT)

Office 365 Groups

Management RoleAccess GrantedRole Type
VIS-Accounts-O365Visibility for all Office 365 groupsVisibility (VIS)
ACT-Account-Object-Administration-O365Create, edit, and delete accounts in Office 365Activity (ACT)

SAP Groups

Management RoleAccess GrantedRole Type
VIS-Groups-SAPVisibility for all SAP roles and profilesVisibility (VIS)
ACT-Group-Object-Administration-AllCreate, edit, and delete all groups, including those in SAPActivity (ACT)

Groups Under All IT Systems

Management RoleAccess GrantedRole Type
VIS-Groups-All-IT-SystemsVisibility for all groups under the All IT Systems locationVisibility (VIS)
ACT-Group-Object-Administration-AllCreate, edit, and delete all groups, including those under All IT SystemsActivity (ACT)

Roles for Managing Groups Across All Systems

These roles grant broad access to manage groups across all systems and locations.

Management RoleAccess GrantedRole Type
UI-Group-Object-AdministrationAccess to user interfaces and workflows for creating, updating, and deleting groupsFeature Set (UI)
VIS-Groups-AllVisibility for all groupsVisibility (VIS)
ACT-Group-Object-Administration-AllCreate, edit, and delete all groups anywhereActivity (ACT)