Manage groups and guest access
Create and maintain groups and external guests with ownership, expiry, membership review, and least-privilege controls.
Audience, roles, and scope
Admin group and guest interfaces; application-specific permissions and external identity policy remain separate.
Who this is for
- Tenant and group administrators
Roles
- Tenant administrator
- Group administrator
- Guest sponsor
Before you begin
- Approved purpose and owner
- Verified member or guest identities
- Expiry or review date for external access
Article tags
- groups
- guests
- membership
- external-access
Procedures
Follow the sequence and stop when identity, authorization, target, or result differs from the article.
Create or change membership
Use an owned group and add only verified identities.
- 1Define purpose and owner
Record what the group grants, accountable owner, review frequency, and guest expiry requirements.
- 2Validate members
Search existing identities, verify similarly named users and guest domains, and remove unauthorized or expired entries.
- 3Save and test
Review the final membership, save once, and verify effective access without using another person’s account.
The group or guest record has a clear owner, justified membership, and reviewable access state.
Security and data handling
- Use only the identity, tenant, role, and data scope approved for the task.
- Verify targets and expected effects before saving, sending, publishing, exporting, deleting, or approving.
- Keep secrets and regulated data out of screenshots, URLs, free-text diagnostics, and ordinary support messages.
- External guests require a verified sponsor and should expire automatically where supported.
- Do not use broad groups to bypass application or data-owner approval.
Known limitations
- Membership changes may take time to propagate to connected applications and identity services.
- Guest lifecycle and domain restrictions depend on tenant federation and policy.
Troubleshooting
You cannot open Vianordis Admin
Likely cause: The session expired, the account is not entitled, or the required tenant or role claim is missing.
- Open the service through the approved Vianordis entry point and sign in again.
- Confirm the intended organization, tenant, and account are in use.
- If access remains denied, record the time and request an entitlement check; do not attempt direct-URL bypasses.
A documented control or navigation item is not visible
Likely cause: The current role, subscription, tenant configuration, release status, or feature flag does not expose it.
- Confirm the audience, role, prerequisites, and limitations in this article.
- Refresh after a new sign-in and verify the correct tenant context.
- Ask the responsible administrator whether the capability is enabled before reporting a defect.
A saved change or background result is not visible
Likely cause: Validation failed, processing is incomplete, the view is stale, or the feature is locally simulated rather than persisted.
- Review inline validation, status indicators, filters, and the selected tenant or workspace.
- Refresh once and search by a stable identifier before repeating the action.
- Do not repeat irreversible or externally visible actions until the first operation's state is known.
Source verification
Group, membership, and guest management surfaces were reviewed in source.
Reviewed paths at 8f3a86e
src/app/(base)/management/groups/page.tsxsrc/app/(base)/management/guests/GuestsView.tsxsrc/app/actions/guests.ts
Contact support
Contact support when
- A repeatable Vianordis Admin error blocks an approved task
- Expected access, tenant scope, data, or status appears incorrect
- A security, privacy, financial, compliance, or data-loss concern is suspected
Include
- The page, action, expected result, and exact error text
- The time of occurrence with time zone and whether it is reproducible
- Your tenant, role, browser, and sanitized record or correlation identifier
- The troubleshooting steps already completed
Never include
- Passwords, access tokens, API keys, recovery codes, session cookies, or private keys
- Unredacted personal, financial, health, student, employee, or other regulated data
- Confidential documents or message bodies unless support provides an approved secure channel