Skip to content

Creating Admin Groups

What are Admin Groups?

Admin Groups give one or more Login Accounts admin access to one or more Security Groups.

How do Admin Groups Work?

They provide a simple way to manage which Admins can access which Security Groups.

Enabling Admin Access

When you Trust an Admin in an Admin Group, they have instant access to the Security Groups already trusting that Admin Group.

When you Trust an Admin Group in a Security Group, all Admins in that Admin Group have instant access to it and all its children in its "Inheritance Tree".

Disabling Admin Access

Similarly, Distrusting an Admin in an Admin Group instantly disables that Admin's access to all Security Groups in the "Inheritance Tree" trusting or inheriting the trust for that Admin Group.

Distrusting an Admin Group in a Security Group instantly disables admin access for ALL of the Admins in that Admin Group.

Using Admin Groups

What is Required?

To use Admin Groups you need to:

  1. Create an Admin Group
  2. Trust an Account Owner in the Admin Group
  3. Trust the Admin Group in a Security Group

Creating an Admin Group

Where to Crate them

Where the Admin Group is created in your Organizations "Inheritance Tree" helps to control who can view and manage the Admins in it.

  • Creating it where the Org's top admin have admin access give them control over it.
  • Disabling "Inheritance" for the Admin Group restricts it to only those Admin Groups or Advisors who are directly trusted within that Admin Group.

How to Create one

Use the "Add Subgroup" option either in the Graph View or the Subgroups Panel.

  1. Enter the Admin Group's name
  2. Change the Alert Email Address if necessary
  3. Click on the "Admin Group" button

Adding an Admin

Enabling Admins

Before you can Trust an Account Owner as an Admin within an Admin Group, you must use "Manage Advisor Access" to identify that Account Owner as "known" for that Admin Group.

This is a security mechanism to prevent inadverntly trusting unknown users.

Adding an Admin

  1. Click on "Manage Advisor Access" in the "Profile Menu"
  2. Click on the "I Know Them" button to enable trusting that Account Owner's Profile
  3. Close the "Manage Advisor Access" panel
  4. Click on "Profiles I Can Trust" in the "Profile Menu"
  5. Click on the "Trust" button for the Account Owner's Profile
  6. Click on the "Trusted Admins" shortcut icon to verify their Admin Access

Applying the Admin Group

Security Groups Tree

Now, simplying Trusting that Admin Group in any Security Group will give ALL of the Admins in that Admin Group instant access to all of the Security Groups that inherit the trust for that Admin Group.

Trust in a Security Group

Select where the Admin Group should be Trusted

  1. Select a Security Group either in the Graph View or the Subgroups Panel
  2. Click on "Admins I Can Trust" in the "Profile Menu"
  3. Click on "Trust" for the Admin Group you want to have admin access

This will instantly provide Admin Access to ALL Admins in that Admin Group.

Security Precautions

  • Only add Account Owners to an Admin Groups after they've activated their account and enable 2-Factor Authentication
  • Control Admin Access to Admin Groups to prevent giving admin access to unauthorized Users