Open Settings > Access Groups. This area requires Full Access and Manage Permissions.
Access groups restrict protected content such as updates, attachments, and configured subject fields after normal case and record access checks pass.
Active groups appear in supported visibility selectors for assigned roles. Inactive or archived groups can continue protecting existing content, but should not be selected for new visibility assignments. Set each role's Default Group under Roles & Permissions, not on the Access Groups page.
Review the usage information before retiring a group. Linked protected records can prevent deletion. Archive or deactivate an in-use group when appropriate, preserving the access boundary on existing content.
A group named Public is a workspace visibility label; the name alone does not publish records to the internet. Conversely, giving a client or vendor role access to an internal group may expose protected records they could not previously see. Review role mappings deliberately.