VerifyFiltering — home VerifyFiltering — home
Learn / Network Security

What Group-Scoped Team Members Can See

When you invite a team member, you choose whether they see your whole fleet or only specific device groups. That choice — group scoping — narrows what they can see and act on, but it doesn't work quite the same way everywhere in the dashboard. Here's what it actually restricts.

Groups belong to you, not to the team member

Device groups are created and owned by your account, not by any team member. Scoping restricts which of your existing groups a team member is allowed to touch at all — it's an allow-list, not a way to hand out a group of their own. A team member whose role permits managing groups can still rename, reconfigure, or delete a group that's inside their assigned scope; scoping decides which groups are in reach, not what they're allowed to do to the ones that are. A device you never assigned to any group stays invisible to every group-scoped team member, even ones who can otherwise see plenty of your fleet.

Two settings, not one

A team member's access is really two independent settings working together, not one:

  • Role — admin, technician, viewer, or billing — decides which actions and pages they can use at all. A viewer can't manage devices no matter what groups they're scoped to; a billing-role member can't see fleet or device data at all, full stop.
  • Scope — full fleet, or specific groups — decides which rows of device data a permitted action is allowed to touch.

They compose rather than override each other. A group-scoped technician can still manage devices — their role allows it — but only the devices inside their assigned groups. Changing one doesn't change the other.

What "no groups assigned" actually means

Choosing group scope for a team member requires picking at least one group up front, and you can't edit them down to an empty selection later either — the dashboard rejects both. But it's still possible for a group-scoped member to end up with zero groups: if the last group they were scoped to gets deleted. The result isn't "they see everything" — it's "they see nothing." A group-scoped member with no groups assigned, and a suspended team member, are both treated as having no access rather than full access, by design.

What group scoping doesn't cover

A couple of things are fleet-wide on purpose and simply aren't scopable by group at all:

Alerts

Alert configuration applies to your whole fleet and has no per-group concept. Rather than showing a group-scoped team member alert data that spans devices outside their assigned groups, the dashboard removes their access to the Alerts page entirely.

Fleet-wide settings

Creating a brand-new group and changing your account's default scan profile both affect the whole account, not any one group. A group-scoped team member can't do either — not because their role lacks permission, but because there's no group-level version of "create a group" or "set the account default" for scoping to apply to.

Groups require the same plan tier as team members

If your plan supports inviting team members at all, it also supports creating device groups to scope them with — there's no tier where you'd have one without the other. See comparing plan tiers for what each tier includes.

Compliance & Filtering

Guides on network content filtering, the standards that regulate it, and how to verify your own network actually meets them.

Standards We Test

  • CIPA
  • UK Safer Internet
  • Friendly WiFi
  • Custom Profiles

VerifyFiltering Monitoring

Move past a one-time scan — scheduled, ongoing checks across every device you manage, with alerts when something changes.

See plans →

CleanBrowsing

VerifyFiltering is a CleanBrowsing service. CleanBrowsing itself offers fast, privacy-first DNS filtering you can deploy directly.

Explore CleanBrowsing →

Contact Us

Have an idea for an article, or see something missing? Email support@noc.org.