Groups are how OptimiDoc grants permissions. A group defines the web-interface role its members receive, the device operations (print, copy, scan, colour) they may perform, and the scan workflows, print connectors, and billing codes they may use. Every user automatically belongs to the built-in Everyone group, which sets the baseline for the whole system; additional groups adjust permissions relative to that baseline. Users can be placed in a group directly or inherit it through their department.
How Groups Work
Understanding a few underlying rules makes group configuration predictable, especially when a user belongs to several groups at once.
1. Everyone is the baseline
The built-in Everyone group (ID 1) applies to every user in the system. It is pinned to the top of the group list and marked with a System badge, cannot be deleted, and its membership cannot be edited — all accounts belong to it implicitly. What you configure on the Everyone group is the baseline: the default web-interface role and the default set of allowed device operations for the whole organisation.
2. Membership comes from two places
A user receives the combined permissions of every group they belong to. Membership is drawn from:
-
Direct assignment — groups added to the user on the user form, or on the group's Users tab.
-
Department inheritance — groups associated with the user's department on the group's Departments tab. Associating a department with a group grants that group to every user in the department.
3. The effective web-interface role is the highest one
When a user belongs to multiple groups, their role is the highest level found across the Everyone group and all of their groups. Levels rank from lowest to highest as User → Department Manager → Manager → Admin → Local Admin. For example, a user in one group set to Manager and another set to User is evaluated as Manager.
4. Device operations are set relative to the baseline
The Everyone group decides which operations are allowed by default. On any other group the same four toggles mean the opposite of the Everyone setting:
-
If Everyone allows an operation, other groups show a Deny toggle — enabling it removes that operation for the group's members.
-
If Everyone denies an operation, other groups show an Allow toggle — enabling it grants that operation to the group's members.
The net result for a user: an operation Everyone allows stays allowed unless one of their groups denies it; an operation Everyone denies stays denied unless one of their groups allows it.
5. Access rights toggle against the baseline
Scan workflows, print connectors, and billing codes follow the same baseline logic. An item granted on the Everyone group is available to all users; granting it on a specific group makes it available to that group's members. Assigning the same item on both Everyone and a specific group cancels out — so grant a resource either on Everyone (for all users) or on specific groups (for some users), not both. These assignments are made on the resource itself (in the Scan Workflows, Print Connectors, and Billing Codes sections); the group editor shows them read-only.
Navigating to Groups
-
In the left sidebar, expand Users and click Groups.
-
The group list displays all groups in a sortable, paginated data grid with the following columns:
|
Column |
Description |
|---|---|
|
Name |
The group name. The built-in Everyone group carries a System badge and is pinned to the top of the list. |
|
Description |
An optional text description of the group's purpose |
|
Users & Departments |
Two badges showing the number of member users and the number of associated departments. Hidden for the system Everyone group, whose membership is implicit. |
Use the search bar to filter groups by name. Results update automatically as you type.
Screenshot: Groups management view
Creating a Group
-
Click the Add Group button in the page header.
-
A creation dialog opens with three tabs: General, Users, and Departments.
General Tab
|
Field |
Description |
|---|---|
|
Name |
A unique name for the group (required, maximum 100 characters) |
|
Description |
An optional description of the group's purpose |
|
Web Interface |
The role members of this group receive in the web interface (see table below) |
|
Device Operations |
Toggle switches for Copy, Print, Scan, and Colour controlling which operations members may perform at MFP devices |
Web Interface Roles
The role is assigned on the group, not directly on the user; a user's effective role is the highest level across all their groups (see How Groups Work above).
|
Role |
Description |
|---|---|
|
User |
Standard interface with access to personal jobs, scan templates, and self-service features |
|
Department Manager |
User features plus visibility of jobs and reports for the user's own department |
|
Manager |
Department Manager features plus organisation-wide visibility of jobs and reports |
|
Admin |
Full administrative access to all configuration, users, and system settings |
|
Local Admin |
The highest level in the hierarchy, granting full administrative access |
Device Operations (Allow / Deny Logic)
The Device Operations toggles control which operations group members may perform at MFP devices. Their behaviour depends on how the built-in Everyone group is configured, because Everyone sets the baseline:
When the Everyone group allows an operation (for example, Copy is enabled on Everyone):
-
Other groups display a Deny toggle for that operation (for example, "Deny Copy").
