Administering Domains, Roles and Users
User Groups
The User Group facility enables the rapid allocation of a set of roles and domains to a user’s account. When a user account is assigned to a user group, the user account automatically assumes the roles and domains of that user group.
When you create or edit a user account, you have the option to manage it in Derived Access Control mode, whereby the user groups (and their assigned roles) to which the user belongs enforce the user’s permissions, read/write access to domains, and change policies.
For a user account in DAC mode, the system automatically propagates any changes to a group and its roles to that account. See Derived Access Control for more information.
Caution
Although a user group can be initially created without them, the appropriate roles, domains and user accounts must have already been created before a user group can be used correctly.
Creating and Editing a User Group
Assigning and Editing User Accounts in a User Group
Assigning and Editing Roles in a User Group
Assigning and Editing Domains in a User Group
Assigning and Editing License Policies in a User Group
Parent Topic:
Administering Domains, Roles and Users
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/id9d716d66-0aa4-4a54-b106-59fb23e43cc2 · retrieved 2026-07-18