Using groups
A group is a workspace-local collection of members that can receive connector access together. Use groups for responsibilities that several people share, such as reviewers, month-end operators, or an external team. Group membership does not change anyone's workspace role.
Groups and API keys are included in the Growth and Enterprise plans. See pricing.
Who can do what
- Every active workspace member can view enabled groups, their members, and their connector access.
- Admins and owners can create or deactivate groups, add or remove members, and manage group connector access.
- A group belongs to one workspace and cannot contain people from another workspace.
Create and staff a group
- Open Groups under Admin.
- Select New group, then give it a clear name and optional description.
- Open the new group and select Add member on the Members tab.
- Add only people who should inherit every connector grant on that group.
You can also open a person under Team, choose their Groups tab, and add them to an existing group. Adding or removing a member changes their inherited access on the next request.
Give a group connector access
You can grant access from either direction:
- Open the group, choose Connector access, and add an enabled connector; or
- open a connector, choose Access, select Grant access, and choose the group.
Every new grant starts with Read. Write and Destructive are independent opt-ins. The group's access drawer also controls which connected accounts its members may reach.
How group access combines with direct access
Connector Central does not add every access level together:
- If a non-owner has a direct grant for a connector, that grant is the access-level authority, even when it is narrower than a group grant.
- Without a direct grant, the most capable active grant from the member's groups supplies the access level.
- Account blocks are deny-wins and are combined from the member and every qualifying group. A direct grant cannot reopen a connected account blocked through a group.
- Group grants never widen or narrow an owner's levels. An owner's direct restriction is the only grant that changes the owner's implicit all-level access.
The connector Access tab shows whether a person's effective access is direct or inherited and identifies overridden grants.
Remove access safely
Removing a person from a group removes access inherited only through that membership. A direct grant or another qualifying group may still provide access, so review the person's connector list afterward.
Deactivating a group revokes its connector grants and removes its inherited access from every member immediately. Historical activity and access-change audit records remain attributable.