{"title":"Role groups","category":"default","creationDate":1788519410,"content":"<p><span style=\"color: #0ABF53;\"><span style=\"font-size: 20px;\"><strong>Limited availability<\/strong><\/span><\/span><br \/>\nRole groups are in pilot phase. Some of the processes and documentation may change as the feature evolves.<\/p>\n<hr \/>\n<p>Role groups let you bundle multiple individual <a href=\"\/account\/user-roles\">roles<\/a> into a single package that you can assign to users. Instead of assigning roles one by one, create a role group based on a job function, such as \"Finance team\" or \"Risk analyst\", and assign it to everyone who needs the same access. This helps keep permissions consistent and makes user management easier as your organization grows.<\/p>\n<h2>Requirements<\/h2>\n<p>Before you begin, make sure that you meet the following requirements:<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\">Requirement<\/th>\n<th style=\"text-align: left;\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align: left;\"><strong>User role<\/strong><\/td>\n<td style=\"text-align: left;\">You need the <strong>Merchant admin<\/strong> or <strong>IAM admin<\/strong> <a href=\"\/account\/user-roles\">role<\/a>.<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Account level<\/strong><\/td>\n<td style=\"text-align: left;\">Role groups are managed at the company level in your <a href=\"https:\/\/ca-test.adyen.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Customer Area<\/a>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"admin-tiers\">Admin tiers<\/h2>\n<p>There are two tiers of admin access for managing users and permissions. The tier determines what an admin can do with <a href=\"\/account\/role-groups\">role groups<\/a> and individual <a href=\"\/account\/user-roles\">roles<\/a>:<\/p>\n<div class=\"sticky-table-container\">\n    \n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\">Admin tier<\/th>\n<th style=\"text-align: left;\">Roles in this tier<\/th>\n<th style=\"text-align: left;\">User management scope<\/th>\n<th style=\"text-align: left;\">Role group management<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align: left;\"><strong>Full admin<\/strong><\/td>\n<td style=\"text-align: left;\"><strong>Merchant admin<\/strong>, <strong>IAM admin<\/strong> (with company-level access)<\/td>\n<td style=\"text-align: left;\">Assign all roles and role groups available in the company account to users.<\/td>\n<td style=\"text-align: left;\">Create, edit, and delete role groups.<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Limited admin<\/strong><\/td>\n<td style=\"text-align: left;\"><strong>Merchant user management<\/strong><\/td>\n<td style=\"text-align: left;\">Assign only the roles and role groups that this admin already has.<\/td>\n<td style=\"text-align: left;\">Cannot create, edit, or delete role groups. Can assign role groups from the <strong>User details<\/strong> page.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n\n<\/div>\n\n<p>The <strong>Merchant admin<\/strong> role includes full user management alongside other administrative permissions, such as risk configuration and payment method management. If a user only needs to manage roles and role groups without those extra operational permissions, assign them the <strong>IAM admin<\/strong> role instead.<\/p>\n<div class=\"notices green\">\n<p>A <strong>Merchant admin<\/strong> user without company-level access has the same user management scope as a limited admin. The full admin tier requires company-level access.<\/p>\n<\/div>\n<div class=\"notices green\">\n<p>If you need permissions that neither you nor your full admin have, reach out to our <a href=\"https:\/\/ca-test.adyen.com\/ca\/ca\/contactUs\/support.shtml?form=other\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Support Team<\/a>.<\/p>\n<\/div>\n<h2 id=\"role-groups-and-individual-roles\">Role groups and individual roles<\/h2>\n<p>You can assign permissions to a user through role groups, individual roles, or a combination of both. The user receives the combined permissions from all assigned role groups and individual roles.<\/p>\n<p>For example, if a user has:<\/p>\n<ul>\n<li>A role group called \"Finance team\" that contains the <strong>Merchant financial<\/strong> and <strong>Download reports<\/strong> roles.<\/li>\n<li>An individually assigned <strong>View Payments<\/strong> role.<\/li>\n<\/ul>\n<p>The user has the permissions from all three roles.<\/p>\n<p>When you update a role group, the changes apply to all users that have the role group. For example, if you add the <strong>Merchant report<\/strong> role to the \"Finance team\" role group, all users with this role group receive the <strong>Merchant report<\/strong> permissions.<\/p>\n<h2>How it works<\/h2>\n<p>The following is an overview of how to set up and use role groups:<\/p>\n<ol>\n<li>You create a role group and select which individual roles to include.<\/li>\n<li>You assign the role group to one or more users.<\/li>\n<li>Each user receives the combined permissions from the role group and any individually assigned roles.<\/li>\n<li>When you update the role group, all users with that role group receive the updated permissions.<\/li>\n<\/ol>\n<h2 id=\"create\">Create a role group<\/h2>\n<p>You need <a href=\"#admin-tiers\">full admin<\/a> access to create a role group.<\/p>\n<p>To create a role group:<\/p>\n<ol>\n<li>Log in to your <a href=\"https:\/\/ca-test.adyen.