Skip to content
Features

Organizing administrators in Teams

A Team is a named group of administrators. Grant roles to the Team once and every member inherits them, with different roles per Service Context. Create teams, add members, and grant access.

A Team is a named group of administrators. Instead of assigning roles to people one by one, you grant roles to a Team and manage who belongs to it — every member inherits the Team’s roles. A Team can hold different roles in different Service Contexts, so one team can run a Sign-In context while holding read-only access to an EntryPoint context.

Teams live at Admin Access Control → Teams in the Organization left navigation.

The Teams page listing two teams with description, source, member count, and context access columns
The Teams page — one row per team, with its source (Manual or SCIM), member count, and how many contexts it has access to.

Click Add Team and give it a name and a short description. A new team starts empty and holds no access yet.

The Add Team dialog with a Team name field and a Description field
Add Team — just a name and a description. You grant roles afterwards.

Open the team and add members by email on the Team Members tab. Members inherit the team’s roles in the Organization.

A team's detail page showing the Team Members section and a Context access section
Team details — add members by email; the Context access section summarizes where the team has roles.

Members must be administrators first

You can only add someone who is already a member of the Organization. If you enter an email that isn't, Netgraph offers to invite them as an Organization Member and add them to the team in one step — they accept the invitation before they can sign in.
A confirmation dialog offering to invite a non-member as an Organization Member and add them to the team
Adding a non-member prompts you to invite them as an Organization Member first.

Creating a team and granting it roles are deliberately separate. You grant roles under Admin Access Control → Administrators, on the Teams tab — at the Organization level, or inside any Service Context.

  1. Open Administrators → Teams

    Go to Administrators and switch to the Teams tab. Do this at the Organization level for Organization-wide roles, or inside a specific Context for roles there.

  2. Add the team and pick roles

    Click Add Team, choose the team, and tick the roles to grant. Each role lists exactly what it allows.

  3. Repeat per context as needed

    Grant the same team different roles in Sign-In, EntryPoint, Meraki WPN, or Cisco ISE — whatever each context needs.

The Add Team role-assignment dialog with a team selector and role checkboxes with descriptions
Administrators → Teams → Add Team — pick a team and grant it roles. Repeat in each context for different roles.

This split means you can change who is in a team without touching what the team can do, and the reverse.

A group synced from your identity provider through SCIM provisioning appears here as a team whose Source is SCIM and whose membership follows the IdP group. SCIM keeps the membership in step but never sets the team’s roles — you grant those exactly as above.

Next