-
Enabling the deny toggle prevents members of that group from performing the operation, even though Everyone allows it.
When the Everyone group denies an operation (for example, Colour is disabled on Everyone):
-
Other groups display an Allow toggle for that operation (for example, "Allow Colour").
-
Enabling the allow toggle grants members of that group permission to perform the operation, overriding the Everyone restriction.
Example: If Everyone allows Copy, Print, Scan, and Colour, but you want to withdraw colour output from a specific department, create a group for that department and enable "Deny Colour" on it.
Users Tab
Use the Search and add users autocomplete field to assign users to the group. The field searches the user database as you type, so it scales to large directories without loading every account. Selected users appear in a list below the field; click a user entry to remove them.
Departments Tab
Use the Search and add departments autocomplete field to associate departments with the group. Every user in the selected departments inherits this group's permissions, which makes departments a convenient way to grant a group to an entire organisational unit at once.
-
Click Create to save the new group.
Editing a Group
-
In the group list, click the three-dot menu on the row of the group you wish to modify.
-
Select Edit from the dropdown menu.
-
The edit dialog opens with the group's current settings. In edit mode the dialog shows up to six tabs:
|
Tab |
Description |
Availability |
|---|---|---|
|
General |
Name, description, web interface role, and device operations |
Always |
|
Users |
Assign or remove individual users |
Always |
|
Departments |
Associate or remove departments |
Always |
|
Scan Workflows |
Read-only view of scan workflows granted to this group |
Edit mode only |
|
Connectors |
Read-only view of print connectors granted to this group |
Edit mode only |
|
Billing Codes |
Read-only view of billing codes (formerly Projects) granted to this group |
Edit mode only; requires the Projects feature enabled in Print Settings |
Each of the read-only tabs shows a counter next to the tab title indicating the number of assigned items, so administrators can see the scope of a group's access at a glance. The items are listed as badges, sorted alphabetically by name.
-
Click Save to apply changes.
Read-Only Access Tabs
The Scan Workflows, Connectors, and Billing Codes tabs display which resources members of the group can access at the MFP terminal or when submitting jobs. These assignments are managed on the resources themselves, not in the Groups dialog:
-
To change scan workflow access, go to Scanning → Scan Workflows and edit the access rights of the workflow.
-
To change print connector access, go to Printing → Print Connectors and edit the access rights of the connector.
-
To change billing code access, go to Reports → Projects and edit the Access Rights of the billing code.
If nothing is assigned, each tab shows a message such as "No scan workflows assigned to this group." The Billing Codes tab appears only when the Projects feature is enabled in Print Settings.
Note: Groups imported from Active Directory are shown with their user and department membership in read-only mode. Those assignments are maintained by directory synchronisation and cannot be edited manually.
Deleting a Group
-
Click the three-dot menu on the group's row.
-
Select Delete.
-
A confirmation dialog appears showing the group name. Click Delete to confirm, or Cancel to abort.
Note: The built-in Everyone group cannot be deleted — its action menu has no delete option and its checkbox cannot be selected. Deleting any other group does not delete its member users; they simply lose the permissions that group provided.
Bulk Operations on Groups
Each row includes a checkbox for multi-selection:
-
Click the header checkbox to select or deselect all groups on the current page.
-
When groups are selected, a Delete button appears in the page header showing the count of selected items.
-
Click Delete to open a bulk deletion confirmation dialog.
The Everyone group's checkbox is always disabled and cannot be included in a bulk deletion.
In Summary
-
Permissions in OptimiDoc come from groups, not from individual users.
-
The Everyone group sets the system-wide baseline; every other group adjusts permissions relative to it.
-
A user's role is the highest level across all their groups; device operations and access rights toggle against the Everyone baseline.
-
Membership can be assigned directly or inherited through a user's department.
Related articles