---
title: "Groups"
description: "Give a set of users and bots the same policies by attaching the policies to a group."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Groups

A group is a set of users and bots. Policies attached to a group apply to every member, in addition to the policies attached to the member directly. Groups don't contain other groups.

Each group has a name (1 to 100 characters), an optional description (up to 1,000 characters), a group ID like `grp_a1b2c3d4e5f6`, and a resource name like `ezgh::org_…:grp_a1b2c3d4e5f6`.

## Create a group

Creating a group needs `groups.create`.

### Console

1. Open **IAM** > **Groups** and select **Create group**.
2. Enter a **Name** and, optionally, a **Description**.
3. Select the **Members** and **Policies** to start with. These steps appear only if you may change members and attach policies.
4. Review, then select **Create group**.
### CLI

```sh
ezgh iam groups create developers --description "Application developers"
```
### API

```sh
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/groups \
  -H "Authorization: Bearer $EZGH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "developers", "description": "Application developers"}'
```

See [CreateGroup](/orgs-api/groups/CreateGroup/).

## Add and remove members

Members are users and bots in the organization. Changing a group's members needs `groups.updateMembers` on the group.

### Console

1. Open **IAM** > **Groups** and select the group.
2. On the **Members** tab, select **Edit members**.
3. Select the users and bots, then **Save**.
### CLI

```sh
ezgh iam groups add-members developers user:ada@example.com bot:deployer
ezgh iam groups remove-members developers user:ada@example.com
```
### API

```sh
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/groups/$GROUP_ID/members/$PRINCIPAL_ID \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

`$PRINCIPAL_ID` is a user ID or a bot ID. See [AddGroupMember](/orgs-api/groups/AddGroupMember/), [RemoveGroupMember](/orgs-api/groups/RemoveGroupMember/) and [SetGroupMembers](/orgs-api/groups/SetGroupMembers/), which replaces all members (up to 500 in one request).

You can also change a user's or bot's groups from their own page. See [Change a user's groups](/iam/users#change-a-users-groups).

## Attach policies to a group

Attaching or detaching policies needs `policies.attach`.

### Console

1. Open **IAM** > **Groups** and select the group.
2. On the **Permissions** tab, select **Edit policies**.
3. Select the policies, then **Save**.
### CLI

```sh
ezgh iam policies attach ReadOnlyAccess --group developers
ezgh iam policies detach ReadOnlyAccess --group developers
```
### API

```sh
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/groups/$GROUP_ID/policies/ReadOnlyAccess \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [AttachGroupPolicy](/orgs-api/policies/AttachGroupPolicy/), [DetachGroupPolicy](/orgs-api/policies/DetachGroupPolicy/) and [SetGroupPolicies](/orgs-api/policies/SetGroupPolicies/).

## Rename or delete a group

On the group's page, select **Edit** to change its name or description (`groups.update`), or **Delete** to delete it (`groups.delete`). Deleting a group removes its memberships and policy attachments: its members lose the access its policies gave them. With the CLI, use `ezgh iam groups update` and `ezgh iam groups delete`.

## Groups provisioned by SCIM

Groups your identity provider pushes over [SCIM](/iam/scim) show **Managed by SCIM**. While SCIM is on, their name and members come from your identity provider, and renaming them, deleting them or changing their members here returns `409` with `managed_by_scim`. Their policies are yours: attach policies to them as to any group.

Source: https://docs.ezghcloud.com/iam/groups/index.mdx
