In This Article: Learn how to effectively manage your Ontario users and groups through the Users and Groups screens. This guide covers viewing and modifying user details, organizing teams into functional groups, performing bulk actions for efficiency, and implementing strategies for structuring your organization within Ontario.
Â
Once you've added users to your Ontario environment, the next step is managing them effectively. The Users and Groups screens provide centralized control over your team structure, allowing you to view user details, modify access levels, organize teams, and perform bulk operations efficiently.
Whether you're managing a small team or a complex multi-entity organization, understanding how to use these management tools helps you maintain security, streamline collaboration, and scale your user base as your needs evolve.
Accessing the User and Group Management Screens
Both the Users screen and Groups screen are accessible from the Ontario landing page, providing environment-level oversight of your entire user base and group structure.
Users Screen
View all users across your Ontario environment, see their roles and group memberships, and manage individual user details and access levels.
Groups Screen
Organize users into functional teams, assign groups to projects in bulk, and manage group membership to streamline access control.
To access these screens, navigate to the Ontario landing page and click either the Users or Groups tab at the top of the page.
Screenshot: Ontario Landing Page Navigation Tabs
The Users and Groups tabs are positioned next to Projects and Overview tabs, providing easy access to user management functions
Working with the Users Screen
The Users screen displays a comprehensive table of all users in your Ontario environment. This centralized view allows you to quickly assess your user base, identify role distributions, and take action on individual or multiple users.
Understanding User Table Columns
The Users table provides key information about each user at a glance. Here's what each column tells you:
User's full name (clickable) and email address for login and notifications
Environment-level role (Admin or Viewer) determining base permissions
Groups the user belongs to, displayed as colored pills for quick identification
Date Created and Last Active timestamps help track account age and usage patterns
Table Controls and Filtering
The Users table includes powerful controls at the top that help you navigate large user lists and find specific individuals:
- Search Bar: Enter a user's name or email to quickly locate them (minimum 3 characters)
- Show Filters: Access advanced filtering options to narrow results by role, group membership, or status
- Pagination: Navigate through pages of users using the arrow controls when you have more than 20 users
- Create + Button: Add new users directly from the Users screen (covered in Adding and Inviting Users)
Screenshot: Users Table with Controls
The Users screen showing the search bar, filter button, pagination controls, and Create + button positioned above the user list table
Learning Check: User Table Efficiency
You need to deactivate all users who haven't logged in for over 90 days. Which columns should you use to accomplish this efficiently?
Managing Individual Users
Each user row includes a three-dot action menu (â‹®) on the right side that provides access to individual user management functions:
Edit
Modify the user's name, email, role, or group memberships. Opens the same modal used during user creation.
View Details
Open a detailed view showing the user's full profile, project assignments, activity history, and permissions.
Assign to Group
Add the user to one or more groups without opening the full edit dialog. Useful for quick group assignments.
Duplicate
Create a new user with the same role and group memberships. Speeds up onboarding users with similar access requirements.
Deactivate/Activate
Toggle the user's status. Deactivated users retain their data but cannot log in. They can be reactivated at any time.
Delete
Permanently remove the user from the Ontario environment. This action cannot be undone and should be used with caution.
Deactivate vs. Delete: Use deactivation for temporary access removal (departing employees, contractors between projects) as it preserves all user data and can be reversed. Only delete users when you're certain you want to permanently remove all traces of that account.
Screenshot: User Action Menu
The three-dot menu expanded showing Edit, View Details, Assign to Group, Duplicate, Deactivate, and Delete options
Performing Bulk User Actions
When managing multiple users simultaneously, Ontario's bulk actions feature dramatically improves efficiency. Instead of modifying users one at a time, you can select multiple users and apply changes to all of them in a single operation.
Selecting Multiple Users
Each user row includes a checkbox on the left side. Click the checkboxes to select individual users, or use the header checkbox to select all users on the current page. As you select users, a dark action bar appears at the bottom of the screen showing how many users are selected.
Screenshot: Bulk Selection Action Bar
The dark blue action bar at the bottom of the screen showing "2 Selected" with buttons for Change Role, Activate Users, Deactivate Users, Add to Group, and Delete
Available Bulk Actions
Once users are selected, the following bulk actions become available in the action bar:
Change Role
Modify environment-level roles for all selected users. Useful for promoting team members to Admin or adjusting contractor permissions.
Activate Users
Restore login access for deactivated users. Perfect for bringing back seasonal employees or reactivating contractors for new projects.
Deactivate Users
Suspend login access while preserving data. Essential for offboarding departing employees or temporary access suspension.
Add to Group
Assign multiple users to groups simultaneously. Ideal for creating project teams or adding new hires to standard groups.
Delete
Permanently remove users from your environment. Use cautiously for cleaning up test accounts or duplicate entries.
Efficiency Tip: Use filters before selecting users for bulk actions. For example, filter to show only Viewer role users, then select all and use Change Role to upgrade them to Admin in one operation. This is much faster than finding and modifying each user individually.
Bulk Action Workflow
Here's the typical workflow for performing bulk actions:
Filter or Search (Optional)
Narrow down your user list using the search bar or filters to show only the users you want to modify. This prevents accidentally selecting the wrong users.
Select Target Users
Click the checkboxes next to each user you want to include, or use the header checkbox to select all visible users on the current page. Watch the action bar update with the selection count.
Choose Bulk Action
Click the appropriate button in the action bar (Change Role, Activate Users, Deactivate Users, Add to Group, or Delete) based on what you want to accomplish.
Confirm or Configure
For some actions (like Add to Group), a modal appears where you can configure additional details. For others (like Deactivate), you'll see a confirmation dialog. Review carefully before proceeding.
