Restrict a Group's Customer and Device Access
Scope a group to specific customers and devices and limit what its members may do, using the Customer Access and Device Access tabs.
Written By Stefan Steuer
Last updated 8 days ago
By default, a new group can reach every customer and every device β but with no actions enabled. This guide narrows a group down: which customers its members see, which of those customers' devices they can reach, and exactly what they may do there. Use it to build least-privilege groups β for example, a help desk that can only start a remote-desktop session on one customer's workstations.
Before you start
- You need the Group Management permission (
groups.manage) to edit groups. - Have a group ready. To create one first, see Create a Group.
How access is scoped
A group's reach is set on two tabs of the group editor, and they work together:
- Customer Access decides which customers members can see and work with.
- Device Access decides which of those customers' devices members can reach and β through Allowed actions β what they may do on them.
Device Access only refines within Customer Access: a group that reaches no customers reaches no devices, whatever its Device Access says.
Restrict customer access
- Go to Administration β Groups and open the group.
- Open the Customer Access tab.
- Turn off Access all customers and scope it instead:
- Specific customers β pick an explicit list of customers.
- Customer tag rules β grant access to every customer whose tags match your rules, so new matching customers are included automatically.
Restrict device access and actions
- Open the Device Access tab.
- Choose which devices members reach: leave Reach all devices on to cover every device of the accessible customers, or turn it off and add Device rules to match only some.
- Under Allowed actions, select only the actions members should perform β use Select all or Clear all to set them in bulk. Leaving the list empty gives read-only device access: members can see the devices but cannot act on them.
- Click Save.
Example: a view-only help desk with remote desktop
Say a help-desk team should reach one customer's workstations and start a remote-desktop session to help users β but change nothing else. Configure the group like this:
Members of this group see only that customer, can open a remote desktop on its devices, and cannot edit, delete, or change anything else β the rest of octoja stays out of reach.
Check the result
Open Access Overview to confirm the scope. It shows access By user, By customer, or By device, with an Allowed actions column and the reason each member has access β so you can verify the group grants exactly what you intended, and nothing more.