Group-based access control — group admins, member management, dataset and recipe sharing
User groups provide organisational structure for multi-user Workbench instances. Groups have administrators (who manage the group), members (who belong to the group), and a defined scope (which datasets, recipes, and connections are visible to the group). Every user belongs to at least one group.
| Role | Permissions |
|---|---|
| System Admin | Create groups, assign group admins, manage all users and groups. System-wide privileges. |
| Group Admin | Manage their group's members (add, remove, change roles), create datasets and recipes for the group, control sharing settings for group-owned resources. |
| Group Member | Create and run recipes using group-accessible datasets. Share their own datasets and recipes with the group. Cannot manage members or delete group resources. |
Resources (datasets, recipes, database connections) can be shared with a group. When shared: all group members can see and use the resource, the group admin controls the sharing level (read-only or read-write), and resources can be unshared without affecting other groups. Group sharing is the primary model for multi-user collaboration in the Workbench.
The Groups tab in Admin (accessible to system admins and group admins) provides: a list of all groups (filtered by admin's scope), member management with add/remove/role-change, resource ownership and sharing settings, and group activity logs showing who accessed what and when.