Create and populate a group
- Open Team and choose its groups view.
- Create a named group such as Operations.
- Open it and use Add member to choose active people or agents.
- Select a shared vault and choose Viewer, Editor, or Vault admin for the group.
- Verify the members can open the expected vault.
How effective access works
Group grants combine with direct vault grants and workspace administration. The strongest applicable role wins. For example, removing someone from a Viewer group does not remove a direct Editor grant they still hold. Workspace owners and admins can administer company and team vaults even if they are not in the group’s membership list. Choose a personal vault for personal knowledge that should not be implicitly available to organization administrators.Boundaries
- Groups can contain people and service principals, but cannot contain other groups.
- Groups grant vault access, not workspace Owner or Admin roles.
- Personal vaults do not accept group grants.
- There is no automatic Everyone group.
- Disabling a member removes their group membership; the group’s vault grants remain for its other members.