Tungsten Automation Knowledge

How User Groups Add to Existing User Privileges and Buyer Access

000045917 · General Info · Last Updated: Sep 2, 2026

QUESTION

Why does a user gain broader access than expected after being added to a user group, even though the user's own direct privileges and buyer assignments were more limited?



ANSWER

User groups add privileges and buyer access on top of whatever a user already has directly. They don't override or narrow existing access.


For example, a user has only the Access Storage privilege plus access to a single Buyer A. The user is then added to a user group that has only the Access Verify privilege and access to 10 other buyers, excluding Buyer A. After the group is applied, the user has access to both Verify and Storage folders and can view documents from 11 buyers total, including Buyer A.


The User management overview page describes groups as a way to avoid assigning privileges one by one, not as a way to scope down access that's already assigned elsewhere.


To restrict a user to only the group's privileges and buyers, remove the direct assignment from the user first. Once the direct assignment is gone, the group becomes the sole source of that user's access.



REFERENCES

User management overview

Applies to

ProductVersionBuildEnvironmentHardware
AP Essentials

Sections recovered from body HTML: issue, solution, refs.

https://aio-eus-uat-cae-aif-app14-local.redglacier-35d7ee4f.eastus.azurecontainerapps.io/article/45917 | Article 000045917 | Printed Sep 30, 2026

Back to the article · use your browser's Print command, or save the PDF.