> ## Documentation Index
> Fetch the complete documentation index at: https://docs.northernlogic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Groups and team vaults

> Manage shared access for a department, project team, or service.

Groups and team vaults are available on Teams and supported Partner workspaces.
Workspace owners and admins manage groups.

## Create and populate a group

1. Open **Team** and choose its groups view.
2. Create a named group such as Operations.
3. Open it and use **Add member** to choose active people or agents.
4. Select a shared vault and choose Viewer, Editor, or Vault admin for the
   group.
5. Verify the members can open the expected vault.

You can also add or remove a group assignment from an individual person's
record.

A group does not automatically create a vault. Create a team vault separately in
**Knowledge → Vault → + New vault**, then grant access to the group.

## How effective access works

Group grants combine with direct vault grants and workspace administration. The
strongest applicable role wins. For example, removing someone from a Viewer
group does not remove a direct Editor grant they still hold.

Workspace owners and admins can administer company and team vaults even if they
are not in the group's membership list. Choose a personal vault for personal
knowledge that should not be implicitly available to organization
administrators.

## Boundaries

* Groups can contain people and service principals, but cannot contain other
  groups.
* Groups grant vault access, not workspace Owner or Admin roles.
* Personal vaults do not accept group grants.
* There is no automatic Everyone group.
* Disabling a member removes their group membership; the group's vault grants
  remain for its other members.

When auditing access, check direct grants, groups, and the person's workspace
role together. See [vault access](/collaboration/vault-access).
