- By team —
backend-team,data-engineering,platform - By department —
engineering,finance,operations - By application —
checkout-service,payments,user-auth - By environment — if different people manage dev vs prod
Creating a Folder
1
Navigate to Accounts
Go to Privileged Access Management → Accounts and click Create Folder.
2
Configure the folder
Click Create.
Managing Access
Access to a folder is controlled through memberships. You assign users or groups a role, and that role determines what they can do.Adding Members
1
Open the folder
Click on the folder to open its detail page.
2
Go to Permissions
Click the Permissions tab.
3
Add a member
Click Assign Access and configure:
Click Add.
Roles
When you assign a role on a folder, it applies to all accounts inside that folder. This is the main way to grant access — you don’t have to set up permissions on each account individually.
Time-Bound Access
For contractors or temporary team members, set an expiration when adding the membership. The access is automatically revoked when it expires — no manual cleanup needed.Groups vs Individual Users
You can grant access to individual users or to groups:- Individual users — straightforward, easy to audit
- Groups — access follows group membership; when someone joins or leaves the group, their folder access updates automatically
Next Steps
Now that you have a folder, you’ll want to add accounts to it. But before that, you might want to set up templates to define what rules apply to those accounts.Templates
Define session rules before adding accounts.
Accounts
Add databases and servers to your folder.