Configuring Access Groups and Default Visibility

Open Settings > Access Groups. This area requires Full Access and Manage Permissions.

Access groups restrict protected content such as updates, attachments, and configured subject fields after normal case and record access checks pass.

Create or edit a group

  1. Create a group or edit an existing one.
  2. Enter a clear name and description explaining what content belongs in the group.
  3. Set its Active state.
  4. Select the roles that can use it.
  5. Save and review a representative protected record with the intended role.

Active groups and default groups

Active groups appear in supported visibility selectors for assigned roles. Inactive or archived groups can continue protecting existing content, but should not be selected for new visibility assignments. Set each role's Default Group under Roles & Permissions, not on the Access Groups page.

Archiving and deletion

Review the usage information before retiring a group. Linked protected records can prevent deletion. Archive or deactivate an in-use group when appropriate, preserving the access boundary on existing content.

Common misunderstanding

A group named Public is a workspace visibility label; the name alone does not publish records to the internet. Conversely, giving a client or vendor role access to an internal group may expose protected records they could not previously see. Review role mappings deliberately.