Assign user groups and check access
Give an account the permissions required for its work.
Access needed: Site administrator with user-management and access-rule permissions.
Start with an existing account and a clear description of its work: which content it maintains, whether it publishes, and whether it manages other people.
- Find the person's page in the user overview and open it.
- In User groups, select the existing group that matches the agreed role. Check inherited memberships and save.
- Use a separate browser profile to sign in as a representative test account with those memberships.
- Check one allowed operation, such as editing a draft in the intended content group.
- Check one restriction, such as editing another team's content or opening user management.
- Record the membership change and the person responsible for approving it.
Do not give an account administrator access merely to fix one missing permission. If no existing role fits, have an access-rule administrator adjust the rules and test them before publication. More than one group can affect the effective permissions.
A person page, login identity, user group, and content group have different purposes. A collection used for navigation is not an access-control boundary.