# Separated groups with separated accesses

**URL:** https://forum.pydio.com/t/separated-groups-with-separated-accesses/2346
**Category:** Pydio Cells
**Created:** [April 12, 2019, 4:00am UTC](https://forum.pydio.com/t/separated-groups-with-separated-accesses/2346 "2019-04-12T04:00:11Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tacticz](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/tacticz/32/849_2.png) [@tacticz](https://forum.pydio.com/u/tacticz)
#### Post date: [April 12, 2019, 4:00am UTC](https://forum.pydio.com/t/separated-groups-with-separated-accesses/2346/1 "2019-04-12T04:00:11Z")

</div>

Hello,

I’m just starting to experiment with Pydio Cells and consider it a wonderful piece of software!

In order to evaluate the possibilities of the system, I’m trying to implement quite a simple use case as follow:

- A Pydio Cells server is deployed by someone who wants to share files with different entities.

That is the very purpose of the software of course 🤣

- Each entity should have a dedicated space to access the files intended for it and should not be able to access files intended for other ones.  
It seems logical to consider that, in Pydio Cells, each entity would then be represented by a _Group_ created under _Identity Management \> People_.

It would then seem obvious to create a folder for each _Group_ and adapt the _Workspaces Accesses_ of this _Group_ to only allow Read or Read/Write access to this folder. Unfortunately, I discovered that, in the Home Edition, one would have to create separated datasources for each entity as I commented in the [Simple folder access use case - Cannot make it work](https://forum.pydio.com/t/simple-folder-access-use-case-cannot-make-it-work/1645/5) topic…

- _Users_ of the respective entities would be assigned to their respective _Group_. Those users should have specific possibilities, like the ability to create _Public Links_, or _Cells_ but only accessible to other users of their own _Group_…

At this stage, using the Home Edition as a testing ground, I’m facing two main difficulties:

1. The _Address Book_ that is presented to the user contains **all users of the system**. I looked for a way to restrict that to only the users in the same _Group_, as presented in the [Users/teams visibility](https://pydio.com/en/docs/cells/v1/usersteams-visibility) section of the documentation. Unfortunately (again), and contrary to what one might think reading this page, this _Visibility_ option doesn’t seem to be accessible in the Home Edition. 😒

2. Based on the _ **Roles and inheritance** _ documentation page (cannot link since I can only use 2 links as a new user 😬), I also tried to understand how to create a _Role_ that would apply to a certain _Group_. Creating a _Role_ named after the same name as the _Group_ didn’t work. From the documentation I though that maybe using a starting “/” before the name would work (i.e. rolename = /groupname), but it didn’t either.

Thus I came to this forum to ask if someone could:

- Tell me whether it is possible, in the Home Edition, to control (limit) users visibility to only their own _Group_ (restricted address book)?
- Help me understand how to create a _Role_ that would apply to a specific _Group_?

Any help would be welcome.

Thank you very much.

---

<div class="post-metadata">

### Author: ![zayn](https://avatars.discourse-cdn.com/v4/letter/z/a87d85/32.png) [@zayn](https://forum.pydio.com/u/zayn)
#### Post date: [April 15, 2019, 9:33am UTC](https://forum.pydio.com/t/separated-groups-with-separated-accesses/2346/2 "2019-04-15T09:33:46Z")

</div>

Hi,

> [@tacticz](#):
>
> Tell me whether it is possible, in the Home Edition, to control (limit) users visibility to only their own _Group_ (restricted address book)?

At the moment it’s not really possible without disabling the address-book (for a group for instance), it’s something that is on our bucket-list.

> [@tacticz](#):
>
> Help me understand how to create a _Role_ that would apply to a specific _Group_ ?

About the role/group process, so lets define the group & role to see the differences,  
basically roles are applied (automatically if you wish) to user with a profile (usually admin, regular users, external-user,…) for instance the `Root Group` is applied to every regular user existing in Cells, whereas the External Users is applied to temporary user form share links, or address book.

Now groups is to enable you to sort users by department(for instance) and manage access rights to their specific resources.

If you want a hint on what’s the best for you, i could guide you given a specific context.

---

<div class="post-metadata">

### Author: ![tacticz](https://yyz2.discourse-cdn.com/flex032/user_avatar/forum.pydio.com/tacticz/32/849_2.png) [@tacticz](https://forum.pydio.com/u/tacticz)
#### Post date: [April 18, 2019, 1:17am UTC](https://forum.pydio.com/t/separated-groups-with-separated-accesses/2346/3 "2019-04-18T01:17:29Z")

</div>

Thank you @zayn for taking the time to reply.

> [@zayn](#):
>
> At the moment it’s not really possible without disabling the address-book

That is indeed the conclusion to which I came from the few experimentation I did. As said in the initial post, from reading the documentation I was expecting to e able to selectively hide some groups from the others (in their address book).

> [@zayn](#):
>
> it’s something that is on our bucket-list.

Am I right in understanding that this feature might be made available in a future release?

> [@zayn](#):
>
> Now groups is to enable you to sort users by department(for instance) and manage access rights to their specific resources.

I think I get it now.  
I probably was mislead by reading, on the **Roles and Inheritance** (I don’t understand why I cannot post a link 😞) page, under the _Groups_ section, that

> **Each group is attached with a _canonical_ role** that takes the group Uuid as Uuid.

And thus I was thinking of creating a _Role_ that would bear a name that would “automatically” relate it to a _Group_ bearing the same name. I now understand that the quoted statement simply relates to the fact that one can define specific **Workspaces Accesses** , **Application Pages** and **Application Parameters** for each _Group_ that is defined under _ **Identity Management \> People \> + GROUP** _

This obviously makes more sense than defining a separated, specifically named, _Role_ to control those parameters for a specific _Group_.

> [@zayn](#):
>
> If you want a hint on what’s the best for you, i could guide you given a specific context.

That is very kind of you and I appreciate!  
For the moment I’ll keep exploring Pydio Cells’ interface and capabilities by myself before I come back and bother you again 😉

Thank you once more for paying attention to my questions, it’s nice to feel supported during the discovery of a software like this!

Best regards.

---

<div class="post-metadata">

### Author: ![zayn](https://avatars.discourse-cdn.com/v4/letter/z/a87d85/32.png) [@zayn](https://forum.pydio.com/u/zayn)
#### Post date: [April 19, 2019, 7:49am UTC](https://forum.pydio.com/t/separated-groups-with-separated-accesses/2346/4 "2019-04-19T07:49:50Z")

</div>

Hi,  
i wanted to add furthermore that in our enterprise edition we just released a feature to restrain the scope for groups, but when you enable the feature it is applied to every group (as long as they match some criteria) and you cannot choose which group is going to be secluded.
