Skip to content

Groups

A group is a named set of people that carries access as a unit. Put someone in the group and they inherit what the group holds; take them out and they lose it. This page creates one, fills it, and gives it permissions. Fifteen minutes.

Groups or teams? Pick before you build

BigLedger has both, they look almost identical, and the difference is one that matters:

GroupTeam
Scoped to a tenantNo — it is platform-wideYes, you pick the tenant when you create it
E-mail addressFixed domain, @groups.akaun.netAny address you give it
Status field on creationNoYes
Everything else — members, ranks, invitations, role linksThe sameThe same

Use a team for “the cashiers at GadgetSphere’s Klang Valley branches” — people doing a job inside one tenant. That is what most readers want, and it is covered in teams and permissions.

Use a group where the set of people spans tenants, or where you want a standing platform-level collection that is not tied to one company’s books.

If you are not sure, you want a team.

Meet GadgetSphere

GadgetSphere Sdn Bhd runs three companies in one tenant and shares a small central finance function across all three. That central team is the case for a group: the same handful of people, the same access, regardless of which company’s books they are in.

Before you start

  • Owner or Admin rank. Member rank can look but not change.
  • Everyone you intend to add has already signed up at akaun.com. A person becomes selectable only once their e-mail exists on the platform.
  • You know what the group is for — one sentence. If you cannot write it, you are probably building the wrong thing.

Step 1: Create the group

Group Maintenance applet > Create

FieldWhat to put in it
Group NamePlain English, at least four characters. GadgetSphere Central Finance
Group CodeAt least four characters; letters, digits, underscore and full stop only. GS_FIN_CENTRAL
Group EmailThe local part only — the domain is fixed at @groups.akaun.net and you cannot change it. At least six characters, and the same character set as the code
Group DescriptionRequired, at least four characters. This is the one sentence from Before you start
Group VisibilityAll members of the group, or Anyone on the web
Group JoiningOnly invited users, Anyone can ask, or Anyone on the web

Click Create.

Set Joining to Only invited users unless you have a specific reason not to. Anyone on the web means exactly that. For any group that will carry access to customer or financial data, invitation-only is the only defensible setting.

The Group Code is what you will be reading in audit trails years from now. Spend the extra ten seconds naming it.

Step 2: Get people into it

The group > people > Manage group members

Three routes in:

  • Direct add members — you add them by e-mail address.
  • Invite members — you invite, they accept. Outstanding invites shows what is still pending.
  • Join requests — they ask, you approve. Only if the Joining setting allows it.

Each member carries a rank and a status:

RankWhat it means
MemberIn the group; inherits its access
AdminCan administer the group — members and permissions
OwnerFull control of the group

Status is Active or Not Active. Setting somebody to Not Active is the right way to suspend access without losing the record of their membership.

Ranks settings is where the rank behaviour itself is configured.

Step 3: Attach the permissions

The group > settings > Manage group permissions

The chain is: permissions → permission setsroles → the group. You do not grant a permission to a group directly; you link the group to roles that already carry the right sets.

Roles and permission sets are built in the Tenant Admin applet, where each permission set is scoped to a target — a company, a branch or a location — on the Branch, Company and Location sub-tabs. A permission set with no target is unscoped and confers access to everything.

List permissions on the group shows what the linked roles actually confer. Check it after every change: a role that reads correctly on paper frequently is not.

Step 4: Test it on one person

Configure one test user in the group, sign in as them, and try to do the thing they should not be able to do. Three checks, two minutes. Roll out only when all three behave.

This is not optional diligence. An unscoped permission set is invisible until somebody exercises it.

What success looks like

Thirty seconds, signed in as one ordinary member of the group:

  1. They can do the thing the group exists for.
  2. They cannot do the thing outside its scope — and get nothing back, not an error.
  3. List permissions on the group matches what you intended, line for line.

Common mistakes

What goes wrongWhyThe fix
Built a group where a team was wantedGroups are platform-wide; teams are scoped to a tenantUse a team for people doing a job inside one tenant
Joining left openAnyone on the web means anyoneSet Only invited users
Permission sets with no targetUnscoped means everythingScope on the Branch / Company / Location sub-tabs in Tenant Admin
Adding people before the permissions are rightThey inherit whatever the group currently holdsPermissions first, people second
A code like GRP1Unreadable in an audit trail three years laterName it for what it is
Deleting a member instead of deactivatingThe record of their membership goes with themSet status to Not Active
Never reviewing itStaff move and leaveA quarterly pass over who holds what takes fifteen minutes

Related documentation

Last updated on