Restrict a Group's Customer and Device Access

Scope a group to specific customers and devices and limit what its members may do, using the Customer Access and Device Access tabs.

Written By Stefan Steuer

Last updated 8 days ago

By default, a new group can reach every customer and every device — but with no actions enabled. This guide narrows a group down: which customers its members see, which of those customers' devices they can reach, and exactly what they may do there. Use it to build least-privilege groups — for example, a help desk that can only start a remote-desktop session on one customer's workstations.

Before you start

  • You need the Group Management permission (groups.manage) to edit groups.
  • Have a group ready. To create one first, see Create a Group.

How access is scoped

A group's reach is set on two tabs of the group editor, and they work together:

  • Customer Access decides which customers members can see and work with.
  • Device Access decides which of those customers' devices members can reach and — through Allowed actions — what they may do on them.

Device Access only refines within Customer Access: a group that reaches no customers reaches no devices, whatever its Device Access says.

Restrict customer access

  1. Go to Administration → Groups and open the group.
  2. Open the Customer Access tab.
  3. Turn off Access all customers and scope it instead:
    • Specific customers — pick an explicit list of customers.
    • Customer tag rules — grant access to every customer whose tags match your rules, so new matching customers are included automatically.
    You can combine a specific list with tag rules in the same group.

Restrict device access and actions

  1. Open the Device Access tab.
  2. Choose which devices members reach: leave Reach all devices on to cover every device of the accessible customers, or turn it off and add Device rules to match only some.
  3. Under Allowed actions, select only the actions members should perform — use Select all or Clear all to set them in bulk. Leaving the list empty gives read-only device access: members can see the devices but cannot act on them.
  4. Click Save.

Example: a view-only help desk with remote desktop

Say a help-desk team should reach one customer's workstations and start a remote-desktop session to help users — but change nothing else. Configure the group like this:

SettingChoice
Customer AccessSpecific customers — the one customer
Device Access — devicesReach all devices (of that customer)
Device Access — Allowed actionsRemote Desktop only
PermissionsCase Management, so the team can log its work

Members of this group see only that customer, can open a remote desktop on its devices, and cannot edit, delete, or change anything else — the rest of octoja stays out of reach.

Check the result

Open Access Overview to confirm the scope. It shows access By user, By customer, or By device, with an Allowed actions column and the reason each member has access — so you can verify the group grants exactly what you intended, and nothing more.