All articlesOrganization And Users

Manage access by department

Give people and Access Groups the right role in the right part of your organization.

People: invite and activate someone

Open Settings, then Access Control. People lists everyone who can sign in or has an open invitation.

Only organization Admins can change access. Security Admins and approved custom roles can use Access Inspector for the departments and Functional Groups they are allowed to review.

  1. Choose Invite User.
  2. Enter the person’s work email and name, then send the invitation.
  3. Open Assignments and grant the role and scope they need.
  4. Return to People and confirm their status changes from Invited to Active after they finish sign-in.
A person with no assignment can sign in, but cannot use product features until an Admin grants access.
Iron Gorilla Access Control People page showing users, status, roles, assignments, and inspect actions.
People shows who can sign in, their role, and how many scope assignments contribute to their access.

Choose the right scope

Organization access covers every department and Functional Group. Department access covers that department and its Functional Groups. Functional Group access covers only that group.

A person can have more than one role at the same scope. Their available actions are added together. There is no deny assignment, so remove an unneeded role instead of trying to override it with a smaller one.

Access Groups: reuse the same access

Access Groups are flat permission groups. They are separate from Functional Groups, which organize agents, policies, usage, and other product resources inside a department.

  1. Open Groups and choose Create group.
  2. Use a short name that matches the team or responsibility, then create the group.
  3. Choose Manage people and add everyone who should receive the same access.
  4. Open Assignments and assign the Access Group to a role and scope.
Iron Gorilla Access Groups page showing locally managed and identity-provider-managed groups.
Access Groups let you assign a role once and then manage the people who receive it.

Scope Assignments: grant access

  1. Open Assignments and choose Add access.
  2. Choose a person or Access Group.
  3. Choose the role that matches the work.
  4. Choose the organization, department, or Functional Group where the role applies.
  5. Review the impact, then apply the change.
Admin is always an organization-wide role. Iron Gorilla also keeps at least one active person as a direct Admin so the workspace cannot lose its recovery owner.
Iron Gorilla Scope Assignments page showing people and Access Groups connected to roles and organization scopes.
Scope Assignments shows who receives a role, where it applies, and whether the assignment is active.

Roles: choose available actions

Roles are reusable sets of product actions. Open Roles to compare the available role names, whether each role is built in or custom, and how many actions it includes.

Choose Manage roles when you need to review or change a custom role. Return to Assignments to decide which person or Access Group receives the role and where it applies.

Iron Gorilla Access Control Roles page showing role names, role types, and available action counts.
Roles define what someone can do; Scope Assignments decides where they can do it.

Understand what becomes visible

The selected scope applies across the product. It limits the agents, policies, approvals, audit evidence, connector resources, model rules, traces, usage, budgets, and operational records the role can use.

Organization billing configuration, the financial ledger, and global model-provider settings remain organization-wide. When a mutable resource moves to another scope, its access moves with it; older audit evidence keeps the scope it had when the event occurred.

Access Inspector: explain access

Leave Date and time blank for current access, or choose an earlier time to investigate a past decision. Complete history is available from the access-control launch date; older history is shown when reliable evidence exists.

  1. Open Inspector and choose a person.
  2. Review Sources to see every direct assignment and Access Group that contributes to access.
  3. Review Available actions to see the resulting permissions in readable language.
  4. Remove the extra source assignment if access is broader than expected.
Iron Gorilla Access Inspector explaining a person’s role sources, scopes, and available actions.
Access Inspector shows each direct or group assignment that contributes to a person’s access.

SCIM and large changes

SCIM creates and updates identity-provider-owned Access Groups. If an incoming group name conflicts with an existing group, Iron Gorilla holds it for review instead of merging memberships. Existing priority mappings appear as proposed assignments and do not grant access until an Admin reviews them.

Large imports run in the background and report each failed item without undoing successful items. Sensitive changes and large batches ask for a recent MFA check. If another Admin changes access while your page is open, refresh and review the updated plan before applying it.

Need help?

Tell us where you got stuck.

Share what you were trying to do, what happened, and how urgent it is. We will route it to the right team.

Submit a ticket