Groups
A group is a named set of people that carries access as a unit. Put someone in the group and they inherit what the group holds; take them out and they lose it. This page creates one, fills it, and gives it permissions. Fifteen minutes.
Groups or teams? Pick before you build
BigLedger has both, they look almost identical, and the difference is one that matters:
| Group | Team | |
|---|---|---|
| Scoped to a tenant | No — it is platform-wide | Yes, you pick the tenant when you create it |
| E-mail address | Fixed domain, @groups.akaun.net | Any address you give it |
| Status field on creation | No | Yes |
| Everything else — members, ranks, invitations, role links | The same | The same |
Use a team for “the cashiers at GadgetSphere’s Klang Valley branches” — people doing a job inside one tenant. That is what most readers want, and it is covered in teams and permissions.
Use a group where the set of people spans tenants, or where you want a standing platform-level collection that is not tied to one company’s books.
If you are not sure, you want a team.
Meet GadgetSphere
GadgetSphere Sdn Bhd runs three companies in one tenant and shares a small central finance function across all three. That central team is the case for a group: the same handful of people, the same access, regardless of which company’s books they are in.
Before you start
- Owner or Admin rank. Member rank can look but not change.
- Everyone you intend to add has already signed up at akaun.com. A person becomes selectable only once their e-mail exists on the platform.
- You know what the group is for — one sentence. If you cannot write it, you are probably building the wrong thing.
Step 1: Create the group
Group Maintenance applet > Create
| Field | What to put in it |
|---|---|
| Group Name | Plain English, at least four characters. GadgetSphere Central Finance |
| Group Code | At least four characters; letters, digits, underscore and full stop only. GS_FIN_CENTRAL |
| Group Email | The local part only — the domain is fixed at @groups.akaun.net and you cannot change it. At least six characters, and the same character set as the code |
| Group Description | Required, at least four characters. This is the one sentence from Before you start |
| Group Visibility | All members of the group, or Anyone on the web |
| Group Joining | Only invited users, Anyone can ask, or Anyone on the web |
Click Create.
The Group Code is what you will be reading in audit trails years from now. Spend the extra ten seconds naming it.
Step 2: Get people into it
The group > people > Manage group members
Three routes in:
- Direct add members — you add them by e-mail address.
- Invite members — you invite, they accept. Outstanding invites shows what is still pending.
- Join requests — they ask, you approve. Only if the Joining setting allows it.
Each member carries a rank and a status:
| Rank | What it means |
|---|---|
| Member | In the group; inherits its access |
| Admin | Can administer the group — members and permissions |
| Owner | Full control of the group |
Status is Active or Not Active. Setting somebody to Not Active is the right way to suspend access without losing the record of their membership.
Ranks settings is where the rank behaviour itself is configured.
Step 3: Attach the permissions
The group > settings > Manage group permissions
The chain is: permissions → permission sets → roles → the group. You do not grant a permission to a group directly; you link the group to roles that already carry the right sets.
Roles and permission sets are built in the Tenant Admin applet, where each permission set is scoped to a target — a company, a branch or a location — on the Branch, Company and Location sub-tabs. A permission set with no target is unscoped and confers access to everything.
List permissions on the group shows what the linked roles actually confer. Check it after every change: a role that reads correctly on paper frequently is not.
Step 4: Test it on one person
Configure one test user in the group, sign in as them, and try to do the thing they should not be able to do. Three checks, two minutes. Roll out only when all three behave.
This is not optional diligence. An unscoped permission set is invisible until somebody exercises it.
What success looks like
Thirty seconds, signed in as one ordinary member of the group:
- They can do the thing the group exists for.
- They cannot do the thing outside its scope — and get nothing back, not an error.
- List permissions on the group matches what you intended, line for line.
Common mistakes
| What goes wrong | Why | The fix |
|---|---|---|
| Built a group where a team was wanted | Groups are platform-wide; teams are scoped to a tenant | Use a team for people doing a job inside one tenant |
| Joining left open | Anyone on the web means anyone | Set Only invited users |
| Permission sets with no target | Unscoped means everything | Scope on the Branch / Company / Location sub-tabs in Tenant Admin |
| Adding people before the permissions are right | They inherit whatever the group currently holds | Permissions first, people second |
A code like GRP1 | Unreadable in an audit trail three years later | Name it for what it is |
| Deleting a member instead of deactivating | The record of their membership goes with them | Set status to Not Active |
| Never reviewing it | Staff move and leave | A quarterly pass over who holds what takes fifteen minutes |