
## What are groups?

URL: https://docs.atlan.com/product/capabilities/governance/access-control/concepts/what-are-groups

> Groups in Atlan bundle users together so you can assign personas, purposes, and roles to a whole team at once instead of editing individuals one by one.

# What are groups?

Groups bundle users together so you can assign access in bulk. Instead of attaching every persona, purpose, or role to individual users, you put users into a group once and assign the group. Every member inherits that access automatically.

## Why use groups

Groups let you manage access by team instead of one user at a time.

 Change access by moving users between groups, not by editing dozens of policies.

 A team always has the same access, regardless of which individual joins.

 New users inherit the group's access on day one, with no manual setup per user.

 Keep membership aligned with Okta, Azure AD, Google, or any OIDC/SAML provider.

Reach for a group when you want to give a whole team the same persona or purpose, when IdP group membership should drive Atlan access, when a new hire needs the right access on day one, or when you want to revoke a leaver's access in one place instead of editing every policy.

## How groups work

Create a group, add users, then assign that group to a persona, purpose, or role. Every member inherits the access automatically, and so does anyone you add later.

 <svg viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2">
Marketing Analysts SA Sarah TO Tom LI Lisa assigned once to Access objects persona · purpose · role Marketing persona PII purpose Member role Result: Assign the Marketing Analysts group to a persona, purpose, or role once, and Sarah, Tom, and Lisa all inherit it. Anyone added to the group later gets the same access automatically, and removing someone revokes it on their next sign-in.

Membership can be **static** (you add and remove users manually) or **dynamic** (driven by rules or synced from your identity provider). Either way, a group does not grant access on its own. It is a convenience layer for assigning personas, purposes, and roles to many users at once.

## Manage groups

 Create groups, add users, and delete groups you no longer need.

 Map identity-provider groups to Atlan groups so membership updates on every sign-in.

 Assign users to groups automatically based on job title or designation.

 Use the User Role Sync app to set each user's role from their group membership.

## See also

- [Scope team access (personas)](https://docs.atlan.com/llms/governance/access-control/what-are-personas/llms.txt): Assign a group to a persona to give a whole team a scoped view.
- [Protect sensitive data (purposes)](https://docs.atlan.com/llms/governance/access-control/what-are-purposes/llms.txt): Assign a group to a purpose for tag-based access.
- [Add and manage users](https://docs.atlan.com/llms/governance/access-control/add-and-manage-users/llms.txt): The roles and user lifecycle that groups build on.
- [Permissions & data access](https://docs.atlan.com/llms/governance/access-control/permissions-and-data-access/llms.txt): How personas, purposes, and roles combine.

---
