Follow
Understanding Group Administrators

***

The highlighted information on this page refers to functionality not yet generally available. It is available only in the Preview Sandbox environment.

When you are the system administrator for a large company with many departments, you might not want to manage all the groups in each department yourself. Instead, you can create one group for each department and assign each group a Group Administrator. The Group Administrator can manage the needs of the group such as user membership to the groups, layout templates, custom data, projects, and templates separate from other groups in the system. 

Designating Group Administrators

As a system administrator, you can create a group. When adding members to the groups you create, you can designate some of them as Group Administrators for the group. 
You can have multiple users designated as group administrators on the group. A group must have at least one Group Administrator. 
For more information about creating groups and designating Group Administrators to them, see the "Creating a Group" section in "Creating and Managing Groups."

Users who have been designated as a Group Administrator for a group have some capabilities that only the System Administrator has. 
For more information about the capabilities of group administrators, see "Capabilities of Group Administrators."

Before designating users as Group Administrators we recommend the following: 

  • Capture the current number of system administrators in your system.
  • Capture the number of Groups you have in your system.
  • Determine whether you can change the Access Level of some of the system administrators and designate them as Group Administrators instead. 
    For more information about capabilities of group administrators, see "Capabilities of Group Administrators."
  • Determine whether you want group administrators to be able to log in as other users, or to reset passwords for users in the groups they administer. Additional access is needed to perform these tasks. 
    For more information about the access needed to log in as or reset the passwords of other users, see "Access Needed for Group Administrators."
  • For better user management, consider assigning Groups instead of users to the following objects:
    • Layout Templates
    • Schedules
    • Timesheet Profiles 

Access Needed for Group Administrators

To designate someone as a Group Administrator and allow them to perform the tasks of a system administrator for their groups, they must have the following access:

  • A Planner license.
    You can designate only users with a Plan license as group administrators. 
  • Edit access to users.
    NOTE We recommend granting edit access with administrative rights to users, but this is not mandatory. If group administrators do not have administrative access to users, they are only able to edit users they create. 
    For more information about granting this access, see "Access Needed to Edit Users" in "Understanding User Access."
  • Group administrative access to users is required only if you want them to perform the following tasks:
    • Log in as other users in the groups and subgroups they manage.
    • Reset the password of another user in the groups and subgroups they manage. 
      For more information about granting a user group administrative access to users, see "Understanding User Access."
  • Timesheets & Hours administrative access is required if you want them to assign Timesheet Profiles to users in their groups and subgroups. 
    For more information about granting administrative access to Timesheets & Hours, see "Administrative Access." 

Capabilities of Group Administrators

As a system or a group administrator, you can designate a user as a Group Administrator, as described in the "Creating a Group" section in "Creating and Managing Groups."

The group administrators that you assign to a group can perform the following tasks for groups they manage and their users:

Create Subgroups and Manage Group Membership

Only system administrators can create Groups. Every Group must have at least one Group Administrator. 

Once designated as a Group Administrator, a user can perform the following tasks:

  • Create subgroups for the groups they administer.
  • Manage the subgroups of the groups for which they are designated as an administrator.
    For more information about creating a subgroup, see the "Creating a Subgroup" section in "Creating and Managing Groups."
  • Add users to groups and their subgroups when editing existing ones. 
    NOTE Group administrators can only add users they have the access to edit to groups and subgroups. 
  • Associate users with groups and subgroups they manage when editing user profiles.
    For more information about editing user profiles, see "Editing User Accounts."

The following users can add the following Groups and Subgroups to a user when editing them:

  • System administrators can add all Groups and Subgroups in the system to any user.
  • Group administrators can add the Groups they manage and Public Groups to a user they can edit. 
  • Users with a Plan license with administrative access to users can add Public Groups to a user they can edit. 

Create and Edit Group-Level Statuses

Only system administrators can create system-level Statuses.

Group administrators can create and edit group-level Statuses. 

