- Google Groups (requires the Google Groups connector)
- Azure Active Directory/Entra ID Groups (requires the Microsoft 365 (O365) connector)
Prerequisites
Before users can share agents with IdP groups, two things must be configured:- The corresponding connector must be set up and actively syncing groups into Glean:
- For Google Groups: set up the Google Groups connector (which requires a connected Google Drive instance).
- For Azure Active Directory/Entra ID Groups: set up the Microsoft 365 (O365) connector.
- An admin must select which IdP source to use for agent group sharing in the Admin Console. See Configure the IdP source for agent group sharing.
Configure the IdP source for agent group sharing
An admin must choose which identity provider supplies the groups that appear when sharing agents.- Navigate to the Admin Console > Agents.
- Under the Manage tab, go to Sharing agents to Identity Groups, and select the identity provider you want to use:
- Google Groups
- Azure Active Directory/Entra ID Groups
It may take up to 4 hours for changes to the configured IdP source to take effect.
Enable group sharing for default members
By default, only Admins and Agent Moderators can share agents with IdP groups. To allow default members to share agents with groups they belong to:- Navigate to the Admin Console > Teammates.
- Select the Default Member permissions button.
- Under Can share agents, enable the With identity provider groups toggle.
Share an agent with an IdP group
After the IdP source is configured and sharing is enabled:- Open the agent you want to share.
- Open the People with access panel.
- Search for the group by name using the group picker.
- Select the group and assign the desired permission level:
- Viewer — can use the agent
- Editor — can use and edit the agent
- Owner — can use, edit, and manage sharing for the agent
- Confirm the selection.
The group picker is optimized for type-ahead search and displays a maximum of 20 groups at a time. Type at least a few characters to narrow results.
How access updates work
Glean evaluates group-based agent permissions at request time using the group membership data already synced from your identity provider. Keep the following in mind:- Sharing with an existing group takes effect immediately: When you share an agent with an IdP group, users who are already members of that group gain access on their next request and there is no additional sync wait.
- Group membership changes in your IdP are not immediate: If someone is added to or removed from a group in your identity provider, the change takes effect in Glean after the next identity sync cycle.
- Permissions are inherited: If a user is a member of a group that has been granted access to an agent, they receive that permission level automatically.
- Individual and group permissions coexist: A user can have access through both individual sharing and group sharing. The highest permission level applies.