Groups
Put people into groups to grant roles together, give a manager a view of them, and compare them in Insights.
A group is a named set of members. It does three things: everyone in it holds the roles assigned on it, a manager can be given a view of its members, and it is the unit Insights and Ask Joring compare people by. Groups are available on the Team plan and above.
Open People → Groups to see every group on the team, its member count, where its membership comes from, and the roles it confers.
What a group is
Every group has a name (unique on the team, case-insensitive), an optional description, members, zero or more roles, and zero or more managers. What differs between groups is who owns the name and the membership:
| Managed in Joring | Synced from your identity provider | |
|---|---|---|
| Name and members | Edited in Joring | Owned by the identity provider; Joring refuses edits |
| Description, roles, managers | Edited in Joring | Edited in Joring |
| Created by | An admin, from People → Groups | A push from the identity provider over SCIM |
A synced group carries a Synced from badge naming your connection. The rest of this page applies to both kinds; Synced groups covers what is different about them.
Create a group
From People → Groups, select New group, give it a name, and optionally a description. Creating, editing, and deleting groups needs the groups permission, which Admin, Co-owner, and IT admin carry.
Invites can add someone to groups when they accept. Pick the groups in the invite dialog on People → Members; only groups managed in Joring can be chosen, since a synced group's membership belongs to the identity provider.
Members
Add members from the group page; anyone on the team can be added, in any number of groups. Removing someone takes effect immediately, including any roles they held through the group. Someone who leaves the team drops out of every group's live membership, and rejoining brings their memberships back.
Roles through groups
Assign roles on the group page. Every live member holds them, and the person's sheet on People → Members lists each one as From group with the group's name.
- Roles stack. Someone in two groups holds both groups' roles, and roles from groups combine with roles granted directly on the person.
- A role from a group is not removed on the person. To take it away, remove the person from the group or unassign the role from the group.
- Admin, Billing admin, Auditor, IT admin, Security admin, and Trail author can be assigned on a group. Co-owner cannot; it is granted only by the Owner. Manager is bound to a group differently, as a group manager.
- You can only assign roles whose permissions you hold yourself, the same rule as granting a role by hand.
Group managers
The Manager role can be scoped to a group. Add a manager from the group page: that person holds the Manager role for this group and sees its members in organization insights. A person can manage several groups, and someone who also has direct reports sees their reporting line and their managed groups together.
Adding a group manager needs the same authority as granting the Manager role
by hand. Removing them from the group page removes that scope; deleting the
group removes it too, recorded as a role revocation with reason
group_deleted.
Groups in Insights and Ask Joring
Organization insights can be filtered to one or more groups, and the By
group view compares groups side by side on the same measures as the
members table. Ask Joring can list groups, read results by group, and read a
group's members. The insights endpoints take the same filter as group_ids,
a comma-separated list of group ids.
Groups do not widen what anyone can see: a manager filtering by group still sees only the people inside their scope.
Synced groups
With SCIM connected, groups your identity provider pushes appear under People → Groups with a Synced from badge naming the connection.
- The identity provider owns the name and the membership. Editing either
in Joring is refused with
group_managed_by_idp; change them in the provider. The description, roles, and managers stay editable in Joring. - Link by name. When the provider pushes a group whose name matches a
group managed in Joring, that group is taken over: its members are
replaced by the push, and its description, roles, and managers are kept.
The takeover is recorded as
team.group.linked. A push whose name matches another synced group is rejected as a uniqueness conflict. - Disconnect. Disconnect from your provider, on the group page, moves the group back to Joring management and keeps its members. The provider's requests for that group then return 404 until it pushes the group again, which links by name as above. Settings → SCIM → Connection has Move all to Joring management, which does this for every synced group at once.
- Deletion in the identity provider deletes the group in Joring with its memberships, its roles, and its managers' scope. Roles the members held through it end.
- Nested groups are not supported;
membersmust reference users.
Delete a group
Delete a group from its page. Its memberships, the roles it conferred, and its managers' scope go with it, and roles that members held through it end immediately. A synced group cannot be deleted in Joring: delete it in the identity provider, or disconnect it first.
Audit events
Group changes are recorded in the audit log under the Members category.
| Action | |
|---|---|
team.group.created | Group created in Joring |
team.group.updated | Name or description changed |
team.group.deleted | Group deleted |
team.group.members_added | Members added |
team.group.member_removed | Member removed |
team.group.roles_changed | Roles assigned on the group changed |
team.group.linked | The identity provider took over a group managed in Joring |
team.group.unlinked | Group moved to Joring management |
team.member.group_roles_changed | A person's roles from groups changed; carries added_roles, removed_roles, and the trigger |
team.role_grant.revoked with reason group_deleted | A group manager's scope removed with the group |
Wire operations from the identity provider are also recorded as
scim.group.* events.
The role catalog, and how roles from groups stack with direct grants.