> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.simplyprint.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# User groups and permissions: what each one controls

# User groups and permissions: what each one controls

Every member of your account belongs to a **user group** (sometimes called a rank), and the group decides what they can see and do, from whether they can start a print to whether they can manage billing. This guide explains how groups work, the default groups you start with, and what the main permissions control.

|| User groups are part of the plans that include multiple users: the Print Farm, School and Enterprise plans. See the [pricing page](https://simplyprint.io/pricing) for the full comparison.

## What you'll find here
- How groups and permissions fit together
- One group per member - and any number of workgroups
- The default groups
- Creating and editing a group
- Group order and who can manage whom
- Controlling which printers a group can use
- Permissions by category
- Quotas, SSO mapping and IP exemptions

## How groups and permissions fit together
A **permission** is a single yes/no capability, for example "Can print" or "Can invite users". A **group** is a named bundle of permissions. You assign a member to a group, and they get exactly that group's permissions.

This means you set up your groups once, then manage people just by choosing the right group for each. The account **owner** always has every permission and isn't part of any group.

## One group per member - and any number of workgroups
A member has **exactly one** user group. It's their role, and it decides their organization-wide authority - whether they can manage users, change the subscription, edit account settings, and so on.

That's the right shape for "who is this person", but not for "what else are they part of". For that there are **workgroups**: additive groups a member can hold **any number of** at once. A workgroup adds permissions, printer access and allowances on top of the member's user group, and can be granted permanently or for a fixed term.

| | User group | Workgroup |
| :--- | :--- | :--- |
| How many per member | Exactly one | Any number |
| Can grant organization authority (users, billing, settings, API) | Yes | No |
| Can grant "Access all printers" | Yes | No - only the printers it names |
| Can expire on a date | No | Yes |
| Effect | Replaces their previous group | Adds to what they already have |

A member's effective access is the **union** of their user group and every currently-active workgroup: they can do something if their user group allows it *or* any active workgroup allows it. Workgroups only ever add - none of them can take away what the user group granted.

So the teacher who also runs the robotics club stays a Teacher, and gets the club's printers through a workgroup. Everything below in this article describes the user-group side; see [Workgroups: layering extra access on top of a member's role](https://help.simplyprint.io/en/article/workgroups-layering-extra-access-on-top-of-a-members-role-qjypld/) for the other half.

|| Workgroups are on the School and Enterprise plans. If your account doesn't have them, everything in this article still applies exactly as written.

## The default groups
When your account is created, SimplyPrint sets up sensible default groups for your account type. You can use them as-is, rename them, or build your own:

- **Print Farm:** Administrator, Operator.
- **School:** Administrator, Teacher, Specialist, Student (new sign-ups become Students by default).
- **Enterprise:** Administrator, Manager, Engineer, Member.

New members join your **default registration group** unless you pick another group when inviting them.

## Creating and editing a group

![The User groups and permissions settings card](https://storage.crisp.chat/users/helpdesk/website/-/f/f/2/2/ff22a914001c1000/user-groups-permissions-user-g_adsdxm.png)

1. Open **Settings → Organization** and find the **User groups & permissions** card. (You can also reach it from the Users page header.)
2. Click to create a new group, or use the **edit** button on an existing one.
3. Give the group a **name** and an optional **description**.
4. Turn permissions on or off. Every permission has a plain-language label, and you can search by name or keyword, expand or collapse categories, and use **Enable all** / **Disable all**.
5. Save.

| Building a group from scratch is tedious, so the editor has shortcuts: **Import default role** loads one of the standard templates as a starting point, **Baseline from** copies the permissions of the group just below this one, and **Compare** shows the differences against another group.

To delete a group, use its **delete** button. If anyone is still in that group, you'll be asked which group to move them to first, and you can't delete your only remaining group.

## Group order and who can manage whom
Groups are arranged in a list from most to least access, and you can drag them to reorder. The order matters: a member can only assign or change other members into groups **at or below their own** level. Administrators and the owner can manage any group.

This is why a new member should usually start in a lower group, it keeps user-management in the hands of the people who are meant to have it. Two related permissions fine-tune this: **Can change user rank** lets someone move others between groups, and **Assign peer rank** lets them grant their own group to others.

## Controlling which printers a group can use
By default a group can use every printer. To limit a group to specific machines, turn off **Access all printers** and turn on **Can see printers they don't have access to** (so locked printers are still visible but not controllable). A selector then lets you choose exactly which **printers, printer models and printer groups** the group may use. This is handy in a workshop or classroom where different teams or classes should only touch their own machines.