Verify Changes
After the action completes, a toast notification confirms success. Review the affected users in the table to verify the changes were applied correctly. Changes take effect immediately.
Learning Check: Bulk Action Safety
You accidentally selected 15 users including yourself when you only meant to select 10 contractors. Before clicking "Deactivate Users," what's the safest way to fix this?
Working with the Groups Screen
Groups provide a powerful way to organize users into functional teams and manage access at scale. Rather than assigning users to projects individually, you can add entire groups to projects, making it easy to grant or revoke access for teams of people simultaneously.
Understanding the Groups Table
The Groups screen shows all groups with key details about composition and access. Each row displays:
Group name with clickable link to full details
Admin and Member role counts (e.g., "Admin (7) Member (2)")
User avatars showing group members (hover to see names)
Projects the group can access (displayed as pills)
Active or inactive status badge
Screenshot: Groups Table Overview
The Groups screen showing multiple groups with their names, role breakdowns, user avatars, project access pills, and status badges
Creating New Groups
Click the Create + button at the top right of the Groups screen to open the Create Group modal. You'll need to provide:
- Group Name: A descriptive name that clearly identifies the team's purpose (e.g., "Analysts Manufacturing", "Admins Consulting")
- Description: Optional details about the group's purpose or membership criteria
- Owner: The user responsible for managing this group (defaults to you)
- Members: Select users to add to the group from the dropdown list
- Instance/Project: Optionally assign the group to specific projects immediately
Screenshot: Create Group Modal
The Create Group modal showing fields for Group Name, Description, Owner dropdown, Members multi-select, and Instance/Project selection
After clicking Save, a toast notification confirms group creation, and the new group appears in the Groups table. Members are immediately added and will have access to any assigned projects based on their role within the group.
Managing Existing Groups
Each group row includes a three-dot action menu providing these management options:
Edit
Modify group name, description, owner, members, or project assignments. Add or remove members using the X button next to their names.
Duplicate
Create a new group with the same structure and membership. Useful for creating similar teams across different departments or entities.
Deactivate/Activate
Temporarily suspend a group without deleting it. Deactivated groups and their members lose project access but can be reactivated later.
Delete
Permanently remove the group. Members are not deleted but their group-based project access is immediately revoked.
Group Management Best Practice: When restructuring teams, use the Duplicate function to create new groups based on existing ones, then modify the membership as needed. This preserves your existing group structure while allowing you to experiment with new team configurations without disrupting current access.
Strategies for Structuring Your Organization
How you organize users and groups in Ontario can significantly impact collaboration efficiency, security, and administrative overhead. While there's no single "correct" approach, certain patterns work well for different organizational structures.
Common Group Organization Patterns
Consider these approaches when designing your group structure:
Scaling Your User Structure
As your Ontario environment grows, keep these principles in mind to maintain manageability:
Keep Groups Focused
Groups should have a clear, specific purpose. Avoid creating "catch-all" groups that include users with diverse access needs, as this makes permission management harder.
Use Descriptive Names
Group names should clearly indicate both function and scope (e.g., "Analysts Manufacturing" not just "Analysts"). This prevents confusion when assigning groups to projects.
Plan for Role Separation
Consider creating separate groups for Admins and Members of the same team (e.g., "Finance Admins" and "Finance Members") when you need different access levels within a functional area.
Review Regularly
Schedule quarterly reviews of group membership and structure. Remove inactive users, consolidate redundant groups, and adjust as your organization evolves.
Example: Multi-Entity PE Firm Structure
Here's how a private equity firm with multiple portfolio companies might organize groups in Ontario:
Environment-Wide Groups
- PE Firm Admins: Internal team with full administrative access across all portfolio companies
- PE Firm Analysts: Internal analysts who need view access to all companies for comparative analysis
- PE Firm Executives: Partners and senior leadership with strategic oversight
Entity-Specific Groups
- Company A Admins: Management team for portfolio company A with admin rights to their projects
- Company A Finance: Finance team for company A with member access to financial projects
- Company B Admins: Management team for portfolio company B
- Company B Operations: Operations team for company B with project-specific access
Project-Specific Groups
- Company A M&A Due Diligence: Temporary team for acquisition evaluation (deallocated after close)
- Portfolio Integration Team: Cross-company team managing post-acquisition integration
- Year-End Audit Team: External auditors granted temporary access during audit season
Learning Check: Group Design Decision
Your finance team needs full admin access to financial projects but only viewer access to operational projects. Should you create one "Finance Team" group or two separate groups?
Best Practices for User and Group Management
Security First
- Apply least privilege principles
- Separate admin duties across team
- Audit access quarterly
- Deactivate promptly on departure
- Document group purposes clearly
Work Efficiently
- Standardize naming conventions
- Assign access through groups, not individuals
- Batch onboarding with bulk actions
- Keep groups sized 5-20 members
- Leverage duplication for consistency
Manage Change
- Test with small pilot groups first
- Communicate changes to users
- Keep deactivated groups temporarily
- Document structure decisions
- Train new administrators properly
What's Next
What's Next
User Roles and Permissions
Understand the detailed differences between Admin and Viewer roles at both environment and project levels, including permission matrices and role best practices.
Working with Project Members
Learn how to add users and groups to specific projects, manage project-level roles, and control member access at the project level.
Adding and Inviting Users
Go back to the basics of creating new user accounts and inviting team members to join your Ontario environment.
Building scalable teams: Effective user and group management is the foundation of a secure, collaborative Ontario environment. By organizing users into logical groups, performing efficient bulk operations, and following best practices for access control, you create a structure that grows with your organization without becoming unmanageable. Regular reviews and thoughtful group design ensure your team can collaborate efficiently while maintaining appropriate security boundaries.
Comments
0 comments
Article is closed for comments.