CapitalKnowledge

Administering Domains, Roles and Users

User Groups

The User Group facility enables the rapid allocation of a set of roles and domains to a user’s account. When a user account is assigned to a user group, the user account automatically assumes the roles and domains of that user group.

When you create or edit a user account, you have the option to manage it in Derived Access Control mode, whereby the user groups (and their assigned roles) to which the user belongs enforce the user’s permissions, read/write access to domains, and change policies.

For a user account in DAC mode, the system automatically propagates any changes to a group and its roles to that account. See Derived Access Control for more information.

Caution

Although a user group can be initially created without them, the appropriate roles, domains and user accounts must have already been created before a user group can be used correctly.

  • Creating and Editing a User Group

  • Assigning and Editing User Accounts in a User Group

  • Assigning and Editing Roles in a User Group

  • Assigning and Editing Domains in a User Group

  • Assigning and Editing License Policies in a User Group

Parent Topic:

Administering Domains, Roles and Users

Capital Access Manager User Guide, 2512.2606

Unpublished work. © 2026 Siemens

Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/id9d716d66-0aa4-4a54-b106-59fb23e43cc2 · retrieved 2026-07-18