## Permissions by category

![The group editor with the permission tree grouped by category](https://storage.crisp.chat/users/helpdesk/website/-/f/f/2/2/ff22a914001c1000/user-groups-permissions-permis_ok6rh8.png)

The permission list is grouped into categories so you can find things quickly. Here's what each category covers and some of the key permissions in it.

### Printing
Everything to do with running prints: **Can print**, **Can slice**, **Clear bed**, **Can pause**, **Can cancel** (and **Cancel others' prints**), **Reprint files**, **Emergency stop**, plus printer tools like **Bed leveling tool**, **Z-offset calibration**, **Send G-code**, **Change temperatures**, **See camera**, and management permissions like **Edit printers**, **Add printers**, **Delete printers** and **Manage printer groups**.

### Print queue
Access to the print queue and what a member can do in it: **Access print queue**, **Re-order print queue**, **Start & slice via print queue** (lets a member print through the queue even without "Can print"), **Assign printers & printer groups to queue item**, **See other users' job items**, and, on the School and Enterprise plans, **Approve/deny queue items** and **Skip approval requirement**.

### Slicer
What a member can change in the cloud slicer, from **Allow custom slicer profiles** and **Access & change account slicer settings** down to individual tools like **Change slicer engine**, **Change slicer print profile settings**, **Auto arrange models**, **Paint support** and **Add and edit text**.

### Courses
For the Academy: **View courses**, **Manage courses**, **View course reports** and **Assign courses**.

### Filament system
Managing filament and the filament tools: **View filament system**, **Add new filament**, **Change filament**, **Manage filament locations**, **Dry filament**, **Generate filament labels**, **Assign & flash filament NFC tags** and **Barcode & QR code scanner access**.

### Maintenance
**View maintenance**, **Manage maintenance**, **Complete maintenance tasks**, **Report maintenance problems** and **Manage spare parts inventory**.

### Users
Team-management permissions: **Can see the Users tab**, **Can invite users** (which also covers approving pending members), **Can delete users**, **Can change user rank**, **Assign peer rank**, and **Can confirm user email** (manual email verification).

### Organisation management
Account-wide settings and visibility. This is the largest category and includes **Edit organisation settings**, **Edit registration settings**, **Manage user groups**, **Manage custom fields**, **Manage subscription**, **View audit log**, **Manage access & security settings** (panel IP restrictions and the require-2FA setting), **Export data**, **Can see statistics page**, **See who printed**, and the quota permissions **Manage quotas & limits**, **Approve quota requests** and **Manage user balance**. On School accounts it also includes **View school dashboard**, **Set user as teacher** and **Change user's school class**.

## Quotas, SSO mapping and IP exemptions
A group can also carry a few settings beyond plain permissions:

- **Quotas & limits** (School and Enterprise plans) - cap how much the group can print, slice or spend. See [quotas and limits](https://help.simplyprint.io/en/article/the-quotas-limits-feature-control-how-much-your-users-can-print-1emghhw/).
- **SSO group mapping** - if your account uses single sign-on, map identity-provider groups to this SimplyPrint group so members land in the right place automatically. See [SAML user groups and group mapping](https://help.simplyprint.io/en/article/saml-single-sign-on-user-groups-group-mapping-and-teacher-mapping-lfgz7/).
- **Exempt from IP restrictions** - if you've set [panel IP restrictions](https://help.simplyprint.io/en/article/require-2fa-and-restrict-panel-access-by-ip-nr6fb4/), members of this group can bypass them.

## Related articles
- [Workgroups: layering extra access on top of a member's role](https://help.simplyprint.io/en/article/workgroups-layering-extra-access-on-top-of-a-members-role-qjypld/)
- [Managing your users: the Users page](https://help.simplyprint.io/en/article/managing-your-users-the-users-page-15hfca/)
- [How to invite users to your account](https://help.simplyprint.io/en/article/how-to-invite-users-to-your-account-1gue0zv/)
- [Give a member temporary access](https://help.simplyprint.io/en/article/give-a-member-temporary-access-58a6an/)
- [Require 2FA and restrict panel access by IP](https://help.simplyprint.io/en/article/require-2fa-and-restrict-panel-access-by-ip-nr6fb4/)
- [The quotas & limits feature](https://help.simplyprint.io/en/article/the-quotas-limits-feature-control-how-much-your-users-can-print-1emghhw/)
- [SAML single sign-on: user groups, group mapping, and teacher mapping](https://help.simplyprint.io/en/article/saml-single-sign-on-user-groups-group-mapping-and-teacher-mapping-lfgz7/)