Skip to main content

Group Management

App showcase

Give IT or group owners a controlled way to update memberships outside automated assignments.

Group Management lets authorized people review a group's current members and add or remove members through a NIM App. The app can expose all eligible groups or only a defined set, depending on who should manage them.

Intended audience

IT team or group owners

Target scope

All groups or specific groups

Required systems

Any

When to use itDirect link to When to use it

Use this pattern when group membership must be maintained outside automated role assignments. For example, a department owner may need to add a project member or remove someone whose assignment has ended. Configure the app to show only the groups that person is allowed to manage.

If a role model controls the same membership, review that automation before making a manual change; the next role-model run may change it again. For exceptions to automated role assignments, see Role Group Overrides.

How it helpsDirect link to How it helps

  • Delegates membership changes through a focused App instead of granting direct administrative access to the target system.
  • Limits the groups available to each operator or owner according to the App's configured scope.
  • Shows available and assigned users side by side so changes can be reviewed before submission.
  • Lets IT maintain memberships that are intentionally outside the normal automated role process.

Membership management flowDirect link to Membership management flow

Select

Find an eligible groupSearch the groups available to the signed-in operator or owner

Review

Inspect current membersCompare available users with users already assigned

Change

Add or remove membersMove the intended users between the available and assigned lists

Apply

Update the groupSubmit the reviewed membership change through NIM
Scope both the groups and the people who can edit them to match your delegation policy.

OutcomeDirect link to Outcome

IT and designated group owners can make approved membership changes through one controlled experience, without needing direct administrative access to the connected system.

App previewDirect link to App preview

The screenshots show an Active Directory implementation labeled AD Group Management. The same pattern can be adapted to other connected systems.

Search the groups available to the operator and select one to manage.
Compare available and assigned users, then add or remove members and update the group.