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Customer Area<\/a>.<\/li>\n<li>Go to <strong>Account<\/strong> &gt; <strong>Role groups<\/strong>.<\/li>\n<li>Select <strong>Create role group<\/strong>.<\/li>\n<li>On the <strong>Details<\/strong> step, enter a <strong>Name<\/strong> for the role group, and optionally add a <strong>Description<\/strong>. Select <strong>Continue<\/strong>.<\/li>\n<li>On the <strong>Roles<\/strong> step, expand a role category and select the roles that you want to include. You can select roles from multiple categories. Select <strong>Continue<\/strong>.<\/li>\n<li>Optionally, on the <strong>Users<\/strong> step, search for and select users that you want to assign to this role group. Select <strong>Continue<\/strong>.<\/li>\n<li>On the <strong>Summary<\/strong> step, review the details, roles, and users. To make changes, select the edit icon next to a section.<\/li>\n<li>Select <strong>Create group<\/strong>.<\/li>\n<\/ol>\n<h2 id=\"assign\">Assign a role group to a user<\/h2>\n<p>Both <a href=\"#admin-tiers\">full and limited admins<\/a> can assign role groups to users. Limited admins can assign role groups from the <strong>User details<\/strong> page, but cannot create, edit, or delete role groups.<\/p>\n<p>You can assign role groups when you <a href=\"\/account\/users#create\">create a new user<\/a>, or add them to an existing user.<\/p>\n<p>To assign a role group to an existing user:<\/p>\n<ol>\n<li>Log in to your <a href=\"https:\/\/ca-test.adyen.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Customer Area<\/a>.<\/li>\n<li>Go to <strong>Account<\/strong> &gt; <strong>Users<\/strong>, and select the user from the <strong>User List<\/strong>.<\/li>\n<li>In the <strong>Role groups<\/strong> section, select the role groups to assign. You can only assign role groups that contain roles your own user already has.<\/li>\n<li>Select <strong>Save<\/strong>.<\/li>\n<\/ol>\n<p>The user now has the permissions from all roles in the assigned role groups, in addition to any individually assigned roles.<\/p>\n<h2 id=\"edit\">Edit a role group<\/h2>\n<p>You need <a href=\"#admin-tiers\">full admin<\/a> access to edit a role group. When you edit a role group, the changes apply to all users that have this role group.<\/p>\n<p>To edit a role group:<\/p>\n<ol>\n<li>Log in to your <a href=\"https:\/\/ca-test.adyen.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Customer Area<\/a>.<\/li>\n<li>Go to <strong>Account<\/strong> &gt; <strong>Role groups<\/strong>, and select the role group that you want to edit.<\/li>\n<li>Make your changes to the name, description, or included roles.<\/li>\n<li>Select <strong>Save<\/strong>.<\/li>\n<\/ol>\n<div class=\"notices yellow\">\n<p>When you remove a role from a role group, users who have that role only through this role group lose the corresponding permissions. Users who also have the role assigned individually are not affected.<\/p>\n<\/div>\n<h2 id=\"delete\">Delete a role group<\/h2>\n<p>You need <a href=\"#admin-tiers\">full admin<\/a> access to delete a role group. Before you delete a role group, check which users have this role group assigned to them. Users who have roles only through this role group lose those permissions after deletion.<\/p>\n<p>To delete a role group:<\/p>\n<ol>\n<li>Log in to your <a href=\"https:\/\/ca-test.adyen.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Customer Area<\/a>.<\/li>\n<li>Go to <strong>Account<\/strong> &gt; <strong>Role groups<\/strong>, and select the role group that you want to delete.<\/li>\n<li>Select <strong>Delete role group<\/strong>.<\/li>\n<li>Review the list of affected users, and then select <strong>Delete<\/strong> to confirm.<\/li>\n<\/ol>\n<h2>See also<\/h2>\n<div class=\"see-also-links output-inline\" id=\"see-also\">\n<ul><li><a href=\"\/account\/user-roles\"\n                        target=\"_self\"\n                        >\n                    User roles\n                <\/a><\/li><li><a href=\"\/account\/users\"\n                        target=\"_self\"\n                        >\n                    Manage users\n                <\/a><\/li><li><a href=\"\/account\/account-structure\"\n                        target=\"_self\"\n                        >\n                    Account structure\n                <\/a><\/li><\/ul><\/div>\n","url":"https:\/\/docs.adyen.com\/account\/role-groups","articleFields":{"description":"Learn how to use role groups to manage user permissions at scale.","feedback_component":true,"robots":"noindex,nofollow","filters_component":false,"page_id":"","decision_tree":"[]"},"algolia":{"url":"https:\/\/docs.adyen.com\/account\/role-groups","title":"Role groups","content":"Limited availability\nRole groups are in pilot phase. Some of the processes and documentation may change as the feature evolves.\n\nRole groups let you bundle multiple individual roles into a single package that you can assign to users. Instead of assigning roles one by one, create a role group based on a job function, such as \"Finance team\" or \"Risk analyst\", and assign it to everyone who needs the same access. This helps keep permissions consistent and makes user management easier as your organization grows.\nRequirements\nBefore you begin, make sure that you meet the following requirements:\n\n\n\nRequirement\nDescription\n\n\n\n\nUser role\nYou need the Merchant admin or IAM admin role.