When you invite a team member, you choose whether they see your whole fleet or only specific device groups. That choice — group scoping — narrows what they can see and act on, but it doesn't work quite the same way everywhere in the dashboard. Here's what it actually restricts.
Device groups are created and owned by your account, not by any team member. Scoping restricts which of your existing groups a team member is allowed to touch at all — it's an allow-list, not a way to hand out a group of their own. A team member whose role permits managing groups can still rename, reconfigure, or delete a group that's inside their assigned scope; scoping decides which groups are in reach, not what they're allowed to do to the ones that are. A device you never assigned to any group stays invisible to every group-scoped team member, even ones who can otherwise see plenty of your fleet.
A team member's access is really two independent settings working together, not one:
They compose rather than override each other. A group-scoped technician can still manage devices — their role allows it — but only the devices inside their assigned groups. Changing one doesn't change the other.
Choosing group scope for a team member requires picking at least one group up front, and you can't edit them down to an empty selection later either — the dashboard rejects both. But it's still possible for a group-scoped member to end up with zero groups: if the last group they were scoped to gets deleted. The result isn't "they see everything" — it's "they see nothing." A group-scoped member with no groups assigned, and a suspended team member, are both treated as having no access rather than full access, by design.
A couple of things are fleet-wide on purpose and simply aren't scopable by group at all:
Alert configuration applies to your whole fleet and has no per-group concept. Rather than showing a group-scoped team member alert data that spans devices outside their assigned groups, the dashboard removes their access to the Alerts page entirely.
Creating a brand-new group and changing your account's default scan profile both affect the whole account, not any one group. A group-scoped team member can't do either — not because their role lacks permission, but because there's no group-level version of "create a group" or "set the account default" for scoping to apply to.
If your plan supports inviting team members at all, it also supports creating device groups to scope them with — there's no tier where you'd have one without the other. See comparing plan tiers for what each tier includes.