Groups
Groups and fine-grained permissions are available on the Enterprise plan. On other plans, access is managed with the Administrator and Member roles — see Roles & Permissions.
Groups are how you organize users and control their permissions in Markup AI. A group carries a set of permissions — and, if your organization has the Style Agent, which style guides its members can use — and everyone in the group inherits them. Manage groups under Team Management → Groups in the console.
Built-in groups
Every organization comes with two groups you’ll recognize from the two roles:
- Writers — everyone who joins the organization is added here automatically. Its permissions cover everyday use of Markup AI.
- Administrators — full workspace management. Membership here is what makes someone an Administrator.
Built-in groups can’t be deleted, and they can’t be mapped to an identity provider — administrator access is always granted deliberately in Markup AI, never inherited silently from a directory group. The Administrators group also can’t be emptied: Markup AI blocks any change that would remove its last member.
Permissions
Each group has a Permissions tab: a grid of switches, organized by area — organization management, style guides and terminology, the Brand Profile, and content checking. What the group grants is exactly what’s switched on, and every member inherits it.
Two things you’ll notice in the grid:
- Locked switches are permissions every member of your organization already has through the default permissions — a group can’t take those away, because access is additive.
- The grid only shows permissions for features your organization actually has.
Adding someone to a group — or mapping an identity-provider group to it — requires that you hold every permission the group grants. Nobody can hand out access they don’t have.
Default permissions
Your organization’s default permissions are what every member can do regardless of groups. They have their own page — open Default permissions from the Groups page. Keep them to the baseline everyone should have, and use groups for anything beyond it.
How membership reaches a group
Membership can arrive three ways, and they can coexist in the same group:
A group can be mixed — for example, IdP-backed with a few users added manually. The source badge on each group tells you how it’s populated:
- SCIM / IdP-backed — fed by an identity provider via SSO or SCIM. Memberships update as users sign in or are provisioned. These can’t be deleted in the console while a connection still feeds them.
- Manual — created and maintained by an admin. No badge; delete them any time.
Create a group
Choose its permissions
Open the group’s Permissions tab and switch on what its members should be able to do.
Add IdP mappings (optional)
Add one mapping per IdP that should populate this group via SSO or SCIM. Leave them empty to keep the group local to Markup AI and add members manually. The IdP string can differ from the group name, and one group can be fed by several connections.
Manage members
Open a group and use its Members tab to add or remove users. You can also manage a person’s groups from the Users page, which lets you set all of their groups in one place.
Style guides
If your organization has the Style Agent enabled, each group also controls which style guides its members can use for checking. That’s managed on the group’s Style guides tab — see Style Agent Visibility.