\n\n\nAccount level\nRole groups are managed at the company level in your Customer Area.\n\n\n\nAdmin tiers\nThere are two tiers of admin access for managing users and permissions. The tier determines what an admin can do with role groups and individual roles:\n\n    \n\n\n\nAdmin tier\nRoles in this tier\nUser management scope\nRole group management\n\n\n\n\nFull admin\nMerchant admin, IAM admin (with company-level access)\nAssign all roles and role groups available in the company account to users.\nCreate, edit, and delete role groups.\n\n\nLimited admin\nMerchant user management\nAssign only the roles and role groups that this admin already has.\nCannot create, edit, or delete role groups. Can assign role groups from the User details page.\n\n\n\n\n\n\nThe Merchant admin role includes full user management alongside other administrative permissions, such as risk configuration and payment method management. If a user only needs to manage roles and role groups without those extra operational permissions, assign them the IAM admin role instead.\n\nA Merchant admin user without company-level access has the same user management scope as a limited admin. The full admin tier requires company-level access.\n\n\nIf you need permissions that neither you nor your full admin have, reach out to our Support Team.\n\nRole groups and individual roles\nYou can assign permissions to a user through role groups, individual roles, or a combination of both. The user receives the combined permissions from all assigned role groups and individual roles.\nFor example, if a user has:\n\nA role group called \"Finance team\" that contains the Merchant financial and Download reports roles.\nAn individually assigned View Payments role.\n\nThe user has the permissions from all three roles.\nWhen you update a role group, the changes apply to all users that have the role group. For example, if you add the Merchant report role to the \"Finance team\" role group, all users with this role group receive the Merchant report permissions.\nHow it works\nThe following is an overview of how to set up and use role groups:\n\nYou create a role group and select which individual roles to include.\nYou assign the role group to one or more users.\nEach user receives the combined permissions from the role group and any individually assigned roles.\nWhen you update the role group, all users with that role group receive the updated permissions.\n\nCreate a role group\nYou need full admin access to create a role group.\nTo create a role group:\n\nLog in to your Customer Area.\nGo to Account &gt; Role groups.\nSelect Create role group.\nOn the Details step, enter a Name for the role group, and optionally add a Description. Select Continue.\nOn the Roles step, expand a role category and select the roles that you want to include. You can select roles from multiple categories. Select Continue.\nOptionally, on the Users step, search for and select users that you want to assign to this role group. Select Continue.\nOn the Summary step, review the details, roles, and users. To make changes, select the edit icon next to a section.\nSelect Create group.\n\nAssign a role group to a user\nBoth full and limited admins can assign role groups to users. Limited admins can assign role groups from the User details page, but cannot create, edit, or delete role groups.\nYou can assign role groups when you create a new user, or add them to an existing user.\nTo assign a role group to an existing user:\n\nLog in to your Customer Area.\nGo to Account &gt; Users, and select the user from the User List.\nIn the Role groups section, select the role groups to assign. You can only assign role groups that contain roles your own user already has.\nSelect Save.\n\nThe user now has the permissions from all roles in the assigned role groups, in addition to any individually assigned roles.\nEdit a role group\nYou need full admin access to edit a role group. When you edit a role group, the changes apply to all users that have this role group.\nTo edit a role group:\n\nLog in to your Customer Area.\nGo to Account &gt; Role groups, and select the role group that you want to edit.\nMake your changes to the name, description, or included roles.\nSelect Save.\n\n\nWhen you remove a role from a role group, users who have that role only through this role group lose the corresponding permissions. Users who also have the role assigned individually are not affected.\n\nDelete a role group\nYou need full admin access to delete a role group. Before you delete a role group, check which users have this role group assigned to them. Users who have roles only through this role group lose those permissions after deletion.\nTo delete a role group:\n\nLog in to your Customer Area.\nGo to Account &gt; Role groups, and select the role group that you want to delete.\nSelect Delete role group.\nReview the list of affected users, and then select Delete to confirm.\n\nSee also\n\n\n                    User roles\n                \n                    Manage users\n                \n                    Account structure\n                \n","type":"page","locale":"en","boost":18,"hierarchy":{"lvl0":"Home","lvl1":"Account","lvl2":"Role groups"},"hierarchy_url":{"lvl0":"https:\/\/docs.adyen.com\/","lvl1":"https:\/\/docs.adyen.com\/account","lvl2":"\/account\/role-groups"},"levels":3,"category":"Account","category_color":"green","tags":["groups"]}}
