---
title: "Groups"
description: "Groups provide structure and flexible access controls."
canonical_url: "https://cobalt-io.brainfish.ai/articles/groups-AFqkqDHbW6"
md_url: "https://cobalt-io.brainfish.ai/articles/groups-AFqkqDHbW6.md"
---
# Groups

Groups provide structure and flexible access controls.


:::info
As an [Organization Owner](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-owner), you can manage access to your organization’s assets and their associated pentests and findings.

:::

Watch a demo video going over the Groups feature:

[https://www.loom.com/share/37841915aabe4bd3a96112ccc097668e](https://www.loom.com/share/37841915aabe4bd3a96112ccc097668e)

## Create a Group

Assign [Organization Members](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-member) into a group:

* Navigate to the **People** page, and then to the **Groups** tab.
* Select **Create Group**.
* The **Create Group** screen prompts you for the following:
  * **Group Name**: Set up a descriptive name to easily identify the group.
  * **Description**: Add information to further describe the group.
  * **Members**: Select from a list of all Organization Members within your organization. These users will have exclusive access to the group’s associated assets, and their pentests and findings.
    * Organization Owners and Cobalt Staff will not appear in this list but will still have access to all assets.
      * [Pentest Team Members](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member) that are not part of your organization can still be [manually added](https://docs.cobalt.io/en-us/articles/manage-pentest-collaborators-2pjt0NS56E#h-add-a-pentest-team-member) to each pentest.
* Select **Create Group**.


:::info
**Note**

Assets can be [individually assigned](https://docs.cobalt.io/en-us/articles/groups-AFqkqDHbW6#h-assigning-a-group-to-an-asset)to a group from the Create or Edit Asset forms.

:::

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=77c97143-24d0-42ba-83d0-0a49627e7297)

## View and Manage Groups

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=7e093416-cc93-40c3-af75-de5e3fc9429c)

On the **Groups** page, you can:

* Create a group
* View all of the groups within your organization
* Manage groups. Select the three-dot icon under **Actions**, and then select the desired option:
  * **Edit Group** to modify group details
  * **Delete Group**, if it doesn’t have associated assets

## Group Details Page ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=529872f6-b67d-47a4-b7d4-e622b340c0bb)

On the group details page, you can:

* View associated assets
* View group members
* Edit group details
* Delete the group, if it doesn’t have associated assets

## Assigning a Group to an Asset

You can assign a group to multiple assets during [asset creation](https://docs.cobalt.io/en-us/articles/assets-are-what-we-pentest-09RgsvQ7zv) or editing. ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=ab4d949e-99cc-4d15-823c-e0b9d5e59a73)

• The **Asset** screen will prompt you for the usual [details](https://docs.cobalt.io/en-us/articles/create-an-asset-9P1WPENeIC#h-asset-details).

* You will additionally see an **Assigned Group** field. This is by default set to the ‘All Org Members’ group. Select from the dropdown to choose another group within your organization.
  * **Organization Members** will only be able to assign groups they are already part of when creating new assets, and do not have permissions to reassign the group once the asset has been created (Organization Owners and Cobalt Staff are able to do both).
* Once created, the asset and any of its pentests and findings will be accessible to its assigned group.


:::info
**Note**

Currently, only one group can be assigned per single asset.

:::

## Access and Permissions

Only [Organization Owners](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-owner) can create, manage, and view all groups across their organization.

While assets can be associated with particular groups and their members, Owners will always still have access to all assets in the organization as well.

[Organization Members](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-organization-member) only have read-only access to groups they are members of.

* Org Members can view and manage assets that belong to their groups. They, however, cannot reassign an asset’s group once the asset has been created.
* Org Members can access every pentest and finding that belong to their groups’ assets.

For more information about user permissions, see [User Roles and Permissions](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR).

## Frequently Asked Questions

Click to view answers.

### How do I know which group owns an individual pentest?

\-The pentest **Collaborators** tab will still show all individual collaborators and any group they may be part of.

### Will all of a pentest’s collaborators carry over when I copy the pentest?

\-Yes. All individual group members that own the pentest and any non-group member that was manually added previously will carry over to the newly copied pentest.

### Are groups required?

\-All assets will require an assigned group. If you plan to not use this feature, however, you can assign assets to the default **All Org Members** group.
