> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.2/3.-guide-to-navigation/3.5-groups.md).

# 3.5 Groups

#### What Is a Group in Ztrust?

Group in ztrust a collection of users that can share common roles, attributes, and access controls. Rather than assigning roles to each user individually, you can assign them to a group and all users in that group will inherit them

Group role inheritance is dynamic: When you add/remove roles from a group, all users in that group are immediately affected.

A user can belong to multiple groups.

<figure><img src="/files/CrM1UhrLB20sVOKuezXs" alt=""><figcaption><p>Fig 3.5.a: Groups Section </p></figcaption></figure>

Under the Groups tab, users have the ability to create various groups to accommodate specific sets of users.

You can use the search box to find a specific user.

You also have the option to go for Exact Search.

Click the Refresh button to see the latest settings.

<figure><img src="/files/MuyB8C47tl4N0oq5Nr8f" alt=""><figcaption><p>Fig 3.5.b: Choose how many groups you want to display on one screen</p></figcaption></figure>

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

<figure><img src="/files/SzU1lU7uEZQpACwc1fGf" alt=""><figcaption><p>Fig 3.5.c: No groups in this realm</p></figcaption></figure>

#### **Create group**

Click on the Create group option to generate a new group.

<figure><img src="/files/ueQEfEqNpUUassaOEHMb" alt=""><figcaption><p>Fig 3.5.d: Create a new group</p></figcaption></figure>

Choose any Name you like and form the group. For example - demo

Click on Create to establish the group, or click Cancel to abort the operation. Upon selecting Create, you will be directed to the screen below.

<figure><img src="/files/qyAnKkIxFNdwILR8dFTa" alt=""><figcaption><p>Fig 3.5.e: Group created</p></figcaption></figure>

<figure><img src="/files/tIQYKXcMVgzFRHkss1AU" alt=""><figcaption><p>Fig 3.5.f: Edit options for group</p></figcaption></figure>

After clicking on the three dots, the following options are visible:

* Rename - After selecting Rename, you will see the following prompt

<figure><img src="/files/mOjRQ1t5edNvx88ZX3BI" alt=""><figcaption><p>Fig 3.5.g: Rename group</p></figcaption></figure>

Enter the desired name for the group.

Click Rename to confirm the new name or Cancel to discard the change.

* Move to - After selecting Move to, the following prompt will appear:

<figure><img src="/files/QXs2xuD2L8Zj0CfnWgte" alt=""><figcaption><p>Fig 3.5.h: Move group to Root</p></figcaption></figure>

Choose the specific group where you want to move your group.

<figure><img src="/files/LOGgkTgQaT1MyIvoOMtm" alt=""><figcaption><p>Fig 3.5.i: Click Move here to confirm</p></figcaption></figure>

Then click Move here to confirm the action.

* Create child group - After selecting this option, the following prompt will appear:

<figure><img src="/files/git6I6dutwXZxNvuePSl" alt=""><figcaption><p>Fig 3.5.j: Create child group</p></figcaption></figure>

Enter any name according to your requirements. Click Create to create the child group, or click Cancel to discard.

<figure><img src="/files/52nFv4GKexEUEhhQyCdx" alt=""><figcaption><p>Fig 3.5.k: Child group created</p></figcaption></figure>

The new group will be created inside the previous group. For example, childgroup\_demo2 will be created inside the rename\_demo group.

* Delete - After selecting Delete, the following confirmation prompt will appear:

<figure><img src="/files/EQ0BxxMVGLD9dEjYeghf" alt=""><figcaption><p>Fig 3.5.l: Confirmation to delete</p></figcaption></figure>

Click Delete to remove the group, or click Cancel to abort the action.

<figure><img src="/files/tp7Dbk73YnOIDAHdPgih" alt=""><figcaption><p>Fig 3.5.j: Available groups</p></figcaption></figure>

You can use the filter groups box to find a specific group.

Click the Refresh button to see the latest settings.

