The Hudu admin area is accessible ONLY to admins and super admin users within your organization.
Security groups let you organize users and control what they can see in Hudu. Restrictions can be applied to almost anything and configured at several levels: by client (e.g., hiding certain client spaces from a group entirely), by feature (e.g., removing access to Passwords or specific asset layouts), by folder (e.g., limiting a KB folder to selected groups), or by individual item (e.g., restricting a single password or KB article).
If no group is assigned when a user is created, they're automatically added to the default group.
Security groups let you:
Organize users who need the same permissions into a single unit.
Apply access changes to a whole group at once instead of configuring each user individually.
Quickly restrict a group from any item stored in Hudu.
Only user roles of a spectator, and editor can be added to security groups; for additional information, visit our User Management article. All users with these user roles are required to be in at least one security group.
Creating security groups
Only Admins and Super Admins can create or update security groups.
- Go to the Admin area and select Groups. This page lists all security groups, along with each group's member count, whether it uses an allow list or a deny list, and whether it's the default group (marked with a Default badge).
- Click New group and enter a name.
- Choose a starting access model.
- Select any restrictions that apply, then click Save.
Starting access model
New groups use the allow list by default.
- Allow list (start with access to no companies): the group has no company access until you grant it.
- Deny list (start with access to all companies): the group has access to every company in Hudu until you remove it.
Restrictions
All features are enabled for new groups by default. Select a restriction only if you want to remove that access.
- Remove access to the Global view: removes access to the Global tab, including global assets, passwords, and other documentation.
- Remove access to Central KB: removes access to Central KB articles and the Central KB navigation link.
- Remove access to Personal Vaults (My Vault): removes the ability to store personal passwords in My Vault.
- Remove access to Hudini: removes access to Hudini features.
- Remove access to Share: removes the ability to share articles, processes, and passwords.
- Remove access to Request: removes the ability to send password requests to others.
- Remove access to Company Passwords: removes the ability to view and store passwords within companies.
- Remove access to Agreements: removes the ability to view agreements.
Setting up restrictions
-
Navigate to the Hudu admin area >> Groups >> and into an existing security group.
-
Members
- Provides an overview of current members of the group.
- Choose to add or update users in the security group.
-
Companies:
-
Select how you'd like client access to default for the group:
- Allow list: Group will only have access to the clients that you allow; all other client spaces will be hidden.
- Deny list: Group will have access to all client spaces; except for the ones that you deny.
-
Select how you'd like client access to default for the group:
-
Login Schedule
- Select "Off" to not set a login schedule.
-
Select "On" to set login restrictions.
- Choose to set restrictions on when a group can access your Hudu environment. Set days of the week or times of the day that they're allowed in.
-
Access
-
Core tools: turn individual core tools on or off for the group. All core tools are enabled by default. Available tools are Global, Central KB, My Vault, Passwords, Processes, Company KB, Photos, IPAM, Racks, Websites, Expirations, Assets, Hudini, Share, Request, and Agreements.
- Share lets users generate external share links for passwords, processes, and articles.
- Request lets users send someone a request to fill in a password.
- Agreements only exist if certain PSA integrations are connected.
-
Asset layouts: choose which asset layouts the group can view. Select All asset layouts to give the group access to every current and future layout, or select specific layouts from the dropdown.
- A group without access to a layout can't view that layout in any client space the group is allowed to access.
- Password folders: shows the password folders the group can currently access. This list is view-only; to change a group's folder access, go to Admin > Password Folders.
-
Core tools: turn individual core tools on or off for the group. All core tools are enabled by default. Available tools are Global, Central KB, My Vault, Passwords, Processes, Company KB, Photos, IPAM, Racks, Websites, Expirations, Assets, Hudini, Share, Request, and Agreements.
If a user belongs to more than one security group and those groups have conflicting permissions on the same item, the restriction takes priority. The user will not be able to access the item, even if another group they're in allows it.
If a core tool is turned off for the entire instance, that tool's switches are locked on every group's Access tab and can't be changed until the tool is turned back on instance-wide. See our article on Admin General Settings for more information on restricting Core Tools instance wide.A group's core tool settings aren't lost while locked. If the tool is turned back on for the instance, that group's previous setting for it is restored automatically.
Restricting individual items
Nearly everything stored in Hudu has a More Options menu, which you can use to restrict individual items from specific security groups.
