A tenant can be organised into units and subgroups. Both appear as trees on the tenant's Units and subgroups page.
Units
Units are the tenant's formal structure, such as departments and teams, usually mirroring the organisation chart. Access given to a unit also reaches the units below it. Administrators and user administrators create, rename and delete units.
Subgroups
Subgroups are groups for a purpose, such as a project or a committee. Owners, administrators and user administrators create them. Subgroups can be nested only a few levels deep (three by default, set by the platform as subgroups.maxNestingDepth); when the limit is reached, the page no longer offers a deeper subgroup and says why.
Private member lists
A subgroup's member list can be made private. Then only its own members, administrators and user administrators can see who is in it; other people can still be given access through the subgroup. Units and role groups can't be private.
Group members
Choose Members on a group to see who is in it. To add someone, search by name or email and choose them; to remove someone, choose the remove button and confirm. Guests can't join units or subgroups: they belong to the tenant only as guests. Leaving a group doesn't affect the person's tenant membership.
Suspension
Suspending a unit or subgroup pauses everything granted to it and to the groups below it, in every app. Memberships and grants are kept and work again when the group is reinstated. A reason is required.
Only the authority directly above a group may suspend it: the tenant's owners and administrators for its units and subgroups, and the Shokoofa platform for the tenant itself. Role groups can't be suspended.