<figure><img src="/files/fnhzM9eAJxEE0VhLptNO" alt=""><figcaption><p>Fig 3.5.k: Choose how many groups you want to display on one screen</p></figcaption></figure>

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

<figure><img src="/files/LCDqSGkbKuL5kJVOcxk1" alt=""><figcaption><p>Fig 3.5.l: To delete multiple groups at once</p></figcaption></figure>

To delete multiple groups at once, select each group by clicking the checkbox next to it. Then, click Delete.

A confirmation prompt will appear.

&#x20;

<figure><img src="/files/1If8xI1JrsiAll9lgP0d" alt=""><figcaption><p>Fig 3.5.m: Confirmation to delete</p></figcaption></figure>

Click Delete to confirm the deletion, or click Cancel to abort.

<figure><img src="/files/ZwsozKT0R3NhWS9IyWT8" alt=""><figcaption><p>Fig 3.5.n: Child group</p></figcaption></figure>

#### **Child groups**

#### **Create group**

To create a new child group, click on Create Group.

<figure><img src="/files/POb7TtgLIvsg576JG48u" alt=""><figcaption><p>Fig 3.5.o: Creating new chaild group</p></figcaption></figure>

Enter the desired name.

Click Create to make the group, or Cancel to discard.

<figure><img src="/files/3cIizoJloi3Vxf3xJY4U" alt=""><figcaption><p>Fig 3.5.p: Available child groups</p></figcaption></figure>

You can use the filter groups box to find a specific group.

Click the Refresh button to see the latest settings.

<figure><img src="/files/Q7PuwI2Ms8NX0CsGOH5Z" alt=""><figcaption><p>Fig 3.5.q: Choose how many groups you want to display on one screen</p></figcaption></figure>

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

#### **Members**

<figure><img src="/files/QVEZQsxJJO9RYfWz6I6a" alt=""><figcaption><p>Fig 3.5.r: Users assigned to this group</p></figcaption></figure>

After selecting Add member, you will be taken to the following screen.

<figure><img src="/files/irRCLNBEJ1qfIRfbXBnx" alt=""><figcaption><p>Fig 3.5.s: List of users under same realm</p></figcaption></figure>

Select the desired users by clicking the checkbox next to their names, then click Add.

<figure><img src="/files/OUuDa4ApNLKdHgOdzi7R" alt=""><figcaption><p>Fig 3.5.t: Clicking the checkbox next to their names to add into group</p></figcaption></figure>

You'll find the specific user within this group.

<figure><img src="/files/kdPAflJ0jL6dvtCfzQoT" alt=""><figcaption><p>Fig 3.5.u: User added into group</p></figcaption></figure>

#### **Name**

This is the name used by the user during creation.

It can also be used for logging into ZTrust.

#### **Email**

The user's provided Email address during registration or in case the user has been created by the Admin. It can also be used for logging into ZTrust.

#### **First Name**

The user's First Name or the First Name provided during registration.

**Last Name**

The Last Name provided by the user during registration, or the user's last name.

#### **Membership**

<figure><img src="/files/SYIeP2ZyBo3EVkmhcmk8" alt=""><figcaption><p>Fig 3.5.v: Option to remove the user</p></figcaption></figure>

To remove the specific user from the group, simply click the Leave button.

#### **Attributes**

<figure><img src="/files/A03f4ENzF2Fv4iCZE7Kq" alt=""><figcaption><p>Fig 3.5.w: Group attributes tab</p></figcaption></figure>

Within the Attributes section, you have the ability to define any variable you require for the entire Group.

Click on Add attributes.

<figure><img src="/files/E9ZbmBHVwc6UDuCd9dR6" alt=""><figcaption><p>Fig 3.5.x: Adding attribute to group</p></figcaption></figure>

Just provide the Key, which is the variable you want to define, and then input its corresponding Value.

Click Add attribute to save the Key-Value pair.

To delete the Key-Value pair, click on the '-' symbol.

Click on Save to keep these alterations, and click on Revert to discard any changes made.