Group-level statuses are only visible to users who belong to those groups. 

For more information about creating or editing group-level statuses, see "Creating and Customizing Group Statuses."

Create Layout Templates

Only system administrators can create system-level Layout Templates.

Group administrators can create group-level Layout Templates and associate them with the groups they manage or the users they can edit. 
Group administrators cannot assign Layout Templates to job roles or teams. 
For more information about creating Layout Templates, see "Creating and Managing Layout Templates."

Group administrators and users with a Plan license who can edit other users can add system-level and group-level Layout Templates to the users they can manage when editing their profile. 

Create Timesheet Profiles

Only system administrators can create system-level Timesheet Profiles. 

Group administrators can create group-level Timesheet Profiles, associate them with users and groups they manage, and manually generate timesheets. 
For more information about creating Timesheet Profiles, see "Creating Timesheet Profiles."

Group administrators can add system-level and group-level Timesheet Profiles to the users they manage when editing their profile. 

Users with a Plan license who can edit other users can add only system-level Timesheet Profiles to other users when editing them.  

Create Schedules

Only system administrators can create system-level Schedules and indicate a Default Schedule. 

Group administrators can create and edit only schedules associated with the groups they manage. They cannot edit system-level Schedules and they cannot designate a schedule as the Default Schedule for the system. 
For more information about creating schedules, see "Creating Schedules."

Group administrators and users with a Plan license who can edit other users can add a system-level or a group-level schedule to another user when they are editing their profile. 

Recover Deleted Items

Group administrators can recover deleted items for users who belong to the groups they manage. 

The following configuration must exist before a group administrator can recover deleted items:

  • The item deleted are associated with a project. 
    NOTE Documents that are uploaded to the Documents area in the Global Navigation Bar and not associated with a project cannot be recovered. 
  • The Group on the project the items originated from is a group the Group Administrator can manage.

Group administrators can restore the project, or any tasks, issues, or documents associated with the project from the Recycle Bin.
For more information about restoring items in Workfront from the Recycle Bin, see "Restoring Deleted Items."

Reset Passwords for Other Users 

Group administrators can reset passwords for users they can edit that are in the groups they manage. 
For more information about resetting users' passwords see "Editing User Accounts."

The following configuration must exist before group administrators can restore the password of another user:

  • The group administrator has access to Edit users with group administrative access in their Access Level. This setting is disabled by default, so it must be enabled. 
    group_administrative_access_level_to_users.png
  • The user they are setting the password for is in a group they manage. 
    When this configuration exists, the group administrator can see the Reset Password link when they are editing the profile of a user. 

NOTE Group administrators cannot reset the password of a system administrator. 

Log in as Other User

Group administrators can log in as other users that are members of the groups they manage.For more information about logging in to Workfront as another user, see "Logging in As Another User." 

NOTE Group administrators can only reset Workfront passwords. If you have integrated Workfront with an SSO solution, group administrators might not be able to reset passwords for other users. Those permissions are configured in your SSO system rather than in Workfront. 

The following configuration must exist before group administrators can restore the password of another user:

  • The group administrator has access to Edit users with group administrative access in their Access Level. This setting is disabled by default, so it must be enabled. 
  • The user that they are logging in as is a member of a group they manage. 

NOTE Group administrators cannot log in as a system administrator. 

View Available Licenses

Group administrators can view the number of licenses available for the groups they manage. For more information, see "Managing Available Licenses in your System."

License_Management_-_Read-only_view_for_Group_Admins.jpg

***

Later on, when permissions around projects will be introduced, add this to the restore items section: They must have permissions to View the project, tasks, issues, or documents before they can restore them.  (this is not true yet, but it will be and it needs to be live when they fix this - after beta 3)
For more information about permissions in Workfront, see "Understanding Permissions in the Access Model."

Linked from and links to Creating and Managing Groups, Managing Group Membership and Subgroups, Logging in as another user;  

This article last updated on 2018-07-09 17:38:05 UTC