Group Management
App showcase
Give IT or group owners a controlled way to update memberships outside automated assignments.
Group Management lets authorized people review a group's current members and add or remove members through a NIM App. The app can expose all eligible groups or only a defined set, depending on who should manage them.
Intended audience
IT team or group ownersTarget scope
All groups or specific groupsRequired systems
AnyWhen to use itDirect link to When to use it
Use this pattern when group membership must be maintained outside automated role assignments. For example, a department owner may need to add a project member or remove someone whose assignment has ended. Configure the app to show only the groups that person is allowed to manage.
If a role model controls the same membership, review that automation before making a manual change; the next role-model run may change it again. For exceptions to automated role assignments, see Role Group Overrides.
How it helpsDirect link to How it helps
- Delegates membership changes through a focused App instead of granting direct administrative access to the target system.
- Limits the groups available to each operator or owner according to the App's configured scope.
- Shows available and assigned users side by side so changes can be reviewed before submission.
- Lets IT maintain memberships that are intentionally outside the normal automated role process.
Membership management flowDirect link to Membership management flow
Select
Review
Change
Apply
OutcomeDirect link to Outcome
IT and designated group owners can make approved membership changes through one controlled experience, without needing direct administrative access to the connected system.
App previewDirect link to App preview
The screenshots show an Active Directory implementation labeled AD Group Management. The same pattern can be adapted to other connected systems.