#### **Role mapping**

<figure><img src="/files/FyucLYCiJPAzoyjBvSOp" alt=""><figcaption><p>Fig 3.5.y: Group role mapping tab</p></figcaption></figure>

Upon selecting the Assign role, you will be directed to the following screen.

<figure><img src="/files/1yGMPHmG39DnMqZq8uUe" alt=""><figcaption><p>Fig 3.5.z: Add role to group</p></figcaption></figure>

You can use the search box to find a specific group.

Click the Refresh button to see the latest settings.

<figure><img src="/files/HdGiFPGZ0uZQjOWPFbbf" alt=""><figcaption><p>Fig 3.5.Aa: Choose how many groups you want to display on one screen</p></figcaption></figure>

You can also choose how many groups you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

<figure><img src="/files/G2bDsgksXTN2pghGi2Tb" alt=""><figcaption><p>Fig 3.5.Ab: Add realm role to group</p></figcaption></figure>

You can then select the checkbox for the specific role you want to assign to this group. Click on the checkbox to select the role, then click on Assign.&#x20;

If you decide not to associate the selected roles, click on Cancel to discard the changes.

<figure><img src="/files/LMPYtEko6QDNeu8tGNWz" alt=""><figcaption><p>Fig 3.5.Ac: Filter tab to clients roles</p></figcaption></figure>

You also have the option to filter roles based on the clients.

<figure><img src="/files/97tHuf8DzKK6oSZ4b1LE" alt=""><figcaption><p>Fig 3.5.Ad: List of client roles</p></figcaption></figure>

You can then select the checkbox for the specific role you want to assign to this group. Click on the checkbox to select the role, then click on Assign.&#x20;

If you decide not to associate the selected roles, click on Cancel to discard the changes.

After clicking on Assign, you can see the below screen.

<figure><img src="/files/JyR1wmApUx20pCv41gF4" alt=""><figcaption><p>Fig 3.5.Ae: Role added to group</p></figcaption></figure>

You can use the search box to find a specific role.

Click the Refresh button to see the latest settings.

<figure><img src="/files/isLLyljPZ04ebwmTLp2B" alt=""><figcaption><p>Fig 3.5.Af:  Choose how many roles you want to display on one screen</p></figcaption></figure>

You can also choose how many roles you want to display on one screen. Select your preferred option from the dropdown menu as shown above.

#### **Hide inherited roles**

Selecting this checkbox hides inherited roles, preventing you from seeing roles inherited from composites. To view inherited roles, simply uncheck this option.

#### **Name**

It includes the list of all the different roles that are already defined in ZTrust.

#### **Inherited**

This pertains to roles explicitly assigned to users and those inherited from composite roles. It can have two values: True (indicating the role is inherited from composites) or False (indicating it is not inherited from any composite role).

#### **Description**

It refers to the description for the role which will aid you in identifying its purpose.

This field can be localized by specifying a substitution variable with ${var-name} strings.

<figure><img src="/files/PCdq7N227RHLlDmisSFv" alt=""><figcaption><p>Fig 3.5.Ag: Option to remove role to group</p></figcaption></figure>

Upon clicking on the three dots, you will find the Unassign option.

When you click on Unassign, a confirmation prompt will appear.

<figure><img src="/files/NV00Xl9G30BmHRXle13G" alt=""><figcaption><p>Fig 3.5.Ah: Confirmation to remove</p></figcaption></figure>

If you wish to unassign a specific role from this group, click on Remove. Otherwise, click Cancel.

<figure><img src="/files/Vo6CvJ2M0xgFV4v1sbWg" alt=""><figcaption><p>Fig 3.5.Ai: To unassign multiple roles simultaneously</p></figcaption></figure>

To unassign multiple roles simultaneously, first, select the specific roles by clicking on the checkboxes next to them. Then, click on Unassign.

<figure><img src="/files/YXa1Yow4wEHfXD19U8hp" alt=""><figcaption><p>Fig 3.5.Aj: Confirmation to remove</p></figcaption></figure>

You'll receive a confirmation prompt similar to the one shown above. To unassign the roles, click on Remove. Otherwise, click on Cancel.

<br>
