# Using groups

A group is a workspace-local collection of members that can receive connector access together. Use groups for responsibilities that several people share, such as reviewers, month-end operators, or an external team. Group membership does not change anyone's workspace role.

Groups and API keys are included in the Growth and Enterprise plans. See [pricing](/pricing).

## Who can do what

- Every active workspace member can view enabled groups, their members, and their connector access.
- Admins and owners can create or deactivate groups, add or remove members, and manage group connector access.
- A group belongs to one workspace and cannot contain people from another workspace.

## Create and staff a group

1. Open **Groups** under **Admin**.
2. Select **New group**, then give it a clear name and optional description.
3. Open the new group and select **Add member** on the **Members** tab.
4. Add only people who should inherit every connector grant on that group.

You can also open a person under **Team**, choose their **Groups** tab, and add them to an existing group. Adding or removing a member changes their inherited access on the next request.

## Give a group connector access

You can grant access from either direction:

- Open the group, choose **Connector access**, and add an enabled connector; or
- open a connector, choose **Access**, select **Grant access**, and choose the group.

Every new grant starts with Read. Write and Destructive are independent opt-ins. The group's access drawer also controls which connected accounts its members may reach.

## How group access combines with direct access

Connector Central does not add every access level together:

- If a non-owner has a direct grant for a connector, that grant is the access-level authority, even when it is narrower than a group grant.
- Without a direct grant, the most capable active grant from the member's groups supplies the access level.
- Account blocks are deny-wins and are combined from the member and every qualifying group. A direct grant cannot reopen a connected account blocked through a group.
- Group grants never widen or narrow an owner's levels. An owner's direct restriction is the only grant that changes the owner's implicit all-level access.

The connector **Access** tab shows whether a person's effective access is direct or inherited and identifies overridden grants.

## Remove access safely

Removing a person from a group removes access inherited only through that membership. A direct grant or another qualifying group may still provide access, so review the person's connector list afterward.

Deactivating a group revokes its connector grants and removes its inherited access from every member immediately. Historical activity and access-change audit records remain attributable.

## Next steps

- [Understand roles and permissions](/docs/team-and-collaboration/understanding-roles-and-permissions)
- [Manage connectors, accounts, and access](/docs/connectors-and-access/connectors-accounts-and-access-grants)
- [Review workspace activity](/docs/connectors-and-access/activity-log)
