New group membership settings

Domains created in Kahua development environments after November 14, 2025 can be used to test our new group membership settings. These settings are not yet available in production environments, and are not available in development environment domains created before November 14, 2025.

Membership in a group is how users are granted access to partitions and projects in your domain. Group members have the permissions associated with the application roles assigned to that group on the group's Permissions tab. For more information, refer to Setting up groups.

These new settings allow administrators to explicitly grant and remove access at selected levels, and to include or not include access to hierarchical child levels as needed. For more information on the partition / project hierarchy in Kahua, refer to Understanding the hierarchical structure of Kahua.

Each user's membership in a group can be established using one of the following three options:

  • Include this level and child levels - This selection grants the user access to the current level and to all child levels below this one in the hierarchy.

  • Include this level only and exclude child levels - This selection grants the user access to only this level. It does not grant access to any child levels below this one in the hierarchy.

  • Exclude this level and child levels - This selection excludes the user from having access at this current level and child levels below this one in the hierarchy. It is used when a user has been granted access at a higher level but needs to be removed at this level and below.

For detailed information on applying the new group membership settings, refer to Manage group membership below.

How to . . .