Acceldata
AIO

Last updated: Oct 06, 2026 15:09 UTC

Resource groups

This page explains how resource groups collect AIO projects and how that grouping decides which projects, rules, and telemetry each user can reach.

What a resource group is

A resource group is a named set of AIO projects. AIO uses resource groups of the type AIO_PROJECT_GROUP. You grant users permissions on a group, and they get those permissions on every project in it.

Resource groups matter because they're how you give users access without making them resource admins. A resource admin can reach every project in the tenant. Every other user can reach only the projects in the groups they hold permissions on.

You create resource groups and choose their projects outside AIO, in Management. AIO has no screen for editing groups.

How it works

  1. Group the projects. In Management, a group editor creates a resource group and picks its projects. The picker lists every project in your tenant, so the editor can add any of them.
  2. Save the group. Management sends the group's full list of projects to AIO. The new list replaces the old one completely: AIO adds the projects you included, removes the ones you left out, and ignores duplicates. Saving the same list again changes nothing.
  3. Grant permissions on the group. Give users view:aioProject or modify:aioProject on the group. For what each permission allows, see Project permissions.
  4. Use AIO. On every request, AIO checks the user's grants and turns their groups into a set of projects. Changes take effect on the user's next request.

A membership change applies in full or not at all. If any project in the list doesn't belong to your tenant, or the change fails for any other reason, the group keeps its previous projects. A failed change never empties the group or applies only part of the list.

What grouping controls

For a user who isn't a resource admin, a project's resource groups decide:

  • Which projects appear in the project list.
  • Which projects the user can open or update.
  • Which rules the user sees in the rule list and can change.
  • Which projects' telemetry a query can return.

How group membership adds up

  • One project, many groups. A project can belong to several resource groups. The user's permissions on the project combine the permissions from all of those groups. If any group that contains the project grants a permission, the user has that permission on the project.
  • Projects in no group. Only resource admins can reach a project that belongs to no group.
  • New projects. A project you create starts out in no group. Until you add it to a group, only resource admins can reach it. To create a project, see Create a project.
  • Deleted projects. Deleting a project removes it from every group automatically.
  • Tenants. Group membership stays within a tenant. A group can't include a project from another tenant.

Next steps