- Navigate to the item (password, KB article, asset, etc.) and select More Options in the top right-hand corner.
- Select Change Permissions.
- Choose which security group(s) you'd like to prevent from accessing the item, then save.
To unrestrict an item, repeat the steps above and deselect the previously restricted security group(s) in Change Permissions, then save. The item will be visible to that group again.
To see which users currently have access to an item, select More Options on that item and choose View Current Access.
Restricting KB folders
As of version 2.46, root-level KB folders in the Central KB or a client's KB can be restricted to specific security groups. This sits between whole-KB access and individual article restrictions, letting you lock down a whole folder tree at once instead of restricting articles one at a time.
- Navigate to the folder and open its Edit Folder panel.
- Under Who can view this folder?, choose All users with access to the knowledge base or Selected groups.
- If you chose Selected groups, use Select group(s) to search for and add the groups that should have access.
- Click Save.
Subfolders always inherit the root folder's permission and can't be set individually.
Only admins and super admins can set or change folder permissions. Admins and super admins always retain access, regardless of group restrictions.
Visit Knowledge Base for additional information on KB folders.
FAQ
What happens if a user is in groups with conflicting permissions?Answer: If a user is in multiple groups with conflicting allow/deny permissions, Hudu defaults to the deny permission.
For example, a user belongs to:
Group A (Deny List): Denies access to companies X and Y
Group B (Allow List): Allows access to companies Y and Z
Group C (Deny List): Denies access to company W
Result:
User cannot access companies W, X, and Y (denied by Groups A and C)
User can access company Z (allowed by Group B)
User cannot access any other companies (due to Allow List default for mixed group types)
When should I put users in multiple groups?Answer: Multiple groups are most useful when you want to create combinations of different permissions for users within the same instance.
Example 1:
An MSP has 10 employees and the following needs:
2 of them should not be able to view company passwords.
All 10 should not view Test Co
1 should not view AtlasCo
Otherwise, they should be able to view everything.
One way to handle this would be to:
Create a group named NoTestCo Group in deny mode, so all users in it can access all companies unless otherwise specified. Deny that group access to TestCo and add all 10 users to it.
Create a group in deny mode named NoAtlasCo Group so all users in it can access all companies unless otherwise specified. Deny that group access to AtlasCo and add the 1 user to it.
Create a group named NoPasswordView Group in deny mode, so all users in it can access all companies unless otherwise specified. Do not specify any companies. On the Access tab, turn off Passwords. Add the 2 users to it.
Multiple groups are also helpful when it comes to password folders.
Example 2:
User A is a part of a Technicians group and a Super Technicians group.
User B is a part of a Technicians group.
There is a password folder named High Security Passwords.
There is a password folder named All Techs Passwords.
Super Technicians group is given access to view the High Security Passwords folder.
Technicians group and Super Technicians group are given access to view the All Techs Passwords folder. Results:
User A (members of Technicians group and Super Technicians group) is ALLOWED to see High Security Passwords.
User B (member of Technicians group) is NOT allowed to see High Security Passwords.
User A is ALLOWED to see All Techs Passwords.
User B is ALLOWED to see All Techs Passwords.
When should I use allow list?Answer: Allow list means the group will only have access to the companies you specifically list. It is the most restrictive method for controlling company access. You may want to use this list for your default group, or if you typically want to restrict users in your instance from accessing companies as much as possible. If you create a new company in Hudu, a group using allow list would automatically not have access to that company unless you add that company to the group’s allowed companies list in the group’s settings.
When should I use deny list?Answer: Deny list means the group will have access to any companies unless you have specifically denied the company. This is a less restrictive option than allow list. If you create a new company in Hudu, a group using deny list would automatically have access to that company unless you manually add that company to the group’s denied companies list in the group’s settings.
What is the difference between "Select all" and "All asset layouts"?Select all is a one-time action that selects or deselects every asset layout currently in the list. All asset layouts means the group can access every asset layout that exists in the instance right now, plus any created in the future. This gives admins control over whether new asset layouts are available to a group by default: if yes, use All asset layouts; if no, manually select only the layouts the group should access, and any new layouts created later won't be accessible to the group unless you add them.
Why doesn't every chip show in the input?An instance can have an unlimited number of asset layouts, so the input can't reasonably display the names of every layout selected (for example, if a group has access to 100 layouts). Once a third item is selected from the dropdown, the chips begin truncating.
-
Members