Scope a connection to a team
Make one installation available only to its assigned teams.
Assign the scope
Prepare the team and its membership before changing connection access.
- Open the connection in the Admin workspace.
- Use the team scope editor to assign the intended group or groups.
- Save and have an assigned member run a reviewed read with their own provider authorization.
- Confirm a member outside every assigned team cannot use that connection.
Troubleshooting
A person retains access after leaving a team
Check their other team memberships and confirm directory changes have synchronized. Also check whether the installation now has an empty, organization-wide scope.
Frequently asked questions
What if a person belongs to two teams?
Membership in either assigned team can satisfy connection scope. Team policy denials and all other access checks still apply.
Are administrators exempt?
No. Administrators can inspect installation settings, but using a scoped connection still requires team access.